🇮🇳

Securing India's National Examinations

A zero-trust reference architecture to prevent paper leaks, protect merit, and rebuild public trust — covering every stage from AI-assisted paper creation to post-exam destruction.

Prepared by Roshan Trivedi, CIAM  ·  PAM Product Owner | Identity & Access Management  ·  24 July 2026
Version 2.0  ·  Classification: Public — Policy Discussion
60L+
Candidates per year (NTA)
5,000+
Exam centres
90+
Exams annually
4
Security pillars
₹79
Cost per candidate / year
0
Target paper leaks

एक दृष्टि में (At a Glance)

भारत की राष्ट्रीय परीक्षाओं में हर वर्ष 60 लाख से अधिक अभ्यर्थी 5,000 से अधिक केंद्रों पर सम्मिलित होते हैं। प्रश्नपत्र लीक की बार-बार होने वाली घटनाएँ यह दर्शाती हैं कि केवल प्रक्रियागत उपाय परीक्षा की अखंडता की रक्षा नहीं कर सकते। यह प्रस्ताव एक ज़ीरो ट्रस्ट (Zero Trust) सुरक्षा वास्तुकला प्रस्तुत करता है — जिसमें बायोमेट्रिक पहचान, प्रश्नपत्रों का एन्क्रिप्शन, कृत्रिम बुद्धिमत्ता (AI) आधारित निगरानी, तथा सभी केंद्रों की भौतिक सुरक्षा सम्मिलित है। तीन वर्षों की कुल लागत ₹1,419 करोड़ है — प्रति अभ्यर्थी प्रति वर्ष केवल ₹79 — जो एक भी परीक्षा रद्द होने से बचाने पर ही अपनी लागत वसूल कर लेती है।

Why India's Exams Are Vulnerable

India operates the world's largest examination infrastructure. A single paper leak cancels an exam for millions and signals that merit doesn't decide outcomes.

ExaminationCandidates (2024)CentresStakes
NEET-UG24.06 lakh~4,750Only gateway to MBBS/BDS in India
JEE Main11.68 lakh500+Gateway to IITs, NITs, IIITs
CUET-UG13.48 lakh313 citiesCentral university admissions
UGC-NET9+ lakh300+Lectureship & PhD eligibility
UPSC CSE~13 lakh72IAS, IPS, IFS civil services
SSC / Banking / Railways5+ croreThousandsGovernment employment

Root Causes of Leaks

🎯

Insider Threat

Officials with standing access to papers leak them for financial gain. No SOP prevents a trusted insider from photographing a paper they already hold.

📦

Physical Custody Failure

Papers transported without cryptographic protection can be opened and photographed mid-transit with no detection until after the exam.

💻

Weak Digital Controls

Systems with weak access controls allow unauthorised bulk downloads of question bank content — often undetected without continuous monitoring.

🧍

Impersonation

Proxies sit examinations using forged credentials. Without biometric verification, centres cannot confirm the candidate is who they claim to be.

📡

No Centralised Monitoring

Without a Security Operations Centre, anomalous access at 2 AM before an exam — a classic pre-leak signal — goes completely undetected.

🏗️

Procedural vs. Architectural Security

Current security relies on humans following rules under pressure. Architecture-level controls are not optional — they are the only reliable solution.

The NEET 2024 controversy affected 24 lakh candidates, triggered a Supreme Court intervention, and cost an estimated ₹700–1,250 crore in direct and indirect costs. The full 3-year security programme costs ₹1,419 crore — it pays for itself by preventing a single cancellation.

Cost of Inaction

Cost CategoryEstimate (₹ Crore)Notes
Re-examination logistics150–250Centre hiring, staff, paper, printing, transport
Candidate travel & accommodation200–400Millions of families absorbing repeat costs
Academic year delay300–500Colleges at partial capacity; delayed intake
Legal & judicial process50–100SC hearings, RTI responses, investigations
Mental health & societal impactUnquantifiedErosion of meritocracy narrative
Total (single NEET-scale event)700–1,250+Conservative estimate
3-year security programme1,419This proposal — breaks even on one prevented event

Four-Pillar Zero Trust Architecture

Four mutually reinforcing pillars, unified by the National Exam-SOC — making a paper leak structurally impossible, not just procedurally prohibited.

Zero Trust, Least Privilege Assume Breach, Monitor Always Secure & Private by Design Cryptographic Enforcement Immutable Accountability NIST SP 800-207 aligned
No user, device, session, or network is trusted by default. Every access request is authenticated, authorised, and logged — regardless of network location or seniority. This applies to ministers, paper setters, and janitors equally.
01

🔐 Identity & Access (Zero Trust)

Biometric verification, zero standing privileges, and just-in-time access for every person who touches an examination. No account — including administrator accounts — holds permanent access to examination content. All access is JIT, dual-authorised, time-limited, and auto-revoked.

PAM platform vaults all privileged credentials. Full session recording. Critical operations require two people to authenticate simultaneously. Re-authentication every 15 minutes.

02

📦 Secure Content Lifecycle

Papers encrypted from AI-assisted authoring through HSM vaulting to geo-fenced, time-locked decryption at the exam hall. Three simultaneous conditions required for decryption: correct GPS location, authorised time window, two authenticated administrators. Fail any one — paper stays encrypted.

Digital watermarking: every copy carries a unique invisible watermark encoding centre ID, session, and batch. If a photo leaks online, forensic extraction identifies the source centre within minutes.

03

🛡️ Threat Detection & Security Ops

AI-driven UEBA establishes behaviour baselines for every user. Deviations — after-hours access, bulk downloads, unusual location — trigger automated risk scoring. 24×7 National Exam-SOC with SIEM/SOAR. 20 pre-built response playbooks execute automatically in under 2 minutes. Dark web and social media monitoring for paper leaks round the clock.

04

🏫 Managed Exam Infrastructure (MEI)

Every centre hardened with certificate-enrolled cameras, metal detectors, signal management, and immutable digital chain of custody. Dedicated encrypted network per centre. Local HSM cache device. Computer vision proctoring at Tier A centres. GPS tamper detection on all physical paper packets.

AI-Assisted Paper Creation Workflow

Questions are created through a secure, AI-augmented process with mandatory human oversight at every gate. Paper setters work in physical isolation on air-gapped NTA terminals — no personal devices, no internet, no external communication.

🤖AI GenerationGenerates question pool from approved syllabus
👨‍🏫SME ReviewTeachers review, reject, edit each AI question
Approval GateMin. 2 subject experts sign off digitally
🔍ModerationSenior examiner checks balance & clarity
🔒EncryptionHSM encrypts & signs final paper immediately
🏦VaultingEncrypted paper enters secure digital vault

Centre Security by Tier

ControlTier A (Urban, 500)Tier B (District, 2,000)Tier C (Rural, 2,500)
NetworkDedicated MPLSVPN + LTE failoverVSAT satellite primary
EndpointsLocked-down terminals, EDR, signed OSSameSame
Local HSM cache
Camera enrollmentFull certificate-basedFullFull
AI proctoringAI-assisted + humanHuman primaryHuman primary
Power backup4-hour UPS + generator2-hour UPS2-hour UPS
GPS tamper device

From Paper Creation to Destruction

Every step from the moment a question is generated to the moment all copies are destroyed — secured, logged, and automated.

Pre-Exam Timeline

Exam Day Protocol

Paper Vaulting — Where Papers Live at Each Stage

StageLocationProtectionAccess Control
AuthoringAir-gapped NTA terminalNo network; device certificate; encrypted local storageSME biometric + PAM
Post-signing (master)NIC National HSM Vault (primary + DR)HSM-encrypted; FIPS 140-2 L3; M-of-N key ceremonyDG NTA + 2 custodians
Regional distributionRegional NIC Secure Vault (4 regions)AES-256-GCM; regional key fragmentRegional NTA officer
Centre cacheCentre HSM local cache deviceEncrypted; geo-locked; time-lockedTwo admins + geo-fence + time window
Post-exam (digital)NIC archive vault7-year retention; WORM storageLegal/RTI access only; dual authorised
Physical copiesCentre vault → shredding facilityTamper-evident seal; GPS trackedDual-authorised shredding within 24h

🚔 Police & Flying Squad Coordination

State Police Integration

  • District SP briefed at D-7 with centre locations
  • Police stationed at perimeter of each centre
  • Plain-clothes officers near Tier A centres
  • Exam-SOC has direct radio contact with centre police officer
  • Any physical security alert triggers immediate police response

Flying Squads & Cyber Cells

  • NTA flying squads make surprise inspections at 10% of centres
  • State cyber cells monitor WhatsApp, Telegram for paper distribution
  • CERT-In cyber cell on standby for digital forensics
  • FIR registration within 2 hours of confirmed leak, with watermark evidence

Automation Map

ActivityAutomationHuman Role
UEBA risk scoringFully automated (AI)Review alerts above threshold
Session suspension (risk >85)AutomatedSOC analyst confirms within 5 min
Paper decryptionAutomated (time + geo check)Two admins must authenticate
CERT-In notificationAutomated (SOAR playbook)SOC manager reviews before send
Watermark extractionAutomated (image analysis)Forensics analyst confirms
Camera health monitoringAutomated (SOC dashboard)SOC alerts centre if outage
Chain of custody loggingFully automated (immutable log)Auditor reviews post-exam
Biometric gate entryAutomated matchOfficer verifies failures
FIR / legal actionNot automatedNTA Director + legal team
Paper shreddingNot automatedDual-authorised (mandatory)

Every Person. Every Device. Verified.

Students, teachers, invigilators, and surveillance devices all have verified, audited digital identities. No anonymous access. No standing privileges.

Student Digital Identity — Documents & Process

DocumentPurposeVerification
Aadhaar CardPrimary identity anchorUIDAI API real-time check
Class 10 / 12 MarksheetEligibility confirmationDigiLocker pull from Board
Category CertificateReservation eligibilityIssuing authority digital stamp
Passport photographVisual identityAI face quality check + liveness
Mobile numberOTP-based 2FATelecom KYC verification
Email addressCommunicationVerified via OTP
SignatureConsent & legal declarationStored; matched at exam hall
  1. Online Application + Aadhaar Verification

    Candidate submits form; Aadhaar number verified against UIDAI in real time. Name and DOB must match exactly.

  2. Document Upload + AI Verification

    Marksheets pulled from DigiLocker. Photo checked for quality, liveness, and consistency with Aadhaar photo.

  3. Biometric Enrolment Centre Visit

    For high-stakes exams: candidate attends an enrolment centre. Fingerprints + iris captured and linked to their Examination Identity Number (EIN).

  4. Digital Admit Card Issued

    Time-limited digitally signed QR code (valid 24 hours before exam). Contains encrypted biometric reference. Cannot be forged or transferred.

  5. Exam Hall Entry

    QR scanned at gate. Fingerprint matched to enrolment record. Face verified by AI camera. Seat assigned by randomised system on exam morning only.

Subject Matter Expert (Teacher) Selection & Identity

Eligibility Criteria

  • Minimum 10 years teaching/research experience
  • Postgraduate or doctoral qualification in subject
  • No prior disciplinary action or conviction
  • Not related to any registered candidate
  • Not employed by a coaching institution in the subject
  • Not from the same state as any exam centre

Selection & Isolation Process

  • Randomly drawn from NTA's encrypted National Examiner Registry
  • Identity known only to DG NTA + one Oversight Board member
  • Criminal background check (state police + court records)
  • Confidentiality agreement with ₹1 crore penalty clause
  • Personal devices surrendered; work on air-gapped NTA terminal only
  • Physical isolation: live-in secure facility for session duration
  • All sessions video-recorded (CCTV + screen capture)

Invigilator Selection & Randomised Deployment

Selection Criteria

  • State/central government employee or accredited institution staff
  • Must not teach the subject being examined
  • Must not be from the same institution as any registered candidate
  • No criminal record; police clearance required
  • Not assigned same centre two consecutive examinations

Randomised Assignment

  • D-21: Notified they are on duty (exam date only)
  • D-1 (8 PM): Encrypted message reveals centre assignment
  • Exam day: Must report by T-2 hours; biometric at gate
  • Rotation: Invigilators moved between halls randomly mid-exam
  • Flying squad: May replace any invigilator at any time

📷 Camera & Device Enrollment

🔏

Device Certificate

Each CCTV, biometric reader, and exam terminal is issued a unique device certificate from NE-PKI. Device must present this certificate to connect to NTA systems.

🚨

Tamper Detection

Cover attempts, power interruptions, or physical movement trigger an immediate Exam-SOC alert. Any camera offline >2 minutes on exam day triggers police notification.

🎭

Anti-Spoof

Video feeds are checked for looping signatures and static image patterns. A looped recording from a compromised camera is detectable by frame-fingerprint analysis.

Derived From an Explicit Threat Model

A security architecture is only credible if it is built from a clear picture of who the adversaries are, what they want, and what they can do. This is the analysis a government evaluation committee looks for first.

Adversary Personas

AdversaryMotivationCapabilityPrimary Vector
Malicious insider (setter / admin)Financial gain, coercionHigh — legitimate accessExfiltrate content they can access
Organised leak syndicateProfit (sell papers / proxies)High — funded, persistentBribe insiders; impersonation rings
External cyber attackerProfit, notoriety, disruptionMedium–HighExploit systems, phishing, malware
Nation-state actorStrategic institutional disruptionVery highSupply chain, zero-days, persistence
Opportunist candidatePersonal advantageLowDevices, impersonation, copying
Compromised vendorVaries (often unwitting)MediumSupply-chain implant, weak update

STRIDE Threat Analysis

CategoryExample ThreatPrimary Mitigation
SpoofingProxy candidate; forged admit card; fake camera feedBiometric + liveness; signed QR; device certs + anti-spoof
TamperingPaper altered in transit; log manipulationHSM signing; immutable WORM log; hash chain of custody
RepudiationInsider denies accessing a paperPAM session recording; non-repudiable digital signatures
Information DisclosurePaper leak; PII exposureAES-256-GCM; ZSP; geo/time-locked decryption; watermarking
Denial of ServiceExam-day outage; network attackOffline HSM cache; DR failover; DDoS protection
Elevation of PrivilegeAdmin escalates to key accessZero standing privileges; JIT + dual auth; M-of-N keys

Risk Register (Top Risks)

Likelihood (L) & Impact (I) scored 1–5. Inherent = before controls; Residual = after this architecture's controls.

IDRiskLIInherentKey ControlResidual
R1Insider leaks pre-exam paper4520 CriticalZSP, PAM, watermarking, UEBA6 Medium
R2Paper intercepted in distribution3515 HighEnd-to-end encryption, hash custody3 Low
R3Candidate impersonation4416 HighBiometric + liveness at gate4 Low
R4Cyber intrusion into exam systems3515 HighZero Trust, SOC, segmentation4 Low
R5AI paper-tool manipulated3515 HighAir-gap, human gates, output validation3 Low
R6Biometric data breach2510 HighEncryption, DPDP controls, no export3 Low
R7Exam-day system outage3412 HighOffline cache, DR, UPS4 Low
R8Supply-chain compromise2510 HighSBOM, sovereign sourcing, audit4 Low
R9Physical breach at centre339 MediumMEI, police, signal mgmt, CCTV3 Low
R10Collusion (multiple insiders)2510 HighSeparation of duties, M-of-N, red team4 Low
Every detection playbook in the Exam-SOC is mapped to MITRE ATT&CK techniques, giving measurable detection coverage and a clear gap analysis during red-team exercises.

Securing the AI That Creates Papers

Because AI assists paper creation, proctoring, and anomaly detection, AI itself is an attack surface. Any modern reviewer will ask how it is secured. Here is the answer.

💉

Prompt Injection

Air-gapped model, sanitised templated prompts, no free-text external input, and output validation prevent the model being steered to leak or bias content.

☠️

Data Poisoning

The syllabus corpus is signed, version-controlled, and integrity-hashed. Every generated question is reviewed by human subject experts.

🎭

Deepfake Impersonation

Liveness detection, multi-modal biometrics (fingerprint + iris + face), and challenge-response defeat synthetic face/voice attacks.

🧬

Model Theft

On-premise sovereign hosting, no public API, PAM-gated access, and query-rate monitoring prevent extraction of question patterns.

🌀

Hallucinated Questions

Mandatory dual-SME approval and a moderation gate mean no unreviewed AI question is ever used in a live paper.

🔌

Kill Switch

AI assistance can be disabled instantly, reverting to a fully manual, human-only workflow with no loss of security.

Human-in-the-loop is mandatory. No AI output — a question, a proctoring flag, or a risk score — is ever actioned autonomously where it affects a candidate. AI accelerates and assists; humans decide. Every AI capability has a manual fallback and a mandatory human decision gate.

AI Model Governance Framework

ControlRequirement
Model registryEvery model version registered, signed, and traceable with an approved-use record
Model risk assessmentBias, fairness, robustness, and adversarial testing before deployment
ExplainabilityProctoring and anomaly models must justify every flag in human-readable terms
Sovereign hostingAll models run on Govt of India (MeghRaj / GI Cloud) or NIC — no foreign cloud, no external LLM API
Continuous red-teamingThe AI paper tool is adversarially tested each cycle for injection and leakage
Audit loggingEvery prompt, output, and human decision logged immutably for post-exam audit

Aligned to the NIST AI Risk Management Framework and OWASP Top 10 for LLM Applications.

Who Is In Charge & How the System Is Audited

A three-tier governance structure with clear accountability at each level, independent oversight, and public transparency reporting.

Authority Structure

BodyChair & MembersAuthorityCadence
National Examination Security Council (NESC) (proposed)MoE Secretary (Chair), DG NTA, DG NIC, DG CERT-In, retired SC judge, 2 independent expertsFinal policy authority; approves architecture changes; reviews audit reportsQuarterly + emergency
Programme Steering CommitteeNTA Director General (Chair), NIC Programme Director, CERT-In repOperational decisions; budget releases; vendor approvals; escalationMonthly
Technical Working GroupLead architects (NTA + NIC), Exam-SOC lead, PAM adminTechnical design, configuration changes, playbook revisionsWeekly
State Security CoordinatorState-level officer liaising with NTA and district policeCentre compliance; local police coordinationPer exam cycle
Independent Oversight Board2 academics, 1 retired IPS, 1 civil society rep, 1 student repWatchdog; review annual audit; publish public transparency reportAnnual
Core principle: No single official — including the Director General of NTA — has unilateral authority over examination content or security controls. Every critical action requires dual authorisation.

Full Exam Audit Lifecycle

Audit TypeTimingAuditorScope
Centre inspectionD-30NTA inspection teamMEI compliance, physical security, device certification
System readinessD-1Exam-SOCAll systems green, HSM health, connectivity
Real-time monitoringExam dayExam-SOCAll centres, all systems, all access events
Post-exam debriefWithin 4 hoursSOC + NTA opsIncidents, near-misses, custody complete?
Chain of custody auditWithin 7 daysNTA Internal AuditEvery event in immutable log verified
Independent security auditAnnualNABCB-accredited auditorISO 27001 surveillance; full system review
Red team exerciseBi-annualExternal red teamFull attempt to compromise system using real TTPs
Parliamentary transparencyAnnualIndependent Oversight BoardPublic KPI report; incident summary

Data Security, Classification & DPDP Act 2023

ClassExamplesControls
Top SecretQuestion papers (pre-exam)HSM-only; dual auth; zero standing access
SecretBiometric data; PAM recordingsEncrypted; PAM-controlled; no export
ConfidentialCandidate PII; staff identityEncrypted; DPDP consent required
InternalSOC logs; audit trailsEncrypted; 7-year WORM retention
PublicExam schedules; resultsDigitally signed; integrity-verified

DPDP Act 2023 Compliance

  • Informed consent at registration for biometric processing
  • Purpose limitation: biometric used only for examination identity verification
  • Data minimisation: only required data collected and retained
  • Breach notification to CERT-In + Data Protection Board within 6 hours
  • Right to erasure: candidate data deleted 3 years post-exam

Data Analysis & Fraud Detection

🔍

Answer Pattern Analysis

Candidates with identical wrong answers (beyond statistical probability) are flagged. Seat adjacency mapping identifies suspected copying rings.

📍

Geographic Clustering

Unusual registration clusters from a single locality, coaching centre, or IP address range are flagged as potential proxy rings.

🕸️

Network Analysis

Social network analysis of registration data identifies clusters linked by phone number, email domain, payment instrument, or device fingerprint — signals of organised fraud.

⏱️

Timing Analysis

Candidates completing an exam in statistically abnormal time (too fast, or with suspiciously consistent response cadence) are flagged for review.

📈

Score Anomaly Detection

Statistically improbable score jumps between attempts, or scores inconsistent with prior academic record, trigger secondary identity verification.

🏆

Historical Pattern Learning

ML models trained on historical leak incidents identify early warning signatures — access pattern changes in the weeks before an exam that preceded past leaks.

Auditable Against Standards & Indian Law

The decisive question for any government committee: is this certifiable and legally compliant? Every control maps to a recognised framework or statute — the system is designed to be audited, not just admired.

NIST Cybersecurity Framework 2.0

FunctionHow This Architecture Satisfies It
GovernNESC, Steering Committee, Oversight Board; documented policy and RACI
IdentifyThreat model, risk register, asset & data classification
ProtectZero Trust, PAM, HSM/PKI encryption, MEI hardening, ZSP
DetectUEBA, SIEM, dark-web monitoring, 24×7 Exam-SOC
RespondSOAR playbooks, breach-response scenarios, CERT-In notification
RecoverBCP/DR, backups, rollback checklist, re-examination protocol

Indian Legal & Regulatory Alignment

InstrumentObligationHow It Is Met
DPDP Act 2023Lawful processing of personal & biometric dataConsent, purpose limitation, minimisation, 6-hour breach notice, erasure at 3 years, DPIA
CERT-In Directions 20226-hour incident reporting; log retentionSOAR auto-notification; 180-day+ logs; ICT clock sync
IT Act 2000Legal validity of e-records & signaturesNE-PKI digital signatures; non-repudiation; Sec. 43A reasonable security
Public Examinations Act 2024Criminalises leaks & organised cheatingWatermark forensics + immutable logs give court-admissible evidence
Aadhaar Act & UIDAI regsLawful, minimal Aadhaar useAuthentication-only (no number storage beyond token); UIDAI-compliant APIs
Compliance is designed-in, not bolted-on. The system is certifiable (ISO 27001), auditable (CERT-In empanelled), and produces court-admissible evidence under the 2024 Act. Also aligned to ISO/IEC 27001:2022 Annex A across organisational, people, physical, and technological controls.

When Systems Fail, and How We Prove It Works

Closing the grey areas experienced reviewers probe: continuity when systems fail, a trusted supply chain, independent proof of security, privacy in law and practice, and inclusion of every eligible candidate.

Business Continuity & Disaster Recovery

SystemRTORPOResilience Measure
Paper decryption at centre0 (no downtime)0Offline local HSM cache; backup HSM device per centre
National HSM vault< 15 min0Active-active primary + DR site; M-of-N key recovery
Exam-SOC< 5 min< 1 minRedundant hot-standby SOC in second region
Identity / biometric service< 10 min< 5 minCached templates at centre; queued sync on recovery
Network (per centre)< 5 minN/AVPN + LTE + VSAT failover by tier

Backups follow a 3-2-1 strategy (3 copies, 2 media, 1 off-site, all encrypted). DR drills run quarterly with documented recovery-time evidence.

🔗 Supply-Chain & Vendor Security

  • Tier-1 due diligence for any vendor touching content or crypto
  • SBOM required for every component; continuous vuln scanning
  • Sovereign sourcing (STQC / Common Criteria); Make-in-India via GeM
  • Cryptographically signed, staged software/firmware updates
  • Open standards (PKCS#11, OIDC, STIX/TAXII) — no vendor lock-in

🔬 Security Assurance & Testing

  • VAPT quarterly + pre-exam (CERT-In empanelled)
  • Bi-annual independent red / purple team
  • Continuous responsible-disclosure / bug bounty
  • Annual ISO 27001 certification & surveillance
  • STQC / Common Criteria evaluation per procurement

Privacy by Design & Accessibility

🔐 Privacy (DPDP + DPIA)

A mandatory Data Protection Impact Assessment before processing, refreshed annually. Data minimisation, purpose limitation, biometric templates deleted 3 years post-exam, consent at registration, and data localisation within India. A Data Protection Officer answers to the Oversight Board.

♿ Inclusion Without Weakening Security

Persons with disabilities (Divyang) get vetted, biometrically-enrolled scribes, extra time, and assistive tech. Rural candidates use VSAT + offline cache. Multi-language papers are each separately watermarked. Every accommodation preserves full cryptographic control.

Security Maturity Roadmap

LevelStageMilestone
1 — InitialTodayProcedural controls; no continuous monitoring
2 — ManagedEnd of Phase 1SOC live; PAM & HSM deployed; pilot centres
3 — DefinedEnd of Phase 2Standardised controls across 2,500 centres; universal watermarking
4 — QuantifiedEnd of Phase 3All 5,000 centres; measured KPIs; ISO 27001 certified
5 — OptimisingYear 4+Continuous red-teaming; post-quantum crypto; predictive threat intel

36-Month Rollout Across 5,000 Centres

A phased programme with clear milestones, ₹1,419 crore budget, RACI accountability, and measurable KPIs.

Phase 1 — Foundation (M1–6)

  • Stand up National Exam-SOC
  • Deploy PAM for NTA central staff
  • Procure HSMs; establish NE-PKI
  • Deploy UEBA baselines
  • Pilot 200 high-risk centres
  • Security awareness training

₹385 crore

Phase 2 — Core Deployment (M7–18)

  • Full encrypted paper distribution
  • Digital watermarking on all exams
  • Biometric enrolment (80% staff)
  • MEI rollout — 2,000 Tier B centres
  • AI proctoring at 500 Tier A centres
  • Dark web monitoring live

₹539 crore

Phase 3 — Full Scale (M19–36)

  • All 5,000 centres on MEI
  • Rural VSAT connectivity rollout
  • 100% biometric coverage
  • Post-quantum cryptography
  • ISO 27001 certification
  • Standing red team programme

₹495 crore

Budget by Line Item

Budget LinePhase 1 (₹Cr)Phase 2 (₹Cr)Phase 3 (₹Cr)Total (₹Cr)
National Exam-SOC804020140
HSM / PKI infrastructure603020110
PAM platform3010545
SIEM / SOAR40201070
UEBA platform2510540
Biometric enrolment & devices206040120
MEI — Tier A (500 centres)750075
MEI — Tier B (2,000 centres)02400240
MEI — Tier C (2,500 centres)00250250
Computer vision proctoring0503080
Rural VSAT connectivity005050
Training & change management15201045
Audits & red team5101025
Contingency (10%)354945129
TOTAL3855394951,419
₹79 per candidate per year — less than 5% addition to the current exam fee. Annual operating cost from Year 4: ₹210 crore. Break-even: one prevented NEET-scale cancellation.

Key Performance Indicators

KPIBaselineYear 1Year 3
Paper leak incidents / year3–5≤ 10
Exam cancellations due to leaks1–2 / year00
Mean time to detect anomalyUnknown< 30 min< 5 min
Staff with zero standing privileges0%80%100%
Centres at MEI baseline0%20%100%
Papers with digital watermark0%100%100%
Biometric false rejection rateN/A< 0.5%< 0.1%
System uptime on exam day~95%99.5%99.9%
Staff trained in security awareness0%70%100%
Annual independent audit completedNoYesYes

RACI Matrix

R Responsible   A Accountable   C Consulted   I Informed
ActivityMoENTANICCERT-InCentresAuditors
Define security policyARCCII
Architecture designCARCIC
Deploy HSM / NE-PKIICA/RCIC
Operate Exam-SOCIARCII
Respond to cyber incidentsIARRCI
Centre MEI deploymentIARIRC
Annual security auditsACCCCR
SME selection & isolationIA/RCIII
Police coordinationCAICRI
Public transparency reportARIIIC

What Happens When Something Goes Wrong

Security architecture cannot guarantee zero incidents — it guarantees a structured, fast, and documented response that limits damage, preserves evidence, and restores integrity. This plan covers human insiders, external attackers, and automated/AI threats.

Core principle: The moment a breach is suspected, the default action is contain first, investigate second, communicate third. No single person has authority to suppress or delay breach response. The Exam-SOC duty officer has authority to suspend any session, revoke any credential, and isolate any system without escalation approval.

Incident Severity Classification

SeverityDescriptionResponse TimeDecision Authority
P1 — CriticalPaper leak confirmed; HSM compromise; biometric system breach; active attacker in exam systemsImmediate (< 5 min)Exam-SOC duty officer (auto-contain) + NTA DG notified
P2 — HighSuspected leak; credential theft; camera system outage; insider access anomaly above UEBA threshold 85< 15 minExam-SOC Tier 2 analyst + NTA security head
P3 — MediumSingle centre connectivity failure; device tamper alert; failed biometric above baseline; suspicious login< 30 minExam-SOC Tier 1 analyst
P4 — LowIndividual access anomaly; failed login attempts below threshold; minor physical irregularity< 2 hoursSOC alert queue

Universal 5-Phase Response (All Breach Types)

🔍1. DetectUEBA / SIEM alert or human report
🔒2. ContainIsolate affected system / session / user
🧹3. EradicateRemove threat; rotate credentials
🔁4. RecoverRestore clean state; verify integrity
📋5. ReviewRoot cause analysis; control improvement

Scenario Playbooks

🟥 Scenario 1: Paper Leak Confirmed (Human Insider)

StepActionOwnerTime Target
1SOAR playbook: suspend all active sessions for suspect user; revoke PAM credentials; preserve session recordingsExam-SOC (auto)T+0 min
2Watermark extraction from leaked image to identify source centre and batchExam-SOC forensicsT+5 min
3Notify NTA DG, MoE security cell, CERT-In duty officerSOC duty officerT+10 min
4Police escalation: contact state SP and district police for suspect's location; begin FIRNTA legal + policeT+15 min
5Decision gate: Can exam continue with this paper? (rotate questions if pool available) or must be halted?NTA DG + MoET+20 min
6If exam halted: trigger re-examination protocol; notify candidates via official channels onlyNTA communicationsT+30 min
7Forensic evidence package prepared for legal proceedings; chain of custody documentedNTA legal + forensicsT+4 hours
8CERT-In incident report submitted (within 6-hour mandate)Exam-SOCT+6 hours
9Root cause analysis and control gap remediation planTechnical Working GroupWithin 14 days

🟥 Scenario 2: External Attacker / Cyber Intrusion

StepActionOwnerTime Target
1SIEM detects anomalous network pattern; SOAR auto-isolates affected system segment from examination networkExam-SOC (auto)T+0 min
2Activate network segmentation: exam centres switch to local HSM cache mode (offline-capable)NIC network teamT+5 min
3CERT-In cyber cell engaged for joint incident response; threat intelligence sharedExam-SOC + CERT-InT+10 min
4Verify HSM integrity via tamper evidence logs; check for key exposure; initiate key rotation if any doubtNIC HSM custodiansT+15 min
5Forensic snapshot of all affected systems before any remediation (evidence preservation)NIC forensicsT+20 min
6Attacker TTPs documented against MITRE ATT&CK; IOCs shared with CERT-InExam-SOC Threat IntelT+1 hour
7Clean rebuild of compromised systems from verified images; credential rotation across all systemsNIC operationsT+4 hours
8Exam continuation decision based on whether content or candidate data was accessedNTA DG + MoET+2 hours

🟧 Scenario 3: Biometric / Identity System Failure

SituationRollback ActionOwner
Biometric reader failure at centre gateFallback: manual document check + photo verification by two invigilators; incident logged; device flagged for replacementCentre administrator
UIDAI API unavailable (cannot verify Aadhaar)Use locally cached enrolment biometric template (pre-loaded to centre HSM at D-1); admission proceeds with local match; sync queuedCentre HSM (auto)
Biometric system compromised (fake templates injected)Halt biometric admission; revert to manual admit card + photo; escalate to Exam-SOC P1; notify UIDAI; forensic review of all admissions since compromiseExam-SOC + NTA
AI proctoring system producing false positives at scaleDisable AI proctoring; human invigilators take over; log all AI flags for manual review post-examExam-SOC duty officer

🟧 Scenario 4: HSM / Decryption Failure on Exam Day

If Centre HSM Fails

  1. Centre switches to backup HSM device (mandatory spare at each centre)
  2. Regional vault pushes re-encrypted copy to backup HSM via authenticated channel
  3. If regional vault unreachable: Exam-SOC authorises emergency decryption using split key (requires NTA DG + MoE security official simultaneously)
  4. Maximum delay tolerance before exam rescheduled at that centre: 90 minutes
  5. Physical paper backup (sealed, dual-custody) at Tier A centres only — opened under CCTV, dual authorisation, police witness

If Geo-fence / Time-lock Fails to Resolve

  1. Centre administrator contacts Exam-SOC with GPS coordinates and NTP timestamp proof
  2. SOC verifies independently using satellite imagery and network time
  3. If legitimate failure: SOC issues time-extended decryption token (one-time, 30-min window)
  4. Token requires two SOC analyst approvals and is logged immutably
  5. If geo-fence dispute: exam delayed; CERT-In notified; physical inspection of centre GPS device

🟨 Scenario 5: Physical Security Breach (On-site)

ThreatResponseExam Decision
Prohibited device (phone) found in exam hallCandidate excluded; device seized; SOC notified; dark web scan for paper content immediatelyExam continues; candidate barred
Camera offline / coveredSOC alerts centre immediately; flying squad dispatched; invigilator to visually verify hall; camera replaced if possibleExam continues if visual supervision maintained
External mob / disturbance at centrePolice on-site respond; SOC puts centre on heightened alert; exam may be suspended at that centre onlyPer NTA DG decision; re-exam at centre if disrupted
Physical paper packet seal broken before authorised timeImmediate halt; seal photo documented; police and flying squad to centre; forensic custody of packetExam cancelled at that centre; re-examination announced
Invigilator suspected of assisting candidateFlying squad replaces invigilator immediately; statement taken; legal action initiated; answer scripts of proximate candidates reviewedExam continues under new invigilator

Exam Continuation vs. Cancellation Decision Tree

Rule: An exam is cancelled only when there is reasonable evidence that exam integrity cannot be maintained going forward. A past breach does not automatically require cancellation — the question is whether the remaining exam can be conducted fairly.
SituationDecisionAuthority
Paper leaked before exam starts (confirmed)Cancel; rotate questions if pool available; otherwise rescheduleNTA DG + MoE Secretary
Paper leaked after exam has started (> 50% through)Continue exam; enhanced monitoring; full post-exam statistical analysis for affected scoresNTA DG
Single centre disrupted (physical/connectivity)Cancel at that centre; other centres unaffected; re-examination for affected candidatesNTA DG
Central system outage (SOC, HSM) lasting > 2 hours on exam daySuspend all decryptions; delay exam by 3 hours maximum; if unresolved, rescheduleNTA DG + Programme Director
Insider access confirmed but no evidence of leakContinue exam; suspect suspended; forensic investigation; result held pending clearanceNTA DG
External attacker in system but no paper access confirmedContinue exam in local HSM mode; online connectivity severed; results not released until forensics completeNTA DG + CERT-In

Post-Incident Rollback Checklist

Immediate (0–24 hours)

  • All compromised credentials rotated globally
  • Forensic snapshots taken (no system modified before this)
  • Evidence chain of custody documented
  • CERT-In notification sent (within 6-hour mandate)
  • Communication issued to candidates (factual, no speculation)
  • MoE and NESC briefed
  • Media statement coordinated through NTA communications

Short-Term (1–14 days)

  • Root cause analysis completed and reported to Steering Committee
  • Control gap identified and remediation plan drafted
  • Red team re-test of specific attack vector exploited
  • Legal proceedings initiated where applicable
  • Re-examination schedule announced if required
  • Affected candidates notified individually with clear guidance
  • Independent auditor engaged to verify remediation
Transparency requirement: Within 30 days of any P1 or P2 incident, a public incident summary (non-sensitive details) must be published by the Independent Oversight Board. Concealing a breach is itself a governance failure — the architecture is designed so that all incident records are immutable and auditable by the Oversight Board regardless of NTA or MoE preference.

Key Terms & Sources

TermDefinition
AadhaarIndia's national biometric identity system (UIDAI). 12-digit unique identity backed by fingerprint and iris biometrics for ~1.3 billion residents.
AES-256-GCMAdvanced Encryption Standard, 256-bit key, Galois/Counter Mode — symmetric encryption providing confidentiality and integrity.
CERT-InIndian Computer Emergency Response Team — national cyber incident response authority under MeitY.
CRYSTALS-KyberPost-quantum key encapsulation mechanism standardised by NIST (FIPS 203). Quantum-resistant alternative to RSA/ECDH.
CRYSTALS-DilithiumPost-quantum digital signature algorithm standardised by NIST (FIPS 204). Quantum-resistant alternative to RSA/ECDSA.
DPDP Act 2023Digital Personal Data Protection Act 2023 — India's primary data protection legislation covering biometrics and personal data processing.
EINExamination Identity Number — unique identifier assigned to every person in the examination ecosystem, linked to Aadhaar.
Exam-SOCNational Examination Security Operations Centre — 24x7 facility monitoring all examination systems.
Geo-fencingA virtual geographic boundary. Decryption of papers is permitted only when the requesting device is within the authorised boundary.
HSMHardware Security Module — FIPS 140-2 Level 3 device that generates, stores, and manages cryptographic keys in hardware. Keys never exist in plaintext outside the HSM.
IGAIdentity Governance & Administration — platform managing the lifecycle of user identities, roles, and access rights.
JIT AccessJust-In-Time Access — access rights granted only at the moment needed, for the minimum duration, automatically revoked thereafter.
MEIManaged Exam Infrastructure — the security baseline all NTA-approved examination centres must meet.
NE-PKINational Examination PKI — dedicated Public Key Infrastructure hierarchy for the examination security programme.
NICNational Informatics Centre — Government of India's primary IT infrastructure organisation under MeitY.
NIST SP 800-207NIST Special Publication on Zero Trust Architecture — the definitive guide to ZTA principles and implementation.
NTANational Testing Agency — autonomous examination authority conducting national entrance and recruitment examinations in India.
PAMPrivileged Access Management — security platform governing access by privileged users to sensitive systems and data.
SIEMSecurity Information & Event Management — platform aggregating and correlating logs to detect threats.
SOARSecurity Orchestration, Automation & Response — platform automating security response actions (session suspension, alerting, forensics).
UEBAUser and Entity Behaviour Analytics — AI/ML technology establishing behaviour baselines and alerting on deviations.
VSATVery Small Aperture Terminal — satellite communications for rural examination centres where broadband is unavailable.
Zero Trust"Never trust, always verify." All access requests are authenticated and authorised regardless of network location or user seniority.
ZSPZero Standing Privileges — no account holds permanent access; all privileges are time-limited and automatically revoked.

References

  1. National Testing Agency. Annual Report 2023–24. nta.ac.in
  2. NIST. SP 800-207: Zero Trust Architecture. 2020.
  3. NIST. FIPS 203: ML-KEM (CRYSTALS-Kyber). 2024.
  4. NIST. FIPS 204: ML-DSA (CRYSTALS-Dilithium). 2024.
  5. NIST. Cybersecurity Framework 2.0. 2024.
  6. ISO/IEC 27001:2022. Information Security Management Systems.
  7. MeitY. CERT-In Directions under Section 70B(6) of the IT Act 2000. April 2022.
  8. Ministry of Electronics & IT. Digital Personal Data Protection Act 2023.
  9. Ministry of Education. National Education Policy 2020.
  10. Ministry of Education. Public Examinations (Prevention of Unfair Means) Act 2024.
  11. Supreme Court of India. WP (Civil) No. 552/2024 — NEET-UG 2024.
  12. National Informatics Centre. GIPKI Framework. nic.in
  13. MITRE Corporation. ATT&CK Framework for Enterprise. attack.mitre.org
  14. UIDAI. Aadhaar Authentication API documentation. uidai.gov.in
  15. Trivedi, Roshan. Securing India's National Exams — Zero-Trust Reference Architecture. LinkedIn, July 2026.