🚂 RailGuruji
Information security and cyber lawसूचना सुरक्षा और साइबर कानून1 / 6

Information security and threatsसूचना सुरक्षा और खतरे

Updated अद्यतन 07 Oct 2026
This pageयह पेज asked in 2 exams2 परीक्षाओं में पूछा गयाThis chapterयह अध्याय asked in 2 exams2 परीक्षाओं में पूछा गया
1
INFORMATION SECURITY AND THE CIA TRIADसूचना सुरक्षा और सीआईए त्रयी
The MHA's National Information Security Policy and Guidelines, NISPG, define INFORMATION SECURITY as protecting information from unauthorised access, use, disclosure, disruption, modification or destruction.
  • CONFIDENTIALITY: only authorised people may access and disclose it
  • INTEGRITY: it is not modified or destroyed improperly; this includes non-repudiation and authenticity
  • AVAILABILITY: timely and reliable access to it
  • AUTHENTICATION verifies who you are; AUTHORIZATION grants what you may do
  • NEED-TO-KNOW, or LEAST PRIVILEGE: access only to what your job needs
So the three goals are confidentiality, integrity and availability, the CIA triad.
गृह मंत्रालय की राष्ट्रीय सूचना सुरक्षा नीति और दिशानिर्देश, अर्थात् एनआईएसपीजी, सूचना सुरक्षा को अनधिकृत पहुँच, उपयोग, प्रकटीकरण, व्यवधान, संशोधन या विनाश से सूचना की रक्षा बताते हैं।
  • गोपनीयता: केवल अधिकृत लोग उस तक पहुँच और उसका प्रकटीकरण कर सकते हैं
  • अखंडता: उसमें अनुचित संशोधन या विनाश नहीं होता; इसमें अस्वीकार्यता-रोधी गुण और प्रामाणिकता शामिल हैं
  • उपलब्धता: उस तक समय पर और विश्वसनीय पहुँच
  • ऑथेंटिकेशन सत्यापित करता है कि आप कौन हैं; ऑथराइजेशन तय करता है कि आप क्या कर सकते हैं
  • नीड-टू-नो, या लीस्ट प्रिविलेज: केवल उतनी पहुँच जितनी आपके काम को चाहिए
अर्थात् तीन लक्ष्य गोपनीयता, अखंडता और उपलब्धता हैं, अर्थात् सीआईए त्रयी।
2
VIRUSES, WORMS AND TROJANSवायरस, वर्म और ट्रोजन
  • A VIRUS infects other programs and copies itself into them. It erases or corrupts data, or annoys you with messages
  • A WORM multiplies like a virus, but spreads from COMPUTER TO COMPUTER on its own
  • A TROJAN HORSE masquerades as a useful program, such as a fake logon screen that steals passwords. It has a client part and a server part
  • A BOTNET is a set of infected computers, the bots, controlled by one bot-master, often for DoS attacks and spam
  • RANSOMWARE, SPYWARE and CRYPTOMINERS are on CERT-In's list of malicious code you must report
So a virus needs a host program, and a worm travels by itself.
  • वायरस दूसरे प्रोग्रामों को संक्रमित करके उनमें अपनी प्रतियाँ बनाता है। यह डेटा मिटाता या बिगाड़ता है, या संदेशों से आपको परेशान करता है
  • वर्म वायरस की तरह बढ़ता है, पर स्वयं कंप्यूटर से कंप्यूटर तक फैलता है
  • ट्रोजन हॉर्स किसी उपयोगी प्रोग्राम का रूप धरता है, जैसे पासवर्ड चुराने वाली नकली लॉगऑन स्क्रीन। इसके क्लाइंट और सर्वर दो भाग होते हैं
  • बॉटनेट संक्रमित कंप्यूटरों, अर्थात् बॉट, का समूह है जिसे एक बॉट-मास्टर नियंत्रित करता है, प्रायः डीओएस हमलों और स्पैम के लिए
  • रैनसमवेयर, स्पाइवेयर और क्रिप्टोमाइनर सर्ट-इन की उस दुर्भावनापूर्ण कोड सूची में हैं जिसकी आपको सूचना देनी है
अर्थात् वायरस को मेजबान प्रोग्राम चाहिए, और वर्म स्वयं चलता है।
3
asked in 1 exam1 परीक्षा में पूछा गया
PHISHING, SPOOFING AND SOCIAL ENGINEERINGफिशिंग, स्पूफिंग और सोशल इंजीनियरिंग
  • SOCIAL ENGINEERING tricks you into revealing sensitive information, or into running files that look harmless
  • PHISHING sends you a fake message or page to steal passwords or bank details. A 2022 NAIR paper keys phishing as a security THREAT
  • SPOOFING alters packets or e-mail headers so a message seems to come from another source
  • E-MAIL BOMBING sends the same message repeatedly to one address; SPAMMING sends mail to thousands
  • IDENTITY THEFT uses your personal information to commit fraud; DATA DIDDLING changes data before or during input
  • CYBER SQUATTING registers a domain name like a popular one to attract its users
So phishing is a threat, the weakness it exploits is a vulnerability, and the chance of harm is a risk.
  • सोशल इंजीनियरिंग आपको छलकर संवेदनशील जानकारी बताने, या हानिरहित दिखने वाली फाइलें चलाने पर मजबूर करती है
  • फिशिंग पासवर्ड या बैंक विवरण चुराने के लिए आपको नकली संदेश या पेज भेजती है। 2022 का एक एनएआईआर प्रश्नपत्र फिशिंग को सुरक्षा खतरा मानता है
  • स्पूफिंग पैकेटों या ई-मेल हेडरों को बदलती है ताकि संदेश किसी अन्य स्रोत से आया लगे
  • ई-मेल बॉम्बिंग एक ही पते पर बार-बार वही संदेश भेजती है; स्पैमिंग हजारों लोगों को मेल भेजती है
  • आइडेंटिटी थेफ्ट आपकी व्यक्तिगत जानकारी से धोखाधड़ी करती है; डेटा डिडलिंग प्रविष्टि से पहले या उसके दौरान डेटा बदलती है
  • साइबर स्क्वाटिंग किसी लोकप्रिय डोमेन जैसा नाम पंजीकृत करके उसके उपयोगकर्ताओं को खींचती है
अर्थात् फिशिंग खतरा है, जिस कमजोरी का वह लाभ उठाती है वह भेद्यता है, और हानि की संभावना जोखिम है।
4
DENIAL OF SERVICEडिनायल ऑफ सर्विस
  • A DENIAL OF SERVICE, DoS, attack floods a computer resource with more requests than it can handle, so it crashes
  • Your authorised users are then denied the service
  • A DISTRIBUTED DoS, DDoS, breaks into hundreds or thousands of computers, the ZOMBIES, and turns them on one target
  • DoS may consume scarce resources such as bandwidth, RAM and CPU time
  • It may also destroy configuration information, or physically damage network components
So DoS floods a target, and DDoS floods it from many zombies at once.
  • डिनायल ऑफ सर्विस, डीओएस, हमला किसी कंप्यूटर संसाधन पर उसकी क्षमता से अधिक अनुरोध भेजता है, जिससे वह ठप हो जाता है
  • तब आपके अधिकृत उपयोगकर्ताओं को सेवा नहीं मिलती
  • डिस्ट्रिब्यूटेड डीओएस, डीडीओएस, सैकड़ों या हजारों कंप्यूटरों, अर्थात् जॉम्बी, में सेंध लगाकर उन्हें एक लक्ष्य पर लगा देता है
  • डीओएस बैंडविड्थ, रैम और सीपीयू समय जैसे दुर्लभ संसाधन खपा सकता है
  • यह विन्यास जानकारी नष्ट कर सकता है, या नेटवर्क घटकों को भौतिक क्षति पहुँचा सकता है
अर्थात् डीओएस लक्ष्य को भर देता है, और डीडीओएस उसे एक साथ कई जॉम्बी से भरता है।
5
asked in 1 exam1 परीक्षा में पूछा गया
DATA MASKING AND SANITIZATIONडेटा मास्किंग और सैनिटाइजेशन
  • DATA MASKING hides original data with modified content, to protect sensitive personal or commercial data. A 2022 NAIR paper keys this
  • The NISPG require masking when data is given for testing or through application interfaces
  • Its techniques are RANDOMIZATION, BLURRING, NULLING, SHUFFLING and SUBSTITUTION
  • SANITIZATION is different: it removes information from media so that it cannot be recovered
  • DATA LEAK PREVENTION, DLP, detects and blocks sensitive data leaving in use, in motion or at rest
So you mask data to use it safely, and you sanitize media to destroy it.
  • डेटा मास्किंग संवेदनशील व्यक्तिगत या व्यावसायिक डेटा की रक्षा के लिए मूल डेटा को संशोधित सामग्री से छिपाती है। 2022 का एक एनएआईआर प्रश्नपत्र यही मानता है
  • एनआईएसपीजी परीक्षण के लिए या एप्लिकेशन इंटरफेस से डेटा देते समय मास्किंग अनिवार्य करते हैं
  • इसकी तकनीकें हैं: रैंडमाइजेशन, ब्लरिंग, नलिंग, शफलिंग और सब्स्टिट्यूशन
  • सैनिटाइजेशन भिन्न है: यह माध्यम से जानकारी इस प्रकार हटाता है कि वह फिर प्राप्त न हो सके
  • डेटा लीक प्रिवेंशन, डीएलपी, उपयोग में, संचरण में या भंडारण में बाहर जाते संवेदनशील डेटा को पहचानकर रोकता है
अर्थात् डेटा को सुरक्षित उपयोग के लिए आप मास्क करते हैं, और माध्यम को नष्ट करने के लिए सैनिटाइज करते हैं।
Report an error on this pageइस पेज में गलती बताएँ
Read it — now test yourself. पढ़ लिया — अब खुद को परखें। Take the free Mock CBTफ्री Mock CBT दें