Backups, Cyber Hygiene and Indian Cyber Law
Saved in this browser only. See all revisions due
Key points
- Full, incremental and differential backups differ in what they copy and how they restore
- Incremental is fast to create and slow to restore; differential is the reverse
- 3-2-1 rule: 3 copies, 2 media, 1 off-site, with at least one offline
- Never reply to a suspicious mail to verify it; use a separate official channel
- CERT-In works under MeitY with authority under section 70B
- Cyber financial fraud helpline is 1930 and the portal is cybercrime.gov.in
- Section 66C is identity theft; 66D is cheating by personation
- Section 66A was struck down in 2015
On this page
Types of backup
| Type | What it copies | Speed and size | Sets needed to restore |
|---|---|---|---|
| Full | All data | Slowest, largest | Only the last full backup |
| Incremental | Changes since the last backup of any type | Fastest, smallest | Last full plus every incremental after it |
| Differential | Changes since the last full backup | Grows each day | Last full plus the latest differential only |
Key point
An incremental backup is quick to create but slow to restore. A differential backup is the opposite. The rule last full plus the latest one belongs to differential backups alone.
Example
A full backup every Sunday night with incrementals on other nights. If the server fails on Thursday morning, restoring needs 4 sets: Sunday full plus Monday, Tuesday and Wednesday incrementals. With differentials it would need only 2.
The 3-2-1 rule
Keep 3 copies of the data on 2 different media with 1 copy off-site. At least one backup should be offline, disconnected from the network, so that ransomware cannot encrypt it. Restoration should be tested regularly, because an untested backup is not a backup.
Cyber hygiene in an office
- Use official e-mail for official work. Do not keep official data in personal e-mail or unapproved cloud accounts.
- Do not use pirated software or unauthorised remote-access tools.
- Lock the screen with Win+L when leaving the desk.
- Never plug an unknown pen drive into an office computer.
- Report any suspicious mail or incident to the IT team at once. Never reply to a suspicious mail to verify it, because the reply reaches the attacker. Verify through a separate known official channel.
Institutions and law in India
- CERT-In, the Indian Computer Emergency Response Team, is the national incident response agency under MeitY, with authority under section 70B of the IT Act.
- Its April 2022 directions require cyber incidents to be reported within 6 hours and logs to be maintained for 180 days. Verify against the latest official instructions.
- Cyber crime complaints go to the national portal cybercrime.gov.in, and financial fraud to helpline 1930, both run under I4C of the Ministry of Home Affairs.
- Personal data is governed by the Digital Personal Data Protection Act, 2023.
Key sections of the IT Act, 2000
| Section | Subject |
|---|---|
| 43 | Penalty and compensation for damage to a computer system |
| 66 | Computer-related offences |
| 66C | Identity theft |
| 66D | Cheating by personation using a computer resource |
| 66E | Violation of privacy |
| 66F | Cyber terrorism |
| 70B | CERT-In as the national incident response agency |
| 72 | Breach of confidentiality and privacy |
Section 66A was struck down by the Supreme Court in Shreya Singhal v. Union of India, 2015.
Exam tip
In scenario questions, the options act promptly, reply to the same mail, and forward it to everyone with the link are almost always wrong. Verify independently and report is almost always right.
Practice questions
Answer all, then check. Explanations appear after checking.
Finished this topic? Tick it off.
Saved in this browser only. See all revisions due