Overview
This chapter, 'Society, Law and Ethics', introduces the social, legal and ethical dimensions of computing and the Internet for Class 11 students. It explains how computing affects individuals, communities and institutions, and why responsible behaviour matters. The chapter highlights key legal frameworks (with a focus on cyber laws and intellectual property), common cybercrimes, ethical principles for use of technology, privacy and data protection, digital safety, and environmental and social impacts such as e-waste and the digital divide. Students learn practical guidelines for safe and responsible online conduct, ways to protect personal and organizational data, the basics of rights and responsibilities under relevant laws, and how to recognise, prevent and report misuse of technology. The content prepares learners to make informed, ethical decisions when using computers and networks and to appreciate the broader societal consequences of computing.
Learning Objectives
- Define common terms such as society, law, ethics, cyber law, cybercrime and intellectual property.
- Explain the social, economic and cultural impacts of computing technologies on individuals, organisations and society.
- Identify common cybercrimes (phishing, identity theft, malware, hacking, cyberstalking) and provide examples for each.
- Describe key provisions of the Information Technology Act, 2000 relevant to cyber offences, electronic contracts and digital signatures.
- Apply ethical principles to analyze real-world computing scenarios and determine appropriate courses of action.
- Distinguish between copyright, patent, trademark and trade secret and explain how each protects software and digital content.
- Explain the concept of digital footprint, associated privacy risks and methods to protect personal data online.
- Demonstrate safe computing practices and basic cybersecurity measures such as strong passwords, software updates, antivirus and secure backups.
Topics in this chapter
18 topics · tap a topic title to jump straight to it.
Introduction to Society, Law and Ethics
Introduction to Society, Law and Ethics
Key Point: CIA triad: Confidentiality + Integrity + Availability = Security goals (concise model for information security).
Introduction
Society, Law and Ethics in the context of computing studies how information technology affects people (society), what legal rules govern IT use (law), and what moral principles guide behaviour (ethics). For Class 11 Computer Science, this topic builds awareness of responsible use of computers, legal obligations and ethical decision‑making in digital environments.
Key Concepts
- Society: A group of people sharing institutions, values and technology. Computing changes social interaction, work, education and privacy.
- Law: Formal rules enacted by the state to regulate conduct; laws relevant to computing include cybercrime statutes, intellectual property law and data protection rules.
- Ethics: Moral principles (right/wrong) that guide individual and professional behaviour beyond legal requirements. Ethics often fill gaps where law is silent or slow to respond.
Why it matters for Computing
Computer professionals and users must understand how software and data affect people’s rights and safety. Design, development and use of technology should respect privacy, avoid harm, and follow applicable laws (for example, handling personal data, avoiding plagiarism, and preventing misuse).
Main Topics Covered
- Digital footprint & privacy: Data created by online activities and how it can be collected, shared or misused.
- Intellectual property: Copyright, software licenses, plagiarism and how to legally use and distribute digital material.
- Cybercrime & security: Types of offences (hacking, phishing, identity theft, malware, cyberbullying) and basic protection measures.
- Legal framework (India): Information Technology Act, 2000 (and amendments) — key provisions cover unauthorized access, data tampering, electronic signatures, and intermediary liability; Copyright Act for creative works; emerging data protection laws.
- Professional ethics: Confidentiality, honesty, accountability, respect for user autonomy and avoiding harm.
Ethical Reasoning & Decision Making
Ethical frameworks help choose actions when law does not give a full answer. Common approaches include utilitarianism (maximise overall good), deontology (follow duties/rules), and virtue ethics (act according to good character traits). In computing, decisions often balance innovation, privacy and safety.
Practical Guidance for Students
- Respect copyrights and software licenses; cite sources and avoid plagiarism.
- Use strong passwords, update software, and be cautious with links and attachments to prevent malware/phishing.
- Think before posting: personal data posted online can persist and affect future opportunities.
- Report cyberbullying, harassment or illegal content to appropriate authorities and platform moderators.
Summary
Society, Law and Ethics teaches students how computing impacts people and how to act responsibly: obey the law, follow ethical principles, and consider social consequences. Understanding these topics helps build safer, fairer and more trustworthy digital systems.
- Phishing email pretending to be a bank asking for login details — legal issue (fraud), ethical issue (deception), social impact (financial loss).
- A student copies program code from the internet and submits it as original work — violates academic honesty and possibly copyright (plagiarism).
- Ransomware attack on a hospital encrypts patient records — causes harm to society (care disruption), is a criminal act, raises ethical concerns about negligence in security.
- Posting someone’s private photos on social media without consent — violates privacy, may be illegal (depending on jurisdiction), and is ethically wrong.
- Using open‑source library without following its license terms in a commercial product — legal/IP compliance issue.
- A social media platform algorithm amplifies false news leading to panic — shows societal impact of tech design and raises ethical questions about platform responsibility.
- \[CIA triad: Confidentiality + Integrity + Availability = Security goals (concise model for information security).\]
- \[Risk (informal): Risk = Threat × Vulnerability × Impact — helps assess and prioritise security controls.\]
- \[Privacy risk (simple model): Privacy Risk ≈ Data Sensitivity × Exposure × Likelihood of Misuse.\]
- \[Ethical utility (utilitarian view\]\[conceptual): Net Utility = Total Benefits − Total Harms (used to compare options morally).\]
- \[Intermediary liability (conceptual rule): Notice + Failure to Act ⇒ Possible Liability (applies in many takedown regimes where intermediaries must act on notified illegal content).\]
Impact of Computers on Society
Impact of Computers on Society
Key Point: Moore's Law (informal): Number_of_transistors ≈ 2^(t/τ) where τ ~ 1.5–2 years — describes exponential growth in transistor density over time.
Introduction: Computers have transformed nearly every aspect of modern life — communication, education, business, healthcare, governance and entertainment. Their widespread use raises social, legal and ethical questions covered in the Class 11 topic "Society, Law and Ethics."
Positive impacts
- Education: Digital classrooms, e-learning platforms and simulations expand access and personalize learning.
- Communication & Social Connectivity: Email, social media, video conferencing and instant messaging enable real-time global communication.
- Economy & Productivity: Automation, data analytics and enterprise software increase efficiency and enable new business models (e-commerce, fintech).
- Healthcare: Telemedicine, electronic health records, medical imaging and AI-assisted diagnosis improve care and access.
- Governance & Public Services: E-governance services, digital payments and online grievance systems improve transparency and reach.
- Research & Innovation: High-performance computing, simulations and access to global knowledge accelerate discovery.
- Accessibility: Assistive technologies (screen readers, speech recognition) help people with disabilities.
Negative impacts
- Privacy & Surveillance: Massive data collection risks misuse, profiling and loss of privacy.
- Security & Cybercrime: Hacking, identity theft, ransomware and online fraud threaten individuals and institutions.
- Employment disruption: Automation and AI can displace routine jobs, requiring workforce reskilling.
- Digital Divide: Unequal access to computers and the internet widens social and economic inequalities.
- Misinformation & Social Harm: False information, echo chambers and online harassment can destabilize societies.
- Health & Well-being: Excessive screen time, addiction to online content and ergonomic issues affect physical and mental health.
- Environmental Impact: Data centers and electronic waste consume energy and resources.
Legal and ethical considerations
- Data protection laws, intellectual property rights, cyber laws and regulations aim to limit misuse.
- Ethical principles — privacy, consent, fairness, accountability — guide design and deployment of computing systems.
- Policies are needed for transparency in algorithms, fair AI, and protection of vulnerable groups.
Mitigation & Responsible use
- Digital literacy and education to reduce the digital divide and improve safe use.
- Strong cybersecurity practices (encryption, authentication, regular updates).
- Regulations (data protection acts), privacy-by-design, and ethical review of AI systems.
- Reskilling programs and social safety nets to handle employment transitions.
Conclusion: Computers bring enormous benefits but also significant social, legal and ethical challenges. Balancing innovation with responsibility — through education, law, ethics and technology design — ensures society reaps the benefits while minimizing harm.
- E-governance: Digital India portals allowing online application for certificates, payment of taxes and subsidies — improves reach and reduces corruption.
- Online education: Platforms like SWAYAM, Coursera and school e-classes enable remote learning and recorded lectures.
- Telemedicine: Remote consultations and sharing of medical records improve access in rural areas.
- E-commerce & fintech: Amazon/Flipkart & UPI payments simplify trade and financial inclusion.
- Automation in manufacturing: Industrial robots increase productivity but reduce some manual jobs.
- Social media effects: Rapid dissemination of news and also spread of misinformation (viral fake news).
- \[Moore's Law (informal): Number_of_transistors ≈ 2^(t/τ) where τ ~ 1.5–2 years — describes exponential growth in transistor density over time.\]
- \[Metcalfe's Law: Value_of_network ∝ n^2 where n = number of users — shows how network utility grows rapidly with more users.\]
- \[Amdahl's Law (parallel computing): Speedup = 1 / ((1 - p) + p/s) where p = parallelizable fraction\]\[s = number of processors — limits expected speedup by parallelization.\]
- \[Exponential growth (data): Data(t) = Data0 × 2^(t/Td) where Td = doubling time — models rapid growth of digital data.\]
- \[Productivity (basic): Productivity = Output / Input — used to measure effects of computerization on economic efficiency.\]
Ethical Concepts and Theories
Ethical Concepts and Theories
Key Point: Total Utility (simple utilitarian): U_total = Σ u_i (sum of utilities u_i for all affected individuals)
Overview
Ethics studies principles that govern right and wrong behaviour. In computing, ethics helps decide how technology should be designed, used and regulated to respect people, society and the law.
Core concepts
- Morality vs Ethics: Morality = personal or cultural beliefs about right/wrong. Ethics = systematic study and justification of those beliefs.
- Values and Norms: Values are what a person/group considers important (privacy, fairness). Norms are behavioural expectations derived from values.
- Rights and Duties: Rights (e.g., privacy, access to information) impose duties on others (e.g., duty to protect user data).
- Responsibility and Accountability: Responsibility is obligation to act; accountability is being answerable for actions and consequences.
- Professional Ethics: Codes (like confidentiality, competence, integrity) that guide practitioners.
Major ethical theories
- Consequentialism / Utilitarianism: Right action maximises overall good (utility). Evaluate actions by their outcomes: greatest good for the greatest number.
- Deontology (Duty-based): Rightness determined by rules or duties (e.g., "do not lie") irrespective of consequences. Kantian ethics emphasizes universalizable maxims and treating people as ends, not means.
- Virtue Ethics: Focuses on moral character and virtues (honesty, courage). Right action expresses a virtuous character.
- Rights-based Ethics: Emphasizes protection of individual rights (speech, privacy); actions violating rights are unethical even if beneficial overall.
- Care Ethics: Emphasizes relationships, empathy and care responsibilities, often prioritising vulnerable parties.
- Ethical Relativism: Claims moral standards depend on culture or individual choice; problematic for universal professional standards.
- Social Contract: Morality arises from implicit agreements in society to secure mutual benefits and co-existence.
Applying theories to computing
- When designing software, consequentialists weigh benefits/harms to stakeholders; deontologists check compliance with duties (privacy laws, no deception); virtue ethicists ask what a responsible developer would do.
- Common dilemmas: privacy vs security, transparency vs intellectual property, automated decisions and bias, software reliability vs deadlines.
Practical decision steps
- Identify stakeholders and relevant facts.
- List possible actions/alternatives.
- Assess harms/benefits and rights/duties for each alternative.
- Apply ethical theories or a weighted decision model.
- Choose action, document reasoning, and plan mitigation for harms.
- Data privacy: A company considers selling aggregated user data. Utilitarian approach weighs economic benefits versus risks to users; deontological view focuses on duties to protect user consent and privacy.
- Plagiarism in code: Copying code without attribution may save time (short-term benefit) but violates professional integrity and legal rights of the original author.
- AI bias: A hiring algorithm favours one group. Consequentialists measure outcome disparities; rights-based and care ethics demand fairness and protection of disadvantaged applicants.
- Whistleblowing: An employee exposes security flaws the company hides. Deontology may support telling the truth as a duty, while consequentialism considers potential public harm prevented by disclosure.
- Software updates vs user consent: Pushing critical security patches automatically helps most users (utilitarian) but may conflict with users' control preferences (rights-based).
- \[Total Utility (simple utilitarian): U_total = Σ u_i (sum of utilities u_i for all affected individuals)\]
- \[Expected Utility: EU = Σ (p_j × u_j) (sum over outcomes j of probability p_j times utility u_j)\]
- \[Cost‑Benefit Ratio: CBR = Total Benefits / Total Costs (used to compare alternatives)\]
- \[Weighted ethical score (multi‑criteria): Score = Σ (w_k × s_k) where w_k is weight for criterion k and s_k is the score on that criterion\]
- \[Fairness difference (example metric): Disparity = |Rate_groupA − Rate_groupB| (used to quantify bias)\]
Computer Ethics (PAPA and related issues)
Computer Ethics (PAPA and related issues)
Key Point: CIA triad (conceptual, not numeric): Confidentiality + Integrity + Availability = core security goals
Overview: Computer ethics studies moral rules and professional conduct for computing professionals and users. It asks what is right or wrong when creating, using, sharing and managing digital information and systems. A useful framework is PAPA — Privacy, Accuracy, Property and Accessibility — which highlights common ethical concerns.
PAPA explained:
- Privacy — Concern about personal data collection, consent, storage, sharing and surveillance. Ethically we must minimize collection, obtain informed consent, protect data, and respect user anonymity when required.
- Accuracy — Ensuring information is correct and up-to-date. Inaccurate data can harm people (wrong medical records, credit reports). Ethical duties include verifying, correcting errors and communicating uncertainty.
- Property — Intellectual property (IP), copyrights, patents, trade secrets and software licenses. Ethical behavior means acknowledging creators, following license terms, and avoiding piracy and plagiarism.
- Accessibility — Fair access to information and computing resources. This covers digital divide issues, reasonable accommodations for people with disabilities, and equitable access to education and services.
Related ethical and social issues: cyberbullying, hacking and unauthorized access, identity theft, online harassment, data breaches, surveillance, targeted advertising, deepfakes, algorithmic bias, automated decision impacts, net neutrality, and the digital divide. Professionals must also follow codes of conduct, legal requirements (for example the IT Act, GDPR principles), and institute safeguards (encryption, authentication, auditing).
Principles and best practices: follow the CIA triad (confidentiality, integrity, availability); apply privacy-by-design and data minimization; use secure coding practices; respect copyrights and licenses; be transparent about data use; keep logs and allow redress; and promote inclusive access.
Decision-making approach: Identify stakeholders, list possible actions, evaluate harms/benefits (short- and long-term), check legal and professional rules, prefer least-harmful option, document and review outcomes.
CBSE classroom relevance: Understand PAPA as a mnemonic, relate each element to everyday school-level examples (sharing photos, group project plagiarism, school databases), and know simple technical controls (passwords, backups, permissions) and ethical responses (seek consent, report misuse).
- Privacy: A school app asks for students' home addresses for optional contact but uploads them to a cloud server without consent — risk of misuse. Ethical fix: collect only what is necessary, inform parents, and secure the data.
- Accuracy: A student’s grade is entered incorrectly in the school database, causing them to miss an award. Ethical action: correct the record, notify affected parties, and audit data-entry processes.
- Property: Copying and submitting code from the internet as your own in a programming assignment. Ethical approach: cite the source, respect license terms, or write original code.
- Accessibility: A teacher shares class PDFs that are not screen-reader friendly, excluding visually impaired students. Ethical remedy: provide accessible formats (tagged PDFs or text).
- Hacking/Unauthorized Access: A student guesses the teacher’s weak password to change marks. This is illegal and unethical — consequences and stronger authentication are required.
- Identity Theft: Using another student’s identity to join online tests or forums to avoid responsibility. Ethical/legal response: report and secure accounts with multifactor authentication.
- \[CIA triad (conceptual\]\[not numeric): Confidentiality + Integrity + Availability = core security goals\]
- \[Accuracy (%) = (Number of correct records / Total records checked) × 100\]
- \[Uptime (%) = (Total available time / Total scheduled time) × 100 — used to measure availability\]
- \[Simple risk model (qualitative): Risk ∝ Threat × Vulnerability × Impact (used to prioritize mitigation)\]
- \[Encryption strength (order estimate): Work to break ≈ 2^k operations for symmetric keys of length k (shows importance of key length)\]
Intellectual Property Rights (IPR)
Intellectual Property Rights (IPR)
Key Point: Copyrightability ≈ Originality + Fixation + Expression (not idea alone)
What are Intellectual Property Rights (IPR)?
Intellectual Property Rights are legal rights granted to creators and owners of works that are the result of human intellect — such as inventions, literary and artistic works, symbols, names, images, designs and industrial processes. IPR gives the owner exclusive rights to use, commercialize or authorize others to use their creation for a limited time.
Objectives of IPR
- Encourage innovation and creativity by giving creators a time-limited monopoly.
- Protect investments in research and development.
- Provide a legal framework to resolve disputes and prevent unauthorized use.
- Promote dissemination of knowledge through licensing and publication.
Main types of IPR (with short descriptions)
- Copyright — Protects original literary, musical, artistic works, films and computer programs. It covers expression, not ideas. (In India: Copyright Act, 1957.) Duration: life of author + 60 years (generally).
- Patent — Protects novel, non-obvious and industrially applicable inventions (products or processes). Grants exclusive rights to make, use or sell the invention for a fixed term. (In India: Patents Act, 1970.) Duration: 20 years from filing.
- Trademark — Protects signs, logos, words or combinations that distinguish goods or services of one enterprise from another. Renewable indefinitely (usually 10-year renewal terms). (In India: Trade Marks Act, 1999.)
- Industrial Design — Protects aesthetic or ornamental aspects of an article (shape, pattern, color). Duration varies (in India: initially 10 years + 5 years renewal = up to 15 years).
- Trade Secret — Information (formulas, practices, designs, processes) kept confidential to retain competitive advantage. Protection lasts as long as secrecy is maintained; no registration required.
- Geographical Indication (GI) — Identifies goods originating from a specific place that have a reputation or qualities due to that origin (e.g., Darjeeling tea). Duration: usually 10 years, renewable.
Key features and concepts
- Rights conferred — Exclusive rights to reproduce, sell, adapt, license, or prevent others from exploiting the protected work without permission.
- Registration vs automatic protection — Copyright arises automatically on creation and fixation; registration provides prima facie evidence. Patents, trademarks and designs require formal registration to enforce rights effectively.
- Infringement — Unauthorized use of protected material. Remedies include injunctions, damages, account of profits, and sometimes criminal penalties (depends on jurisdiction and IPR type).
- Limitations and exceptions — Fair dealing/fair use, compulsory licensing (for patents), freedom of expression and research exemptions. Indian law recognizes "fair dealing" for certain purposes like criticism, review, reporting, education and research.
IPR and software
- Computer programs are protected by copyright as literary works (source code and object code). Copyright protects expression of the code, not the underlying ideas or algorithms.
- Software patents are controversial: in India, "mathematical methods, business methods, algorithms per se" are not patentable, but inventions that apply software to a technical effect may be considered.
- Licenses determine use rights: proprietary (closed) licenses vs open-source licenses (GPL, MIT, Apache, Creative Commons). Choose license based on distribution and reuse goals.
How enforcement typically works
- Identify the right (copyright, patent, trademark etc.) and confirm ownership or registration.
- Send a cease-and-desist or take legal action (civil suit, criminal complaint where applicable).
- Courts may issue injunctions, award damages, or order account of profits. Administrative authorities can handle trademark oppositions and patent office proceedings.
Practical tips for students and developers
- Always check licenses before using code, images, music or datasets — attribute and comply with license terms.
- Use open-source software responsibly: follow copyleft terms (GPL) or permissive terms (MIT/Apache) as required.
- Protect your original classroom projects (keep drafts, timestamps) and consider registration for valuable works.
Note: IPR laws differ by country. For India-specific rules refer to the Indian Acts: Copyright Act 1957, Patents Act 1970, Trade Marks Act 1999, Designs Act 2000 and Geographical Indications of Goods (Registration and Protection) Act 1999.
- Copyright: A student writes a program and its source code is protected automatically; distributing it without permission infringes the author's copyright.
- Patent: A company patents a new method of battery charging (if novel and technical). They have exclusive rights for 20 years to commercialize it.
- Trademark: The Nike "Swoosh" and the word "Coca‑Cola" are registered trademarks that prevent others from using similar marks on related goods.
- Trade secret: Coca‑Cola's secret formula and KFC's recipe are examples of information protected as trade secrets.
- Open-source licensing: Linux (GPL) allows users to run, study, modify and redistribute code, but derivative works must also be GPL licensed; MIT license permits more permissive reuse.
- Geographical Indication: Darjeeling tea is protected as a GI—only tea from that region may use the name.
- \[Copyrightability ≈ Originality + Fixation + Expression (not idea alone)\]
- \[Patentability criteria: Patentable = Novelty + Inventive Step (Non-obviousness) + Industrial Applicability\]
- \[Trademark protection lifecycle: Registration → 10-year term → Renewable every 10 years → Indefinite protection (if renewed)\]
- \[Design protection timeline (India): Initial 10 years + Renewal 5 years = up to 15 years\]
- \[Trade Secret protection: Confidentiality maintained → Indefinite protection (no formal registration)\]
- \[Infringement test (simple): Does the use fall within the scope of exclusive rights? → If yes and no exception applies → Likely infringement\]
Software Piracy and Plagiarism
Software Piracy and Plagiarism
Key Point: Piracy rate (%) = (Number of pirated copies / Total copies in use) × 100
Introduction
Software piracy and plagiarism are violations of intellectual property rights and academic/ professional ethics. Software piracy is the unauthorized copying, distribution, or use of software. Plagiarism is presenting another person's code, documentation, or ideas as your own without correct attribution.
Software Piracy — Types
- End-user piracy: Installing one licensed copy on multiple machines (overuse) or copying from one computer to many (hard-disk loading).
- Internet piracy: Illegal downloads via torrents, file‑sharing, or cracked software sites.
- Counterfeiting: Selling packaged, fake copies that mimic genuine software CDs/boxes.
- OEM and site license violations: Misuse of original equipment manufacturer (OEM) or site licenses beyond permitted terms.
- Bootlegging: Unauthorized copying of live software demonstrations or proprietary builds.
Plagiarism in Computing
- Direct copy: Copying source code or documentation verbatim without credit.
- Source modification: Making small edits to someone else’s code but retaining the structure and logic.
- Self-plagiarism: Reusing your previous work in a new submission without disclosure.
Consequences
- Legal: Copyright law (penalties, fines, civil suits) and license enforcement.
- Economic: Revenue loss for developers and reduced incentive for innovation.
- Academic/professional: Penalties ranging from failed assignments to expulsion or job termination; damage to reputation.
Detection and Tools
Software piracy is tracked by audits, serial-key validation, and telemetry; plagiarism in code is detected by tools like MOSS, JPlag, and general text checkers like Turnitin. Version control history and timestamps also help establish authorship.
Prevention and Best Practices
- Use properly licensed software (FOSS where appropriate) and keep license records.
- Educate users and students about copyrights and citation norms.
- Apply technical measures: license keys, code obfuscation (with caution), update servers, and DRM only when justified.
- For assignments, require code comments, design documents, and repositories (with commit history) to show individual work.
- Always attribute and include license headers in shared code; follow open-source license terms when using third-party code.
Ethical Perspective
Beyond legal risks, piracy and plagiarism undermine trust, fairness, and the incentive structure that allows creators to be rewarded for their work. Respect for intellectual property fosters innovation and learning.
- A small company installs one licensed copy of a graphic editor on ten PCs (license overuse).
- A student copies a GitHub project into their submission without credit and changes variable names (plagiarism).
- A website offers paid software downloads with 'cracks' to bypass activation (internet piracy).
- A street vendor sells boxed copies of a commercial OS at a low price with counterfeit labels (counterfeiting).
- A developer copies a function from an open-source project but omits the original license and attribution (licensing violation).
- A classroom uses screenshots of a proprietary textbook chapter distributed as a PDF without permission (copyright infringement).
- \[Piracy rate (%) = (Number of pirated copies / Total copies in use) × 100\]
- \[Estimated revenue loss = Number of pirated copies × Retail price per copy\]
- \[Detection match (%) = (Number of matched lines or tokens / Total lines or tokens) × 100\]
- \[Average cost per infringement = Estimated total loss ÷ Number of proven infringements\]
Cyber Crimes
Cyber Crimes
Key Point: Cybercrime incidence rate (%) = (Number of reported cyber incidents / Total population or user base) × 100
Definition: Cyber crimes are illegal acts committed using computers, networks or the Internet to harm individuals, organisations or society. They exploit digital systems, data and communications.
Types (classification):
- Against persons: cyberstalking, cyberbullying, identity theft, online grooming.
- Against property/finance: online fraud, banking trojans, credit-card fraud, phishing, ransomware.
- Against data and systems: hacking, malware, DoS/DDoS attacks, data breaches, SQL injection.
- Against society/state: cyberterrorism, propaganda, information warfare, distribution of illegal content.
Common techniques / attack vectors: phishing emails and fake websites; malicious attachments; infected downloads; social engineering (manipulating people to reveal secrets); unpatched software exploits; weak or reused passwords; insecure Wi‑Fi or public networks.
Motives: financial gain (most common), political objectives, espionage, revenge, activism, or simply curiosity and notoriety.
Legal framework (India, brief): Information Technology Act, 2000 (IT Act) is the principal law dealing with cyber offences in India, with sections addressing unauthorised access, data tampering, identity theft, electronic forgery and obscene content. Cyber crimes are also tried under relevant sections of the Indian Penal Code (IPC) where applicable. Victims should report incidents to local cyber cells or the National Cyber Crime Portal (cybercrime.gov.in).
Consequences / impact: financial loss, reputational damage, loss of privacy, intellectual property theft, disruption of services, physical harm in critical infrastructure attacks.
Prevention and best practices:
- Use strong, unique passwords and enable two-factor authentication (2FA).
- Keep OS, applications and security software up to date.
- Be cautious with emails, links and attachments; verify senders.
- Use firewalls, antivirus/antimalware and encryption for sensitive data.
- Backup important data regularly and test restoration.
- Limit data sharing on social media; review privacy settings.
- Educate users about social engineering and safe browsing.
Ethical considerations: Responsible use of digital resources, respecting others' privacy and intellectual property, avoiding actions that may harm systems or people, and reporting vulnerabilities rather than exploiting them.
Study tips for Class 11: Learn common attack types and examples, understand legal/ethical implications, practise simple risk calculations (see formulas), and consider real incidents to see how prevention and legislation are applied.
- WannaCry ransomware (2017): A global ransomware outbreak that encrypted files on vulnerable Windows systems, demanding ransom payments and disrupting hospitals, businesses and government services.
- Equifax data breach (2017): Personal data (names, SSNs, birth dates) of millions exposed due to unpatched software, leading to identity theft risk and regulatory action.
- Phishing attack on bank customers: Fraudsters send convincing fake emails asking users to 'verify' credentials on a cloned bank site, harvesting login details to steal funds.
- NotPetya (2017): Malware that looked like ransomware but acted as a destructive wiper, causing widespread damage to firms worldwide.
- Cambridge Analytica (data misuse): Collection and misuse of Facebook users' personal data for political profiling and targeting.
- SIM swapping/identity theft: Attackers socially engineer or bribe telecom employees to port a victim's phone number, then bypass 2FA and access accounts.
- \[Cybercrime incidence rate (%) = (Number of reported cyber incidents / Total population or user base) × 100\]
- \[Percentage change in incidents = ((Incidents_year2 - Incidents_year1) / Incidents_year1) × 100\]
- \[Average loss per incident = Total reported loss in period / Number of incidents\]
- \[Expected loss (annual) = Probability of incident × Impact (monetary loss if incident occurs)\]
- \[Risk score (simple) = Threat likelihood × Vulnerability level × Asset value (use normalized scales for calculation)\]
Legal Framework and Cyber Laws
Legal Framework and Cyber Laws
Key Point: CIA triad: Confidentiality + Integrity + Availability = Basic objectives of cybersecurity
Overview
The legal framework for cyber laws covers statutes, rules and judicial decisions that regulate electronic communication, protect data and punish cybercrime. It balances promoting digital transactions and protecting citizens from misuse of technology. For Class 11 Computer Science, the focus is on basic rights and duties, common offences, relevant laws, investigation and prevention.
Key concepts
- Cyber law: Legal rules that apply to the internet, computers, networks and electronic data.
- Cybercrime: Any criminal activity where computers or networks are used as tools, targets or places of criminal activity (e.g., hacking, phishing, identity theft).
- Cyber security: Practices and technologies to protect confidentiality, integrity and availability of information (CIA triad).
Important elements of the legal framework (India)
- Information Technology Act, 2000: Primary statute dealing with electronic records, digital signatures, admissibility of electronic evidence and many cyber offences. It has been amended to address new threats.
- Intermediary Guidelines and Digital Media Rules: Define due diligence and responsibilities of intermediaries (social media platforms, ISPs).
- Digital Personal Data Protection Act, 2023: Rules for processing personal data, obligations on data fiduciaries and rights of data principals (users).
- Indian Penal Code & Evidence Act: Many cyber offences overlap with traditional crimes (cheating, defamation, criminal intimidation) and rules on electronic evidence were updated for admissibility.
- Cert-In and other agencies: Computer Emergency Response Team (CERT-In) provides cyber security alerts and incident reporting mechanisms.
Common cyber offences
- Unauthorized access/hacking of systems
- Phishing and online fraud
- Identity theft and financial fraud
- Ransomware and malware attacks
- Cyberstalking and cyberbullying
- Online defamation and hate speech
- Copyright and IP violations (piracy)
- Cyber terrorism and attacks on critical infrastructure
Legal concepts students should know
- Electronic contract: Valid if it satisfies offer, acceptance, consideration and consent rules even when done electronically.
- Digital signature & authentication: Ensures authenticity and integrity of electronic documents. Public key infrastructure (PKI) is often used.
- Intermediary liability: Platforms may have limited liability if they follow due diligence rules and remove illegal content when notified.
- Jurisdiction & cross-border issues: Cyber offences often involve multiple countries; international cooperation and mutual legal assistance are important.
- Admissibility of electronic evidence: Electronic records can be produced in court provided proper authentication and chain of custody are maintained.
Investigation and remedies
- Victims should preserve evidence (screenshots, logs) and report to local police or designated cyber cells / CERT-In.
- Complaints can lead to criminal prosecution, monetary compensation, takedown orders or blocking of content.
- Companies must follow breach notification rules and data protection obligations under the applicable law.
Prevention & good practices
- Use strong, unique passwords and two-factor authentication.
- Be cautious with links and attachments to avoid phishing and malware.
- Protect personal data; share only when necessary and on trusted platforms.
- Install updates and antivirus software; backup important data.
- Schools should teach digital citizenship, responsible use and legal consequences of misuse.
Why this matters
Legal protections enable safe electronic commerce, protect privacy and provide remedies when rights are violated. Understanding cyber laws helps students make responsible choices online and recognize when to seek help.
- Phishing email impersonates a bank, user provides credentials and money is transferred from bank account. Offence: fraud and identity theft. Remedy: Report to bank, file police/Cyber Cell complaint, preserve emails, follow bank's dispute process.
- Ransomware attack on a school server encrypts student records. Offence: unauthorized access and extortion. Remedy: Report to CERT-In/police, disconnect affected systems, restore from backups, notify affected persons if personal data exposed.
- Student posts harmful, false statements about a classmate on social media. Offence: cyberbullying/defamation. Remedy: Take screenshots, request removal from platform, file complaint with police or cyber cell; platform may remove content under intermediary rules.
- An online seller refuses to honor an electronic contract for purchase. Legal point: Electronic contracts are enforceable if offer, acceptance and consideration are present. Remedy: Raise grievance with consumer forum / civil court using electronic evidence (emails, order confirmations).
- Use of digital signatures to file income tax or submit school forms. Legal point: Digital signatures provide authenticity and are admissible as evidence under law.
- \[CIA triad: Confidentiality + Integrity + Availability = Basic objectives of cybersecurity\]
- \[Valid Electronic Contract = Offer + Acceptance + Consideration + Intention to create legal relations + Capacity + Free Consent\]
- \[Elements of many cyber offences = Action (hacking/unauthorized access) + Mens rea (intent) + Result (data theft/damage)\]
- \[Digital signature verification (conceptual): Verify(public_key\]\[signature\]\[data) -> if true then authenticity && integrity ensured\]
- \[Chain of custody shorthand for electronic evidence: Collect -> Preserve -> Authenticate -> Produce in court\]
- \[Intermediary safe-harbour checklist: Follow due diligence + No active role in content + Remove illegal content upon notice = Limited liability\]
Data Protection and Privacy
Data Protection and Privacy
Key Point: Encryption notation: C = E_k(P) and P = D_k(C) (C = ciphertext, P = plaintext, E_k = encryption with key k, D_k = decryption with key k).
Definition: Data protection and privacy refers to the legal, technical and organizational measures taken to ensure personal and sensitive information is collected, stored, processed and shared in ways that respect individuals' rights and prevent misuse, unauthorized access, loss or disclosure.
Why it matters:
- Protects individuals from identity theft, financial loss, discrimination and reputational harm.
- Builds trust between users and organisations that handle personal data.
- Is required by laws and regulations (e.g., GDPR, DPDP/IT Act in India) — noncompliance can cause heavy penalties.
Core principles (common to most data protection frameworks):
- Lawfulness, fairness and transparency: Collect and use data only with a legal basis and inform data subjects.
- Purpose limitation: Use data only for the purposes specified at collection.
- Data minimization: Collect only the data necessary for the purpose.
- Accuracy: Keep data accurate and up to date.
- Storage limitation: Retain data only as long as needed.
- Integrity and confidentiality: Protect data against unauthorized access and breaches.
- Accountability: Organisations must be able to show compliance.
Technical and organisational safeguards:
- Encryption: Convert data into unreadable form (ciphertext) so only authorised parties can read it.
- Access control: Role-based access, least privilege, strong authentication (passwords + MFA).
- Anonymization and pseudonymization: Remove or mask identifiers to reduce re-identification risk.
- Hashing: Use one-way functions for storing passwords or verifying integrity.
- Secure transmission: Use TLS/HTTPS for data in transit.
- Backups, logging and monitoring: Maintain logs, detect intrusions, and restore data after incidents.
- Policies and training: Clear data-handling policies and employee training to avoid human error (e.g., phishing).
Legal aspects and rights: Data protection laws give rights such as consent, access to one’s data, correction, deletion (right to be forgotten), restriction of processing and data portability. Organisations must often report breaches to authorities and affected individuals.
Common threats and breaches: Identity theft, phishing, ransomware, accidental disclosure (mis-sent emails), insider misuse, insecure third-party services, weak passwords.
Best practices (Individuals): Use strong unique passwords, enable two-factor authentication, limit sharing of personal data, review app permissions, clear cookies and privacy settings.
Best practices (Organisations): Apply privacy-by-design, perform data protection impact assessments, keep software patched, use encryption, limit data retention, appoint a data protection officer where required.
Summary: Data protection and privacy combine legal rights, ethical principles and technical controls to safeguard personal information. Understanding the lifecycle of data, reducing unnecessary collection, and applying strong technical controls are key to protecting individuals and organisations.
- Social media: A user posts personal details publicly and later faces targeted scams — demonstrates need for default privacy settings and user awareness.
- E-commerce site stores card details insecurely; a breach exposes customers' payment info — shows importance of encryption and PCI-compliant storage.
- Hospital data breach: Medical records leaked due to weak access controls — sensitive health data requires strict confidentiality and audit trails.
- Mobile apps tracking location and sharing with ad networks without explicit consent — illustrates transparency and purpose-limitation violations.
- Phishing attack: An employee clicks a malicious link and reveals corporate credentials, enabling attackers to access customer data — highlights need for training and MFA.
- Government ID databases (e.g., national ID systems): improper data sharing or weak APIs can risk mass privacy violations — need for legal safeguards and technical hardening.
- \[Encryption notation: C = E_k(P) and P = D_k(C) (C = ciphertext\]\[P = plaintext\]\[E_k = encryption with key k\]\[D_k = decryption with key k).\]
- \[Password entropy (approximate Shannon entropy): H = - Σ p_i * log2(p_i) (higher H means stronger\]\[less guessable password).\]
- \[Breach rate (%) = (Number of breached records / Total records stored) × 100%\]
- \[Risk (qualitative) ≈ Threat × Vulnerability × Impact (used to prioritise mitigation efforts).\]
- \[k-anonymity concept (privacy metric): every combination of quasi-identifiers appears at least k times in the dataset (no explicit numeric formula but a requirement: |group(qi)| ≥ k).\]
Digital Signatures, Encryption and Security Technologies
Digital Signatures, Encryption and Security Technologies
Key Point: Symmetric encryption/decryption: C = E_K(M), M = D_K(C) (K is the shared secret key, M plaintext, C ciphertext)
Overview
Digital signatures, encryption and related security technologies protect data confidentiality, integrity, authenticity and non-repudiation in digital communication and storage. These techniques are the foundation of secure e-mail, online banking, software distribution, e‑governance and many other services users rely on every day.
Encryption
- Purpose: transform readable data (plaintext) into an unreadable form (ciphertext) so only authorized parties can recover it.
- Symmetric (secret‑key) encryption: same key is used to encrypt and decrypt. Fast and used for bulk data. Examples: AES, DES, 3DES. Use case: encrypting files on a disk or communication within an encrypted channel once a session key is shared.
- Asymmetric (public‑key) encryption: uses a key pair — a public key for encryption (or verification) and a private key for decryption (or signing). Slower, used for key exchange, digital signatures and small payloads. Examples: RSA, ECC.
- Hybrid approach: common practical method: use asymmetric encryption to securely exchange a symmetric session key, then use symmetric encryption (AES) for the data.
Hash functions
- A hash function maps data of arbitrary size to a fixed‑length output (digest). Good cryptographic hashes are one‑way (fast to compute, infeasible to invert), collision resistant (hard to find two inputs with the same digest) and sensitive to input changes.
- Examples: SHA‑256 (secure, widely used), MD5 (broken for collision resistance).
Digital signatures
- Purpose: prove the origin (authenticity) of data, ensure integrity, and provide non‑repudiation (sender cannot deny having signed).
- How it works (high level): the sender hashes the message to create a digest, encrypts (signs) the digest using their private key to produce a signature, and sends message + signature. The receiver hashes the received message and uses the sender's public key to decrypt the signature; if the decrypted signature equals the computed hash, the signature is valid.
- Digital signatures depend on secure key management and trustworthy public key distribution (see PKI below).
Public Key Infrastructure (PKI) and Certificates
- PKI is a system that binds public keys to identities using digital certificates issued by Certificate Authorities (CAs). An X.509 certificate contains a public key, subject identity, validity period and CA signature.
- Web browsers and operating systems trust a set of root CAs. TLS/HTTPS uses certificates so browsers can confirm a website's identity and establish an encrypted connection.
TLS/SSL (example of applied technologies)
- TLS secures web traffic. Simplified handshake: ClientHello → ServerHello + Certificate → (key exchange) → both derive shared session key → encrypted communication. The certificate assures the client it is talking to the real server.
Other security technologies
- Firewalls: filter traffic between networks based on rules.
- Antivirus / anti‑malware: detect and remove malicious software.
- Intrusion Detection/Prevention Systems (IDS/IPS): monitor networks/applications for attacks.
- VPNs: create an encrypted tunnel between endpoints.
- Two‑factor (multi‑factor) authentication (2FA/MFA): combines something you know (password) with something you have (token) or are (biometrics).
- Access control and least privilege: users/processes get only the rights needed.
- Steganography (related): hiding information inside other files (images, audio) — not encryption, but used for covert transfer.
Security properties and best practices
- Use strong, up‑to‑date algorithms (e.g., AES‑256, RSA with sufficiently large keys or ECC) and current protocols (TLS 1.2/1.3).
- Protect private keys (hardware security modules, secure enclaves, encrypted storage).
- Keep software updated, use principle of least privilege and enforce MFA for sensitive accounts.
- Verify certificates and avoid self‑signed certificates in production unless trusted explicitly.
Class‑11 level summary
Encryption ensures confidentiality; hashing ensures integrity; digital signatures ensure authenticity and non‑repudiation. PKI and certificates provide a trust model for public keys. Practical systems combine these technologies to secure everyday services like HTTPS, signed software, and secure e‑mail.
- HTTPS web browsing: When you visit your bank's website, TLS uses the bank's certificate (issued by a CA) to verify identity; a session key (symmetric) is negotiated and used to encrypt data like passwords and transactions.
- Email signing and encryption (S/MIME or PGP): You can sign an email with your private key so recipients verify it came from you and the content wasn't changed; encryption with the recipient's public key ensures only they can read it.
- Software distribution: Developers sign application installers. When you download software, your system verifies the signature before installation to ensure the package wasn't tampered with.
- Instant messaging end‑to‑end encryption (e.g., Signal or WhatsApp): Each user has key pairs; messages are encrypted so only the intended recipient can decrypt them.
- File encryption: Use AES to encrypt sensitive files stored on a laptop or cloud so that stolen devices or compromised storage cannot reveal data without the key.
- \[Symmetric encryption/decryption: C = E_K(M)\]\[M = D_K(C) (K is the shared secret key\]\[M plaintext\]\[C ciphertext)\]
- \[RSA key generation: n = p * q, φ(n) = (p−1)(q−1)\]\[choose e such that gcd(e, φ(n)) = 1\]\[find d such that e * d ≡ 1 (mod φ(n)).\]
- \[RSA encryption/decryption: C = M^e mod n\]\[M = C^d mod n\]
- \[Digital signature (RSA style): Signature S = H(M)^d mod n\]\[Verification: compute H(M) and check H(M) ?= S^e mod n (using signer’s public key e\]\[n).\]
- \[Hash function (informal): H = hash(M)\]\[small change in M ⇒ completely different H. (No algebraic formula — properties: one‑way\]\[collision resistant\]\[fixed length.)\]
Cyber Security Measures and Best Practices
Cyber Security Measures and Best Practices
Key Point: Risk ≈ Likelihood × Impact — (qualitative formula used to prioritize security efforts).
Introduction
Cyber security refers to the practices, technologies, and processes designed to protect networks, devices, programs and data from attack, damage or unauthorized access. For students and organizations, cyber security is essential to protect personal information, academic records, financial data and digital infrastructure.
Core Principles
- Confidentiality – ensuring information is accessible only to authorized users.
- Integrity – ensuring information is accurate and unaltered.
- Availability – ensuring information and resources are available when needed.
Common Threats
- Phishing and social engineering (fraudulent emails/links to steal credentials)
- Malware: viruses, worms, Trojans, ransomware
- Man-in-the-middle attacks and eavesdropping
- Denial-of-Service (DoS) attacks
- Unauthorized access due to weak passwords or misconfigured systems
Practical Security Measures & Best Practices
- Strong, unique passwords – use long passphrases and avoid reuse. Prefer password managers to store credentials securely.
- Multi-factor authentication (MFA) – combine something you know (password) with something you have (OTP, authenticator app) or something you are (biometrics).
- Keep software updated – apply OS, browser, and application patches promptly to fix vulnerabilities.
- Use antivirus/endpoint protection and enable real-time scanning and automatic updates.
- Secure networks – use WPA3/WPA2 on Wi‑Fi, change default router passwords, and avoid public Wi‑Fi for sensitive transactions (or use a VPN).
- Backups – keep regular, offline and offsite backups of important data; test restore procedures.
- Encryption – use HTTPS for websites, enable full-disk encryption on devices, and encrypt sensitive files in transit and at rest.
- Least privilege & access control – give users only the permissions they need; use role-based access control (RBAC).
- Secure development practices – validate inputs, sanitize data to prevent injection attacks, and follow secure coding standards.
- Incident response & reporting – have a plan to detect, contain, eradicate and recover from breaches; report incidents to relevant authorities if required.
- Awareness & training – educate users about phishing, safe browsing, and social engineering tactics.
- Data classification & retention – classify data by sensitivity and apply appropriate controls; dispose of data securely when no longer needed.
- Legal and ethical responsibilities – comply with laws (for example, India’s IT Act provisions and privacy regulations) and respect user privacy and intellectual property.
How these measures work together
Good cyber security is layered (defense-in-depth): technical controls (firewalls, encryption), administrative controls (policies, training), and physical controls (secure premises). Layering reduces the chance that a single failure leads to a major breach.
Student-level practical tips
- Enable MFA on email and social accounts.
- Use a reputable password manager and create unique passwords for each account.
- Don’t click suspicious links; verify senders before sharing personal information.
- Regularly back up school projects and notes to an encrypted cloud or external drive.
- Keep mobile OS and apps updated; only install apps from trusted stores.
Summary
Cyber security is an ongoing process that combines technical tools, secure habits, policy and awareness. Following the best practices above reduces risk of data loss, identity theft and disruption to systems.
- WannaCry ransomware (2017): infected computers worldwide by exploiting a Windows vulnerability, encrypting files and demanding ransom. Lesson: apply patches and keep backups.
- Phishing email that mimics a bank asking to 'verify' account details: users who click malicious links may expose login credentials. Lesson: verify sender, check URLs, enable MFA.
- Social media credential reuse: attacker reuses leaked password from one site to access the same user’s email, causing identity theft. Lesson: use unique passwords and a password manager.
- Public Wi‑Fi eavesdropping: an attacker on the same unsecured Wi‑Fi intercepts unencrypted traffic to capture login cookies. Lesson: prefer HTTPS, use VPNs on public networks.
- \[Risk ≈ Likelihood × Impact — (qualitative formula used to prioritize security efforts).\]
- \[Password entropy (bits) ≈ L × log2(N) — where L = password length\]\[N = number of possible characters per position\]\[Higher entropy = stronger password.\]
- \[Brute-force attempts ≈ 2^(entropy bits) — approximate number of guesses needed on average to exhaust keyspace\]\[doubling entropy doubles exponent base.\]
- \[Protection coverage (simple view) = 1 - Π(1 - p_i) — where p_i are probabilities that independent controls stop an attack\]\[Shows layered defenses increase overall protection.\]
Cyber Forensics and Investigation
Cyber Forensics and Investigation
Key Point: Hash function notation: H(message) = digest. Example: SHA-256(file) = 256-bit digest used to verify integrity.
What is Cyber Forensics?
Cyber forensics (also called digital forensics) is the practice of identifying, collecting, preserving, analysing and presenting digital evidence in a way that is legally acceptable. It applies scientific and investigative techniques to computers, networks, mobile devices, cloud services and other digital media to discover what happened, who was involved and how to prevent a recurrence.
Why it matters
- Helps solve cybercrimes (hacking, fraud, identity theft, intellectual property theft).
- Supports legal proceedings by preserving admissible evidence.
- Enables organizations to respond to incidents and recover systems safely.
Core phases of a digital forensic investigation
- Identification: Detect affected systems and sources of potential evidence (computers, phones, logs, cloud accounts).
- Preservation: Protect evidence from alteration. Use write-blockers, take memory dumps, secure devices.
- Collection (Acquisition): Create bit‑for‑bit images of storage, capture volatile memory, collect logs and network captures—always document steps.
- Examination: Use tools to extract files, recover deleted data, parse logs, reconstruct timelines, decode artifacts.
- Analysis: Interpret findings to determine sequence of events, attribution, and impact. Correlate evidence from different sources.
- Presentation/Reporting: Produce a clear report and evidence chain for stakeholders and courts. Explain methods, tools and conclusions.
Types of evidence
- Storage data: hard drives, SSDs, USB drives, memory cards.
- Volatile data: RAM, running processes, open network connections.
- Network evidence: packet captures (PCAP), firewall/IDS logs, server logs.
- Mobile and IoT artifacts: app data, SMS, GPS logs, call history.
- Cloud and social media: snapshots of cloud storage, account activity logs, posts and messages.
Key principles and legal/ethical aspects
- Chain of custody: Record who handled evidence, when and why. Without it, admissibility may be lost.
- Integrity: Use cryptographic hashes to prove images are unaltered.
- Authorization: Obtain appropriate warrants or permissions before seizing devices (unless exigent circumstances).
- Minimal handling: Avoid changing evidence; work on copies whenever possible.
- Privacy and ethics: Limit analysis to scope of investigation and respect privacy laws.
Common tools
- Imaging and analysis: Autopsy/Sleuth Kit, EnCase, FTK.
- Memory forensics: Volatility, Rekall.
- Network analysis: Wireshark, tcpdump.
- Mobile forensics: Cellebrite, MSAB, open-source mobile tools.
Practical precautions
- Document every action in a log with timestamps.
- Always work on copies (forensic images) and keep originals secured and sealed.
- Capture volatile data first (RAM, active network connections) because it is lost on shutdown.
- Note time zones and clock skew when building timelines.
Limitations
Forensics cannot always attribute an action to a person beyond reasonable doubt (e.g., shared accounts, spoofing). Encryption, anti-forensic methods and cloud/distributed architectures make investigations harder.
Summary
Cyber forensics combines technical methods and legal procedures to collect, analyse and present digital evidence. Good forensic practice follows strict documentation, uses cryptographic hashes and chain-of-custody procedures, and respects legal limits. It is an essential part of incident response, law enforcement and corporate governance.
- Ransomware attack (WannaCry, May 2017): Forensic analysts imaged infected systems, examined ransom notes and network traffic, traced attack vectors (EternalBlue exploit), and collected indicators of compromise for containment and recovery.
- Data breach investigation (Equifax, 2017): Forensics used server logs and application artifacts to determine how attackers accessed sensitive data and estimate affected records.
- Insider theft: An employee copies proprietary designs to a USB drive. Investigators create disk images, recover deleted files, check USB connection logs and present the timeline linking the employee to the act.
- Phishing/fraud: Analysts examine email headers, message sources, and payloads to identify phishing infrastructure and trace fraudulent transactions to compromised accounts.
- Mobile forensics: In a harassment case, examiners extract messages, call logs and GPS data from a phone backup to corroborate timelines and locations.
- Network intrusion: Packet capture (PCAP) analysis reveals unusual outgoing connections; correlation with server logs shows data exfiltration and the affected accounts.
- \[Hash function notation: H(message) = digest\]\[Example: SHA-256(file) = 256-bit digest used to verify integrity.\]
- \[Digital signature (conceptual): Signature = Sign_private( H(message) )\]\[Verify_public(Signature) ?= H(message)\]\[If equal\]\[signature valid.\]
- \[Collision probability (approx.): For an n-bit hash\]\[uniform collision chance ~ 1 / 2^n. (E.g.\]\[SHA-256: ~1/2^256 — practically negligible.)\]
- \[Brute-force keyspace/time estimate: Time ≈ 2^n / attempts_per_second. (n = key bits\]\[e.g.\]\[for 64-bit key and 10^9 attempts/s\]\[Time ≈ 2^64/10^9 seconds.)\]
- \[Shannon entropy (for passwords\]\[conceptual): H = -Σ p_i log2(p_i)\]\[Higher H → harder to guess.\]
E‑commerce, Online Transactions and Consumer Protection
E‑commerce, Online Transactions and Consumer Protection
Key Point: Conversion rate (%) = (Number of purchases / Number of website visitors) × 100
What is E‑commerce? E‑commerce means buying and selling goods or services and transferring money and data over electronic networks, primarily the Internet. It includes web stores, mobile apps, online marketplaces, digital services, and electronic payments.
Online transactions are the payment and data exchanges that complete an e‑commerce purchase: product selection, payment authorization, order confirmation, fulfillment and delivery, and after‑sales support. Secure transaction technologies (HTTPS/SSL‑TLS, encryption, tokenization, two‑factor authentication, PCI‑DSS compliance) protect confidentiality and integrity.
Key stakeholders: buyers (consumers), sellers (merchants), payment processors/gateways, banks, delivery/logistics providers, and intermediaries/platforms (marketplaces, hosting providers).
Risks and ethical/legal issues: fraud (phishing, card‑not‑present attacks), identity theft, counterfeit/fake products, misleading advertising, unfair terms (hidden charges), privacy breaches and data misuse, unfair cancellation/return policies, and disputes over refunds or delivery.
Consumer protection framework (India context): Consumer Protection Act, 2019; Consumer Protection (E‑commerce) Rules, 2020; Information Technology Act, 2000 (liability of intermediaries, data aspects); Payment Card Industry Data Security Standard (PCI‑DSS) and RBI/UPI guidelines for payments. E‑commerce rules require display of seller details, return/refund policy, and appointment of a grievance officer with contact details.
Consumer rights in e‑commerce include the right to be informed (accurate product info), right to safety (safe products), right to choose (fair competition), right to be heard (grievance redressal), and right to seek redressal (refund, replacement, compensation). Platforms must provide clear terms, grievance officer contact, and means to file complaints.
Practical protections and good practices: use HTTPS sites, check seller ratings and reviews, prefer reputed payment methods (UPI, trusted wallets, card gateways), enable 2FA and strong passwords, verify return/refund and warranty policies, keep transaction receipts and screenshots, monitor bank statements, and report fraud promptly. Sellers should publish transparent policies, secure user data, and comply with regulations.
Dispute resolution: try first to resolve with the seller/platform (grievance officer). If unresolved, escalate to banking chargeback, file complaint on consumer portals (e.g., National Consumer Helpline), or initiate proceedings in Consumer Dispute Redressal Commissions (district/state/national levels) depending on value and jurisdiction.
- Buying a phone on an online marketplace: Customer places order, pays via UPI or card, receives order tracking, inspects product on delivery, and requests return within the seller's return window if defective.
- Subscription renewal fraud: A user receives a fake email claiming subscription renewal and clicks a phishing link. The attacker captures payment details—prevented by verifying sender and checking card statements.
- Chargeback case: A buyer receives a counterfeit handbag instead of the branded product; buyer files a dispute with the card issuer and requests a chargeback while contacting the marketplace for refund.
- Digital service purchase: Paying for an online course—consumer must ensure refund policy and that access credentials are received and protected; disputes may be handled under e‑commerce rules if service is not delivered.
- UPI payment safety: User enables UPI PIN and 2FA on the app; avoids sharing OTP/PIN and checks beneficiary details before confirming payment to prevent transfer fraud.
- \[Conversion rate (%) = (Number of purchases / Number of website visitors) × 100\]
- \[Average order value (AOV) = Total revenue / Number of orders\]
- \[Cart abandonment rate (%) = (1 - (Number of completed purchases / Number of carts initiated)) × 100\]
- \[Transaction success rate (%) = (Successful transactions / Total transaction attempts) × 100\]
- \[Chargeback rate (%) = (Number of chargebacks / Total transactions) × 100\]
Responsibilities and Liabilities of Users and Organisations
Responsibilities and Liabilities of Users and Organisations
Key Point: Negligence (legal) = Duty of care + Breach of duty + Causation + Damage
Overview
Responsibilities and liabilities in computing describe what users and organisations must do to behave legally and ethically, and what they may be held accountable for if they fail to meet those duties. These concepts cover data privacy, cyber security, intellectual property, ethical behaviour and legal compliance.
Responsibilities of Users
- Lawful and ethical use: Use software, content and services according to licence terms and copyright law. Do not pirate software or plagiarise content.
- Data protection and privacy: Respect other people's personal information — do not share or expose private data without consent.
- Security hygiene: Use strong passwords, enable multi-factor authentication, keep devices and software updated, avoid suspicious links and attachments.
- Reporting incidents: Notify appropriate authorities or organisation security teams when breaches, fraud or suspicious activities are discovered.
- Respecting policies: Follow workplace/school acceptable-use policies, terms of service and internet usage rules.
Responsibilities of Organisations
- Legal compliance: Follow applicable laws (for example, the Information Technology Act, 2000 in India; GDPR in EU) regarding data protection, cybercrime reporting and record-keeping.
- Data protection measures: Implement technical and organisational measures—encryption, access controls, backups, secure development practices—to protect personal and sensitive data.
- Privacy transparency: Publish privacy policies telling users what data is collected, why, how long it is stored and with whom it is shared.
- Employee training: Educate staff on security best practices, phishing, social engineering and legal obligations.
- Incident response: Maintain an incident response plan to detect, contain, remediate and report breaches in defined timelines.
- Third-party management: Ensure vendors and partners meet security and privacy standards (through contracts and audits).
Types of Liability
- Civil liability: Organisations or users may be required to pay compensation for losses caused by negligence, breach of contract, or unauthorized use of data/intellectual property.
- Criminal liability: Certain acts (hacking, identity theft, publishing obscene content, unauthorised access) can attract criminal prosecution and penalties under relevant laws.
- Vicarious liability: An organisation can be held responsible for wrongful acts of its employees carried out in the course of employment.
- Strict liability and regulatory fines: Under some privacy laws, organisations may be fined for data breaches even if negligence is not proven (e.g., large fines under GDPR for inadequate protection).
When Liability Arises — key factors
- Duty of care: Was there an obligation to protect data or prevent harm?
- Breach of duty: Were reasonable steps taken, or was there negligence?
- Causation and damage: Did the breach cause measurable harm (financial loss, privacy invasion, reputation damage)?
- Statutory provisions: Do laws specify penalties or mandatory reporting (e.g., Section 43 of the IT Act covers compensation for damage to computer systems)?
Practical consequences and best practices
- For users: Keep credentials private, respect licences, read privacy notices, report security issues promptly.
- For organisations: Do regular risk assessments, maintain logs, encrypt sensitive data, conduct security audits, create clear contracts with vendors, and follow legal breach-notification timelines.
Summary
Responsibilities are proactive duties: follow laws, protect data, act ethically. Liabilities are the legal and financial consequences if duties aren’t met. Good governance, training and technical controls reduce risk of both breaches and liability.
- An employee clicks a phishing link that exposes customer data. The organisation faces regulatory fines and must notify affected customers — demonstrating vicarious and organisational liability for weak training and controls.
- A student installs pirated software on a school computer. The student is breaching software licence terms and school policy — personal responsibility and possible disciplinary action.
- A social media platform collects personal information without clear consent. Regulators investigate for privacy violations (possible fines under data-protection laws like GDPR).
- A hospital fails to encrypt patient records and a hacker leaks them. The hospital may be liable for negligence, must compensate victims, and may be penalised under health-data protection rules.
- An organisation hires a vendor whose insecure cloud storage exposes customer records. The hiring organisation can be held accountable if it failed to vet the vendor properly — illustrating third-party risk management responsibility.
- A developer publishes copyrighted images without permission in a mobile app. The copyright owners sue for infringement — showing individual and organisational liability for IP violations.
- \[Negligence (legal) = Duty of care + Breach of duty + Causation + Damage\]
- \[Risk = Threat × Vulnerability × Impact (used in security risk assessment)\]
- \[Security Goals: Confidentiality + Integrity + Availability = Basic security objectives (CIA triad)\]
- \[Vicarious liability principle: Employer liability if wrongful act is committed by employee while acting in course of employment\]
E‑waste and Environmental Ethics
E‑waste and Environmental Ethics
Key Point: Total e‑waste generated (mass/year) = Σ (number of disposed devices × average mass per device)
What is E‑waste?
E‑waste (electronic waste) means discarded electrical and electronic equipment and their components and consumables that are no longer wanted. Examples: mobile phones, laptops, printers, refrigerators, batteries, circuit boards.
Why it matters
E‑waste contains valuable materials (gold, copper, rare earths) and hazardous substances (lead, mercury, cadmium, brominated flame retardants, PCBs). If handled improperly, these toxic elements pollute soil, air and water and cause serious health problems for workers and communities.
Environmental and health impacts
- Soil and water contamination from leached heavy metals.
- Air pollution from open burning of cables and plastics releasing dioxins and furans.
- Direct human exposure to toxic metals causing neurological, respiratory and reproductive harm.
- Resource depletion: lost opportunity to recover valuable metals and reduce mining impacts.
Environmental ethics — the moral questions
- Responsibility: Who is responsible for safe disposal — manufacturers, consumers, governments, or informal recyclers?
- Intergenerational justice: Are we leaving a toxic legacy for future generations?
- Precautionary principle: When a technology may cause harm, precautionary measures should be taken even if full scientific certainty is lacking.
- Polluter‑pays principle: Parties that produce pollution should bear the costs of managing it to prevent damage.
- Right to a healthy environment: Communities (often poor) near informal recycling sites are disproportionately affected.
Solutions and ethical practices
- Reduce and design for longevity: Ethical product design emphasizes durability, repairability and modular upgrades.
- Reuse and refurbishment: Extending device life reduces total e‑waste generated.
- Formal recycling and safe treatment: Certified facilities use mechanical separation, controlled smelting and proper disposal of hazardous fractions.
- Extended Producer Responsibility (EPR): Producers take-back and manage end‑of‑life treatment — shifts responsibility upstream.
- Public awareness and consumer responsibility: Proper drop‑off, data wiping and choosing repairable products.
- Legal frameworks and enforcement: Standards for collection, recycling, export controls and worker safety.
Role of Computer Science students
Students should learn safe disposal practices, support recycling drives, design software/hardware with energy efficiency and upgradability in mind, and understand data privacy issues when discarding digital devices.
Key takeaways
E‑waste is both an environmental and ethical issue. Responsible manufacturing, informed consumer choices, effective laws (like EPR), and safe recycling practices reduce harm and conserve resources.
- Agbogbloshie, Ghana: a large informal e‑waste recycling site where informal burning of cables and extraction of metals causes severe pollution and health problems.
- Informal recycling clusters in parts of India, China and other countries where e‑waste is dismantled by hand without protective equipment, exposing workers to toxins.
- Manufacturer take‑back programs: some electronics companies offer trade‑in or recycling schemes under Extended Producer Responsibility to collect and recycle old devices responsibly.
- School or college e‑waste drive: students collect old phones and laptops for secure data wiping and refurbishment or handover to certified recyclers.
- Repair cafés and right‑to‑repair initiatives: community programs that teach and enable repairing devices to extend their life and reduce waste.
- \[Total e‑waste generated (mass/year) = Σ (number of disposed devices × average mass per device)\]
- \[Per capita e‑waste (kg/person/year) = Total e‑waste generated (kg/year) / Population\]
- \[Recycling rate (%) = (Mass recycled / Total e‑waste generated) × 100\]
- \[Average device lifespan (years) = Total years in use across devices / Number of devices — use this to estimate replacement frequency\]
- \[Material recovery efficiency (%) = (Mass of recovered valuable material / Mass of that material in input e‑waste) × 100\]
Social Issues and Emerging Ethical Challenges
Social Issues and Emerging Ethical Challenges
Key Point: Risk ≈ Probability × Impact — simple risk assessment formula used to prioritise security controls.
Overview
Social issues and emerging ethical challenges in computing are concerned with how information technology affects individuals, groups and society, and with the moral questions that arise from designing, deploying and using computing systems. This topic covers privacy, security, intellectual property, digital divide, cybercrime, health and social impacts, and new challenges from AI, big data, surveillance and automation.
Core ethical principles
- Confidentiality – keeping personal and sensitive information private.
- Integrity – ensuring data and systems are accurate and unaltered without authorization.
- Availability – ensuring authorized users can access systems and data when needed.
- Accountability – actors should be responsible for their actions in cyberspace.
- Fairness & non‑discrimination – systems should not produce biased or unjust outcomes.
- Transparency & explainability – users should be able to understand or get reasons for important automated decisions.
- Consent – individuals should be able to choose how their data is collected and used.
Major social issues
- Privacy and surveillance: collection, storage and secondary use of personal data (location, health, biometrics). Concerns include unauthorized access and government or corporate surveillance.
- Cybercrime and security: hacking, identity theft, phishing, ransomware and other malicious activities that harm individuals, businesses and infrastructures.
- Intellectual property (IP): copyright, software piracy, fair use and licensing of digital content and code.
- Digital divide: unequal access to technology and the internet across socio‑economic, geographic and demographic groups, leading to unequal opportunities.
- Social & mental health impacts: cyberbullying, addiction to social media/gaming, misinformation and social polarization.
- Automation and employment: job displacement and skill shifts due to robotics, AI and automated decision systems.
Emerging ethical challenges
- AI bias and fairness: machine learning models can replicate or amplify societal bias when trained on biased data; decisions affecting loan approval, hiring, policing can be unfair.
- Deepfakes and misinformation: realistic synthetic audio/video that can deceive and harm reputations or democratic processes.
- Autonomous systems: ethical design of self‑driving cars, drones and robots — who is responsible in case of harm?
- Data ownership and consent: who owns personal data, and how should individuals control its use?
- Surveillance capitalism: monetization of personal data by platforms that personalise behavior through profiling.
- Cyber warfare and critical infrastructure threats: nation‑level attacks on power grids, hospitals or communication systems raise ethical and legal questions.
Legal & policy context (brief)
Countries have laws and guidelines that address cyber offences, data protection and IP (for example: India’s IT Act, data protection bills and global frameworks like GDPR). These laws define offences, penalties and user rights (consent, right to access, correction).
Practical mitigation & responsible practices
- Adopt security best practices: strong authentication, encryption, regular updates and backups.
- Privacy by design: minimise data collection, anonymise where possible, obtain informed consent.
- Ethical AI: test for bias, maintain transparency, keep human oversight in critical decisions and document datasets and models.
- Digital literacy: educate users on safe behaviour, misinformation detection and responsible online conduct.
- Policy & accountability: clear laws, corporate ethics codes, impact assessments and audit trails.
Classroom links
Students should be able to discuss examples, identify stakeholders, analyse risks and propose technical and social solutions (education, policy, design changes). Case studies and debates help build ethical reasoning.
- Cambridge Analytica (Facebook) — massive harvesting of user data for political profiling and targeted advertising without informed consent.
- WannaCry ransomware — global attack that encrypted data on thousands of computers, affecting hospitals and businesses, illustrating cybercrime impact and the need for patching and backups.
- Facial recognition bias — studies showing higher error rates for certain demographic groups (gender/skin tone), highlighting algorithmic unfairness.
- Deepfake videos of public figures — used to spread misinformation and fake news, undermining trust in media.
- Digital divide during COVID‑19 — students without reliable internet/devices missed online schooling opportunities, demonstrating social inequality in access to technology.
- Autonomous vehicle incidents — crashes involving semi‑autonomous driving features raising questions about responsibility and safety standards.
- \[Risk ≈ Probability × Impact — simple risk assessment formula used to prioritise security controls.\]
- \[Data_volume = Number_of_users × Average_data_per_user (useful to estimate storage and privacy risk as user base grows).\]
- \[Key_space = 2^n where n is key length in bits (e.g., 128-bit key has 2^128 possible keys).\]
- \[Time_to_bruteforce = Key_space / Attempts_per_second — estimates how long an attacker would need to brute-force an encryption key.\]
- \[Precision = TP / (TP + FP)\]\[Recall (Sensitivity) = TP / (TP + FN) — basic metrics to evaluate ML models\]\[disparities between groups indicate possible bias.\]
Reporting, Redressal and Awareness Mechanisms
Reporting, Redressal and Awareness Mechanisms
Key Point: Report completeness score = (Description_score + Evidence_score + Contact_info_score + Timeline_score) / 4 (each component rated 0–1; closer to 1 = higher completeness)
Overview
Reporting, redressal and awareness mechanisms are the systems and processes that enable individuals, organisations and authorities to (1) report digital incidents (cybercrime, data breaches, harassment, copyright infringement), (2) get the complaint investigated and resolved, and (3) increase public understanding to prevent future incidents. Effective mechanisms reduce harm, preserve evidence, and improve trust in online services.
Key components
- Detection & Preservation: Identify the incident, immediately preserve evidence (screenshots, logs, emails, transaction IDs, timestamps) and avoid modifying affected devices.
- Reporting channels: Platforms’ in‑app/report buttons, Internet Service Provider (ISP) grievance officers, law enforcement cyber cells, national portals (e.g., India’s National Cyber Crime Reporting Portal), CERT teams for security incidents, banking grievance/ombudsman for financial fraud.
- Redressal bodies & roles: Platform/content moderation teams (take down or block), CERT (technical response, advisories), police/cyber cell (criminal investigation), consumer courts/RBI ombudsman (financial disputes), civil courts (injunctions/damages).
- Procedure & lifecycle: Report → Acknowledgement → Triage/Priority assignment → Investigation → Remediation & recovery → Communication & closure → Lessons learned.
- Awareness & prevention: Education campaigns, school curriculum, phishing simulations, community workshops, helplines, easy reporting guides and multi‑lingual materials.
What to include when reporting
- Clear description of the incident (what happened, when, where).
- Evidence (screenshots, chat logs, email headers, transaction IDs, URLs, phone numbers).
- Personal/contact details for follow up (use secure channels if sensitive).
- Actions already taken (passwords changed, bank contacted, device isolated).
Best practices
- Report quickly — prompt reporting improves chances of recovery and evidence integrity.
- Preserve evidence without altering it (take copies, avoid reusing compromised devices).
- Use official portals and keep complaint reference numbers for follow up.
- Escalate if there is no timely response (platform grievance officer → regulator → police/courts).
- Participate in awareness activities and teach safe online habits (strong passwords, two‑factor authentication, cautious clicking).
Why awareness matters
Awareness reduces victimisation and reporting delays. Well‑informed users recognise scams, follow safe practices, and provide higher quality reports that speed redressal.
- Phishing and banking fraud: A user receives a fake bank email, enters credentials and notices unauthorized withdrawal. Steps: immediately contact the bank’s fraud desk, change passwords, report the incident to the bank and file a complaint on the national cybercrime portal; preserve the phishing email and transaction IDs.
- Cyberbullying on social media: A student finds abusive posts. Steps: take screenshots, report the content and account to the platform (use report abuse feature), inform the school counsellor/police if threats are involved, request takedown and document reference numbers.
- Malware/ransomware attack on an organisation: IT detects encryption of files. Steps: isolate infected systems, preserve logs, notify CERT (or relevant national incident response team), engage forensic investigators, restore from backups and inform affected stakeholders.
- Copyright infringement: A creator finds their video reposted without permission. Steps: collect URLs and timestamps, use the platform’s copyright takedown form (e.g., DMCA notice), and if needed, pursue legal action through civil courts.
- Fake profile and identity theft: Someone creates a fake profile impersonating a person. Steps: report the fake account to the platform, inform friends/family, lodge a police complaint if the impersonation causes harm, and request account removal.
- Online marketplace fraud: Buyer pays for goods but seller disappears. Steps: raise dispute within the marketplace, provide transaction proof, escalate to consumer forum or file FIR with cyber cell if large monetary loss occurs.
- \[Report completeness score = (Description_score + Evidence_score + Contact_info_score + Timeline_score) / 4 (each component rated 0–1\]\[closer to 1 = higher completeness)\]
- \[Priority score = Impact × Urgency (Impact: scale 1–5 based on number of users/data sensitivity\]\[Urgency: scale 1–5 based on ongoing harm\]\[higher product → higher priority)\]
- \[Estimated resolution time = Acknowledgement_time + Investigation_time + Coordination_time + Remediation_time (all measured in hours/days)\]
- \[Preservation quality (%) = (Number_of_preserved_evidence_items / Total_relevant_evidence_items) × 100\]
Case Studies and Ethical Scenarios
Case Studies and Ethical Scenarios
Key Point: Ethical decision framework (conceptual): Facts + Stakeholders + Duties/Principles + Options + Consequences + Laws = Justified Action
What this topic covers
Case studies and ethical scenarios teach how to apply legal rules, ethical theories and professional principles to real-world computing problems. They train students to identify facts, stakeholders, legal obligations, likely consequences and defensible courses of action.
How to analyse an ethical scenario (step-by-step)
- Gather facts: What happened, when, where, what systems and data are involved? Distinguish known facts from assumptions.
- Identify stakeholders: Users, company, employees, regulators, third parties, public.
- Identify legal & policy constraints: Applicable laws, organisational policies, contracts and professional codes.
- Identify ethical issues: Privacy, consent, fairness, harm, copyright, accountability.
- Apply ethical theories/principles: Utilitarian (consequences), deontological (duties/rights), justice/fairness, professional duties (confidentiality, integrity).
- List possible actions: For each action, list probable benefits, harms, legal risk and stakeholders affected.
- Weigh options and choose: Use reasoned justification (balancing harms, rights, laws). Consider mitigations and safer alternatives.
- Document & communicate: Record the decision, reasons and follow-up measures; notify affected parties if required.
Common ethical principles used
- Non-maleficence: avoid causing harm.
- Beneficence: act to benefit users/society where reasonable.
- Respect for autonomy: obtain informed consent for data collection/use.
- Justice/fairness: avoid discrimination or unequal treatment by algorithms.
- Accountability & transparency: be able to explain decisions and actions.
Role of law & professional rules
Laws (for example, cybercrime provisions, copyright and data-protection rules) set minimum legal duties; professional codes set higher ethical expectations (confidentiality, competence). An ethical decision should satisfy both legal obligations and professional ethics wherever possible.
Using case studies in learning
A case study gives a concrete story to practise the steps above—students identify facts, list stakeholders and apply principles, then justify a recommended action and note preventive measures (policy changes, technical controls, training).
- Cambridge Analytica (data misuse): personal profiles harvested without informed consent were used for targeted political advertising—issues: privacy, consent, transparency, and regulatory scrutiny.
- Ransomware attack (WannaCry): organisations faced encrypted data and extortion demands—issues: incident response, backups, disclosure to stakeholders, legal reporting obligations.
- Equifax data breach: failure to patch known vulnerabilities led to large-scale exposure of personal data—issues: duty of care, risk management, notification and compensation.
- Use of deepfakes to impersonate individuals: risk of reputational harm and fraud—issues: authenticity, consent, legal redress and technical detection.
- Student using pirated software for projects: copyright infringement and academic dishonesty—issues: legal consequences and professional ethics.
- Developer ignoring input validation leading to data leak: poor software practice causing harm—issues: negligence, accountability, need for secure coding standards.
- \[Ethical decision framework (conceptual): Facts + Stakeholders + Duties/Principles + Options + Consequences + Laws = Justified Action\]
- \[Risk formula: Risk = Likelihood × Impact (used to prioritise responses)\]
- \[Cost–benefit heuristic: Choose option with highest (Benefits − Harms) subject to legal/ethical constraints\]
- \[Responsibility assignment (RACI): Responsible / Accountable / Consulted / Informed — a framework to assign roles in incident handling\]
- \[Privacy trade-off (conceptual): Privacy Risk ∝ (Amount of Data Collected × Sensitivity) / (Consent + Purpose Limitation + Security Controls)\]
Key Concepts
- Computer Ethics
- Moral principles that govern the use of computers and digital technology to ensure responsible behaviour.
- Intellectual Property Rights (IPR)
- Legal rights that protect creations of the mind (e.g., inventions, literary works, designs) and give creators control over their use.
- Copyright
- A legal protection that grants the creator of original literary, artistic or musical works exclusive rights to use and distribute them.
- Patent
- An exclusive right granted for an invention, giving the patent holder control to prevent others from making or using it for a limited time.
- Trademark
- A sign, logo, word or symbol legally registered to represent a company or product and distinguish it from others.
- Plagiarism
- Presenting someone else's work or ideas as one's own without proper acknowledgment.
- Piracy
- Unauthorized copying, distribution or use of copyrighted materials such as software, music, films or books.
- Cybercrime
- Criminal activities carried out using computers or the internet, targeting data, systems or people.
- Malware
- Malicious software designed to harm, disrupt or gain unauthorized access to computer systems.
- Phishing
- A fraudulent attempt to obtain sensitive information by impersonating a trustworthy entity, usually via email or fake websites.
- Hacking
- Gaining unauthorized access to computer systems or networks; can be malicious or ethical depending on intent.
- Cyberbullying
- Using digital communication tools to harass, threaten, or humiliate someone repeatedly.
- Privacy
- The right of individuals to control access to their personal information and how it is used.
- Data Protection
- Measures and policies to safeguard personal and sensitive data from unauthorized access, loss or misuse.
- Encryption
- The process of converting information into a code to prevent unauthorized access during storage or transmission.
- Digital Signature
- An electronic, cryptographic method to verify the authenticity and integrity of digital documents or messages.
- E-waste
- Discarded electrical and electronic devices that may contain hazardous materials and need special disposal or recycling.
- Digital Divide
- The gap between individuals or regions with access to modern information and communication technologies and those without.
- Net Neutrality
- The principle that internet service providers should treat all data on the internet equally without favoring or blocking particular products or websites.
- Open Source
- Software whose source code is made available for anyone to inspect, modify and distribute, often collaboratively.
Practice Questions
-
Define cybercrime and give two examples of crimes committed against a person. / साइबर अपराध को परिभाषित करें और किसी व्यक्ति के विरुद्ध किए गए दो अपराधों के उदाहरण दें।
Show answer
Cybercrime is any illegal act committed using computers or networks to cause harm; examples against a person include cyberstalking and identity theft. / साइबर अपराध कंप्यूटर या नेटवर्क का प्रयोग करके हानि पहुँचाने वाला कोई भी अवैध कार्य है; व्यक्ति के विरुद्ध उदाहरण हैं साइबरस्टॉकिंग और पहचान चोरी।
-
What does the PAPA framework stand for in computer ethics? / कंप्यूटर एथिक्स में PAPA फ्रेमवर्क किसका प्रतिनिधित्व करता है?
Show answer
PAPA stands for Privacy, Accuracy, Property and Accessibility — the four key ethical concerns in handling digital information. / PAPA का अर्थ है Privacy (गोपनीयता), Accuracy (सटीकता), Property (संपत्ति) और Accessibility (पहुँच) — डिजिटल सूचना के प्रबंधन में चार प्रमुख नैतिक चिंताएँ।
-
Distinguish between copyright and patent in terms of what they protect and their duration in India. / भारत में कॉपीराइट और पेटेंट के बीच, वे क्या संरक्षित करते हैं और उनकी अवधि के संदर्भ में अंतर बताएं।
Show answer
Copyright protects the expression of literary, artistic works and computer programs for the author's life plus 60 years, while a patent protects a novel invention for 20 years from filing. / कॉपीराइट साहित्यिक, कलात्मक कृतियों और कंप्यूटर प्रोग्राम की अभिव्यक्ति को लेखक के जीवन + 60 वर्ष तक संरक्षित करता है, जबकि पेटेंट एक नई खोज को दाखिल करने से 20 वर्ष तक संरक्षित करता है।
-
Name the principal Indian law dealing with cyber offences and state one matter it covers. / साइबर अपराधों से निपटने वाले प्रमुख भारतीय कानून का नाम बताएं और इसके द्वारा कवर किए गए एक विषय को बताएं।
Show answer
The Information Technology Act, 2000 is the principal law; it covers matters such as unauthorized access, data tampering, digital signatures and electronic records. / सूचना प्रौद्योगिकी अधिनियम, 2000 प्रमुख कानून है; यह अनधिकृत पहुँच, डेटा छेड़छाड़, डिजिटल हस्ताक्षर और इलेक्ट्रॉनिक रिकॉर्ड जैसे विषयों को कवर करता है।
-
What is phishing, and why is it both a legal and an ethical issue? / फिशिंग क्या है, और यह कानूनी और नैतिक दोनों समस्या क्यों है?
Show answer
Phishing is deceiving users with fake emails or websites to steal credentials; it is a legal issue because it is fraud and an ethical issue because it involves deliberate deception causing harm. / फिशिंग नकली ईमेल या वेबसाइट से उपयोगकर्ताओं को धोखा देकर क्रेडेंशियल चुराना है; यह कानूनी समस्या है क्योंकि यह धोखाधड़ी है और नैतिक समस्या है क्योंकि इसमें हानि पहुँचाने वाला जानबूझकर किया गया छल शामिल है।
-
Explain the CIA triad as the core goals of information security. / सूचना सुरक्षा के मूल लक्ष्यों के रूप में CIA त्रय की व्याख्या करें।
Show answer
The CIA triad consists of Confidentiality (only authorized access), Integrity (data remains accurate and unaltered) and Availability (data and services are accessible when needed). / CIA त्रय में Confidentiality (केवल अधिकृत पहुँच), Integrity (डेटा सटीक और अपरिवर्तित रहे) और Availability (आवश्यकता पड़ने पर डेटा और सेवाएँ उपलब्ध हों) शामिल हैं।
-
How does a digital signature ensure authenticity and integrity of an electronic document? / डिजिटल हस्ताक्षर इलेक्ट्रॉनिक दस्तावेज़ की प्रामाणिकता और अखंडता कैसे सुनिश्चित करता है?
Show answer
The sender hashes the message and encrypts the digest with their private key; the receiver decrypts it with the sender's public key and compares it to a freshly computed hash — a match confirms authenticity (origin) and integrity (no tampering). / प्रेषक संदेश को हैश करता है और डाइजेस्ट को अपनी निजी कुंजी से एन्क्रिप्ट करता है; प्राप्तकर्ता इसे प्रेषक की सार्वजनिक कुंजी से डिक्रिप्ट कर नए गणना किए हैश से तुलना करता है — मिलान प्रामाणिकता (स्रोत) और अखंडता (कोई छेड़छाड़ नहीं) की पुष्टि करता है।
-
What is plagiarism in computing, and how can students avoid it in programming assignments? / कंप्यूटिंग में साहित्यिक चोरी (प्लैगियरिज़्म) क्या है, और छात्र प्रोग्रामिंग असाइनमेंट में इससे कैसे बच सकते हैं?
Show answer
Plagiarism is presenting another's code or ideas as one's own without attribution; students can avoid it by writing original code, citing sources, respecting license terms and keeping commit history to prove individual work. / साहित्यिक चोरी किसी और के कोड या विचारों को बिना श्रेय दिए अपना बताकर प्रस्तुत करना है; छात्र मौलिक कोड लिखकर, स्रोतों का उल्लेख करके, लाइसेंस शर्तों का सम्मान करके और अपना कार्य सिद्ध करने हेतु कमिट इतिहास रखकर इससे बच सकते हैं।
Related Laws & Principles
Explore allFoundational laws & principles connected to this chapter — tap to open in the Laws Explorer.