Cyber Security Basics 📂 Slides · 14 of 15 36 min read

Internet Governance, Cyber Laws and Ethical Responsibilities

Who runs the internet? This tutorial explains internet governance, the multistakeholder model, and bodies like ICANN and IETF. It covers India's IT Act 2000 and DPDP Act 2023, global laws like GDPR, and how a cybercrime case moves from report to court. It ends with the ethical duties every cybersecurity learner must follow.

🌐

Internet Governance, Cyber Laws & Ethics

Who runs the internet? Which laws protect you online? And what duties do you carry as a cybersecurity learner? This module answers all three.
Internet Governance IT Act & DPDP Global Laws Ethical Duties

Press Next → or use ← → arrow keys

Section 01

Who Runs the Internet?

A giant city with no mayor
Imagine a city of billions of people. It has roads, addresses, shops and police. But it has no single mayor and no single owner. The city still works because many groups agree on shared rules.

The internet is exactly that city. Internet governance is the set of shared rules, standards and policies that keep this ownerless network running for everyone.
0Owners of the internet
5B+People online today
190+Countries connected
1998ICANN created
💡
Simple Definition

Internet governance means the development and use of shared principles, norms, rules and procedures that shape how the internet evolves and how it is used.

Section 01 · Model

The Multistakeholder Model

🌐 INTERNET 🏛️ Governments laws & national policy ⚙️ Technical Bodies ICANN · IETF · W3C 🏢 Private Sector ISPs · tech companies 👥 Civil Society users & rights groups 🎓 Academia research & standards
🤝
No Single Boss — Everyone at the Table

Governments, technical bodies, companies, civil society and researchers all shape internet policy together. This is called the multistakeholder model. No one group can control the whole network alone.

Section 01 · Bodies

The Organisations You Should Know

BodyWhat it doesEasy way to remember
ICANNManages domain names and IP address allocationThe internet's address book keeper
IETFCreates technical standards (TCP/IP, HTTP, TLS)Writes the internet's rulebook
W3CSets web standards (HTML, CSS, accessibility)Keeps the web speaking one language
ITUUN agency for global telecom coordinationThe UN's phone-and-signal desk
IGFUN forum where all stakeholders debate policyThe internet's town hall (since 2006)
CERT-InIndia's national incident response teamIndia's cyber emergency service
NIXIManages .in domains and Indian internet exchangesIndia's corner of the address book
🧭
One Line to Keep

ICANN names it, IETF connects it, W3C displays it, ITU coordinates it, IGF debates it — and CERT-In defends it in India.

Section 02

Why Do We Need Cyber Laws?

A thief who never enters the country
A scammer in one country empties a bank account in another country, using a server in a third country. Which police force acts? Whose court judges the case?

Ordinary laws were written for physical borders. Cyber laws extend the law into cyberspace — they define digital crimes, make electronic records and signatures legally valid, and give courts and police the power to act on online offences.
🗺️
Jurisdiction
whose court?
Attacks cross borders in milliseconds. Laws decide which country can investigate and punish.
🧾
Digital Evidence
proof that holds up
Laws make emails, logs and electronic records valid evidence in court.
🛡️
Victim Protection
rights & remedies
Laws give victims of fraud, stalking and data theft a clear path to justice and compensation.
Section 02 · India

India's IT Act, 2000 — Key Sections

The Information Technology Act, 2000 (amended in 2008) is India's main cyber law. These are the sections you will hear most often.

SectionCoversExample
Sec 43Damage to a computer or data without permission — civil penaltyDeleting files on someone's laptop
Sec 66Computer-related offences done dishonestly — criminalHacking an account to steal data
Sec 66CIdentity theftUsing another person's password or OTP
Sec 66DCheating by impersonation onlineFake bank call asking for card details
Sec 67Publishing obscene material electronicallySharing obscene content on social media
Sec 72Breach of confidentiality by officialsOfficial leaking data accessed on duty
⚠️
It Applies to Students Too

"I was just testing" is not a defence. Accessing any system without written permission can fall under Sections 43 and 66 — even if you cause no damage.

Section 02 · Privacy

The DPDP Act, 2023 — India's Privacy Law

The Digital Personal Data Protection Act, 2023 governs how organisations collect and use personal data in India.

Consent First
clear & specific
Personal data can be processed only after free, informed consent — or for defined legitimate uses.
🧑‍⚖️
Your Rights
as a data principal
You can ask what data is held about you, get it corrected, get it erased, and raise complaints.
💸
Heavy Penalties
up to ₹250 crore
A data fiduciary that fails to protect personal data can face penalties up to ₹250 crore per breach.
🗂️
Two Words to Learn

Data Principal — the person the data is about (you). Data Fiduciary — the organisation that decides why and how your data is processed (a bank, an app, a university).

Section 03

Cyber Laws Around the World

🇪🇺
GDPR (EU, 2018)
The world's strictest privacy law. Fines up to 4% of global turnover. It inspired privacy laws worldwide, including India's DPDP Act.
🇺🇸
CFAA (USA, 1986)
The main US anti-hacking law. Makes "unauthorised access" to computers a federal crime.
🌍
Budapest Convention (2001)
The first international cybercrime treaty. Helps countries share evidence and cooperate across borders.
🏥
HIPAA (USA)
Protects health records. Hospitals and insurers must secure patient data or face heavy fines.
💳
PCI DSS (Industry)
Not a law but a binding industry standard. Anyone handling card payments must follow it.
🇮🇳
CERT-In Directions (India)
Indian organisations must report major cyber incidents to CERT-In within 6 hours of noticing them.
🧩
The Pattern

Every region repeats the same three ideas: punish unauthorised access, protect personal data, and force organisations to report breaches.

Section 03 · In Action

From Cybercrime to Courtroom

💥 Incident fraud, hack, stalking 📞 Report 1930 · cybercrime.gov.in 🔍 Investigation cyber cell · CERT-In · forensics ⚖️ Court trial under IT Act + IPC/BNS 📁
⏱️
Speed Saves Money

In online financial fraud, the first hours matter most. Reporting fast on 1930 (India's cyber fraud helpline) or cybercrime.gov.in lets banks freeze the money before it disappears. The green file in the diagram is the evidence — it must travel with the case at every step.

Section 04

Same Skills, Different Choices

🧑‍💻 Hacking Skills the same knowledge 😇 White Hat permission → legal ✅ 😐 Grey Hat no permission → risky ⚠️ 😈 Black Hat crime → jail ❌
🔑
One Word Separates a Career From a Crime

Permission. A white hat tests systems with written consent and gets paid. A grey hat probes without asking — even good intentions can break Section 43. A black hat attacks for gain and faces prison. The skills are identical; the choice is not.

Section 04 · Code

The Professional's Code of Conduct

🤝 ETHICAL DUTIES OF A SECURITY PROFESSIONAL
1
Get written permission first. Never test a system you do not own without a signed agreement that defines the scope.
2
Stay inside the scope. If the contract says "test the web app", the mail server is off limits. Scope creep is unauthorised access.
3
Protect what you find. Data seen during a test is confidential. Never copy, share or keep it longer than needed.
4
Disclose responsibly. Found a vulnerability? Report it privately to the owner and give them time to fix it — do not post it publicly first.
5
Report honestly. Never hide a finding, inflate a risk, or claim a test you did not run. Your report drives real decisions.
6
Do no harm. Avoid tests that could crash production systems or expose real user data. Safety of live systems comes first.
Section 04 · Everyday

Ethics for Every Internet User

You do not need to be a hacker to face ethical choices online. These apply to everyone, every day.

🔏
Respect Privacy
theirs, not just yours
Do not share someone's photos, chats or personal details without their consent.
📰
Verify Before Sharing
stop misinformation
Forwarding fake news makes you part of the problem. Check the source first.
©️
Respect Ownership
no piracy
Software, music, courses and books are someone's work. Pirating them is theft.
🚫
Never Use Leaked Data
even if it's public
Downloading or searching leaked databases keeps the harm alive for the victims.
🗣️
No Harassment
trolling is not a joke
Cyberbullying and stalking cause real harm — and are punishable offences.
🚨
Report, Don't Ignore
be an upstander
See a scam, a fake profile or abuse? Report it on the platform or on cybercrime.gov.in.
Section 05

Case Study — The Cosmos Bank Heist

₹94 crore gone in one weekend — across 28 countries
Attackers planted malware inside Cosmos Bank's systems in Pune and cloned thousands of debit cards. In about 2 hours, money was pulled from ATMs in 28 countries. A separate SWIFT transfer moved more money abroad. Total loss: about ₹94 crore.

The case shows every theme of this module at once: a borderless crime, Indian police working with international agencies, charges under the IT Act, and years of cross-border legal work to trace the money.
🌐
Why Governance and Law Must Work Together

No single country could handle this alone. It needed shared technical standards to trace the transactions, cyber laws in many countries to arrest suspects, and treaties to share the evidence. That is internet governance in action.

FINAL

Rules Keep the Ownerless City Running

5Stakeholder groups govern the internet
2000India's IT Act arrives
2023DPDP Act protects personal data
1930India's cyber fraud helpline
6Duties in the professional code
1Word between career and crime: permission
🎯
What You Now Know

The internet has no owner — it runs on the multistakeholder model. Cyber laws like the IT Act, DPDP Act and GDPR extend justice into cyberspace. And ethics decide what you do with your skills when no one is watching.

📚
Where To Go Next

Read a summary of the IT Act and the DPDP Act. Explore cybercrime.gov.in to see how reporting works. Follow an IGF session online to watch governance debates live. And before any security test — get it in writing.

🌐 End of tutorial · Press to review, or click Restart