Cyber-Physical Systems represent a critical integration of computation, networking, and physical processes, essential for modern infrastructure such as power grids, healthcare, and transportation. This paper examines the security and privacy challenges within Cyber-Physical System, particularly in the Indian context. It explores the legal framework governing Cyber-Physical System security in India, highlighting gaps and vulnerabilities. By analysing international incidents such as the Stuxnet worm, the WannaCry ransomware attack, and the Ukraine power grid attack, the paper underscores the global nature of these threats and the requirement for robust cybersecurity measures. The discussion extends to India’s own experiences, including the Mumbai power grid attack, the Kudankulam nuclear power plant breach as well as the Aadhaar data breach. The paper further reviews relevant Indian laws, such as the Information Technology Act, 2000 and Digital Personal Data Protection Act, 2023 evaluating their effectiveness in addressing Cyber-Physical Systems’ security. Moreover, the authors have proposed recommendations that include enhancing regulatory frameworks, implementing advanced cybersecurity protocols, strengthening incident response mechanisms, and fostering public–private partnerships. By proposing actionable strategies, the paper aims to contribute to the development of a secure and resilient Cyber-Physical System infrastructure in India, capable of withstanding evolving cyber threats.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Transcending the Firewall: Legal Policies and Case Studies on Cyber-Physical System’s Security and Privacy Landscape in India

  • Shipra Sinha,
  • Kritika Ramya

摘要

Cyber-Physical Systems represent a critical integration of computation, networking, and physical processes, essential for modern infrastructure such as power grids, healthcare, and transportation. This paper examines the security and privacy challenges within Cyber-Physical System, particularly in the Indian context. It explores the legal framework governing Cyber-Physical System security in India, highlighting gaps and vulnerabilities. By analysing international incidents such as the Stuxnet worm, the WannaCry ransomware attack, and the Ukraine power grid attack, the paper underscores the global nature of these threats and the requirement for robust cybersecurity measures. The discussion extends to India’s own experiences, including the Mumbai power grid attack, the Kudankulam nuclear power plant breach as well as the Aadhaar data breach. The paper further reviews relevant Indian laws, such as the Information Technology Act, 2000 and Digital Personal Data Protection Act, 2023 evaluating their effectiveness in addressing Cyber-Physical Systems’ security. Moreover, the authors have proposed recommendations that include enhancing regulatory frameworks, implementing advanced cybersecurity protocols, strengthening incident response mechanisms, and fostering public–private partnerships. By proposing actionable strategies, the paper aims to contribute to the development of a secure and resilient Cyber-Physical System infrastructure in India, capable of withstanding evolving cyber threats.