A zero-trust reference architecture to prevent paper leaks, protect merit, and rebuild public trust — covering every stage from AI-assisted paper creation to post-exam destruction.
भारत की राष्ट्रीय परीक्षाओं में हर वर्ष 60 लाख से अधिक अभ्यर्थी 5,000 से अधिक केंद्रों पर सम्मिलित होते हैं। प्रश्नपत्र लीक की बार-बार होने वाली घटनाएँ यह दर्शाती हैं कि केवल प्रक्रियागत उपाय परीक्षा की अखंडता की रक्षा नहीं कर सकते। यह प्रस्ताव एक ज़ीरो ट्रस्ट (Zero Trust) सुरक्षा वास्तुकला प्रस्तुत करता है — जिसमें बायोमेट्रिक पहचान, प्रश्नपत्रों का एन्क्रिप्शन, कृत्रिम बुद्धिमत्ता (AI) आधारित निगरानी, तथा सभी केंद्रों की भौतिक सुरक्षा सम्मिलित है। तीन वर्षों की कुल लागत ₹1,419 करोड़ है — प्रति अभ्यर्थी प्रति वर्ष केवल ₹79 — जो एक भी परीक्षा रद्द होने से बचाने पर ही अपनी लागत वसूल कर लेती है।
India operates the world's largest examination infrastructure. A single paper leak cancels an exam for millions and signals that merit doesn't decide outcomes.
| Examination | Candidates (2024) | Centres | Stakes |
|---|---|---|---|
| NEET-UG | 24.06 lakh | ~4,750 | Only gateway to MBBS/BDS in India |
| JEE Main | 11.68 lakh | 500+ | Gateway to IITs, NITs, IIITs |
| CUET-UG | 13.48 lakh | 313 cities | Central university admissions |
| UGC-NET | 9+ lakh | 300+ | Lectureship & PhD eligibility |
| UPSC CSE | ~13 lakh | 72 | IAS, IPS, IFS civil services |
| SSC / Banking / Railways | 5+ crore | Thousands | Government employment |
Officials with standing access to papers leak them for financial gain. No SOP prevents a trusted insider from photographing a paper they already hold.
Papers transported without cryptographic protection can be opened and photographed mid-transit with no detection until after the exam.
Systems with weak access controls allow unauthorised bulk downloads of question bank content — often undetected without continuous monitoring.
Proxies sit examinations using forged credentials. Without biometric verification, centres cannot confirm the candidate is who they claim to be.
Without a Security Operations Centre, anomalous access at 2 AM before an exam — a classic pre-leak signal — goes completely undetected.
Current security relies on humans following rules under pressure. Architecture-level controls are not optional — they are the only reliable solution.
| Cost Category | Estimate (₹ Crore) | Notes |
|---|---|---|
| Re-examination logistics | 150–250 | Centre hiring, staff, paper, printing, transport |
| Candidate travel & accommodation | 200–400 | Millions of families absorbing repeat costs |
| Academic year delay | 300–500 | Colleges at partial capacity; delayed intake |
| Legal & judicial process | 50–100 | SC hearings, RTI responses, investigations |
| Mental health & societal impact | Unquantified | Erosion of meritocracy narrative |
| Total (single NEET-scale event) | 700–1,250+ | Conservative estimate |
| 3-year security programme | 1,419 | This proposal — breaks even on one prevented event |
Four mutually reinforcing pillars, unified by the National Exam-SOC — making a paper leak structurally impossible, not just procedurally prohibited.
Biometric verification, zero standing privileges, and just-in-time access for every person who touches an examination. No account — including administrator accounts — holds permanent access to examination content. All access is JIT, dual-authorised, time-limited, and auto-revoked.
PAM platform vaults all privileged credentials. Full session recording. Critical operations require two people to authenticate simultaneously. Re-authentication every 15 minutes.
Papers encrypted from AI-assisted authoring through HSM vaulting to geo-fenced, time-locked decryption at the exam hall. Three simultaneous conditions required for decryption: correct GPS location, authorised time window, two authenticated administrators. Fail any one — paper stays encrypted.
Digital watermarking: every copy carries a unique invisible watermark encoding centre ID, session, and batch. If a photo leaks online, forensic extraction identifies the source centre within minutes.
AI-driven UEBA establishes behaviour baselines for every user. Deviations — after-hours access, bulk downloads, unusual location — trigger automated risk scoring. 24×7 National Exam-SOC with SIEM/SOAR. 20 pre-built response playbooks execute automatically in under 2 minutes. Dark web and social media monitoring for paper leaks round the clock.
Every centre hardened with certificate-enrolled cameras, metal detectors, signal management, and immutable digital chain of custody. Dedicated encrypted network per centre. Local HSM cache device. Computer vision proctoring at Tier A centres. GPS tamper detection on all physical paper packets.
Questions are created through a secure, AI-augmented process with mandatory human oversight at every gate. Paper setters work in physical isolation on air-gapped NTA terminals — no personal devices, no internet, no external communication.
| Control | Tier A (Urban, 500) | Tier B (District, 2,000) | Tier C (Rural, 2,500) |
|---|---|---|---|
| Network | Dedicated MPLS | VPN + LTE failover | VSAT satellite primary |
| Endpoints | Locked-down terminals, EDR, signed OS | Same | Same |
| Local HSM cache | ✅ | ✅ | ✅ |
| Camera enrollment | Full certificate-based | Full | Full |
| AI proctoring | AI-assisted + human | Human primary | Human primary |
| Power backup | 4-hour UPS + generator | 2-hour UPS | 2-hour UPS |
| GPS tamper device | ✅ | ✅ | ✅ |
Every step from the moment a question is generated to the moment all copies are destroyed — secured, logged, and automated.
Paper setters enter isolation protocol. Devices surrendered. Work only on air-gapped NTA terminals. No external communication.
AI generates question pool. SMEs review, edit, and digitally sign approved questions. Multi-layer moderation. Final paper signed and encrypted into HSM immediately.
NTA teams inspect all centres. MEI compliance check. Non-compliant centres decertified and replaced.
Randomised centre assignments generated. Invigilators informed only of exam date — not centre — until D-1.
Encrypted paper files distributed from NIC vault to regional secure vaults via certificate-authenticated channels. Chain of custody hash recorded at every hop.
State police duty officers briefed. Cyber cells put on standby. Flying squad routes assigned. CERT-In duty officer notified.
Exam centre sealed. Only authorised staff with pre-enrolled identity may enter. CCTV recording begins continuous loop.
All exam terminals, biometric devices, cameras, and network connections verified. HSM local cache loaded. Exam-SOC confirms centre readiness.
Invigilators receive their centre assignment via encrypted notification. Must report at T-2 hours on exam day.
All Tier 1 & Tier 2 analysts on shift. Real-time dashboard live. Dark web channel active. CERT-In duty officer confirmed.
Biometric verification at gate. QR admit ticket scanned. Fingerprint + face match against enrolment record. Metal detector sweep. Signal management zone active.
Geo-fencing confirmed. Time window authorised. Two centre administrators authenticate simultaneously. Paper decrypts. Watermark confirmed.
Computer vision proctoring active. Human invigilators monitoring. Any phone or prohibited device detected triggers immediate alert. Police stationed at perimeter.
Dual-authorised collection. Digital chain of custody recorded. Scanned on-site. Physical sheets sealed under CCTV and transported under GPS tracking.
| Stage | Location | Protection | Access Control |
|---|---|---|---|
| Authoring | Air-gapped NTA terminal | No network; device certificate; encrypted local storage | SME biometric + PAM |
| Post-signing (master) | NIC National HSM Vault (primary + DR) | HSM-encrypted; FIPS 140-2 L3; M-of-N key ceremony | DG NTA + 2 custodians |
| Regional distribution | Regional NIC Secure Vault (4 regions) | AES-256-GCM; regional key fragment | Regional NTA officer |
| Centre cache | Centre HSM local cache device | Encrypted; geo-locked; time-locked | Two admins + geo-fence + time window |
| Post-exam (digital) | NIC archive vault | 7-year retention; WORM storage | Legal/RTI access only; dual authorised |
| Physical copies | Centre vault → shredding facility | Tamper-evident seal; GPS tracked | Dual-authorised shredding within 24h |
| Activity | Automation | Human Role |
|---|---|---|
| UEBA risk scoring | Fully automated (AI) | Review alerts above threshold |
| Session suspension (risk >85) | Automated | SOC analyst confirms within 5 min |
| Paper decryption | Automated (time + geo check) | Two admins must authenticate |
| CERT-In notification | Automated (SOAR playbook) | SOC manager reviews before send |
| Watermark extraction | Automated (image analysis) | Forensics analyst confirms |
| Camera health monitoring | Automated (SOC dashboard) | SOC alerts centre if outage |
| Chain of custody logging | Fully automated (immutable log) | Auditor reviews post-exam |
| Biometric gate entry | Automated match | Officer verifies failures |
| FIR / legal action | Not automated | NTA Director + legal team |
| Paper shredding | Not automated | Dual-authorised (mandatory) |
Students, teachers, invigilators, and surveillance devices all have verified, audited digital identities. No anonymous access. No standing privileges.
| Document | Purpose | Verification |
|---|---|---|
| Aadhaar Card | Primary identity anchor | UIDAI API real-time check |
| Class 10 / 12 Marksheet | Eligibility confirmation | DigiLocker pull from Board |
| Category Certificate | Reservation eligibility | Issuing authority digital stamp |
| Passport photograph | Visual identity | AI face quality check + liveness |
| Mobile number | OTP-based 2FA | Telecom KYC verification |
| Email address | Communication | Verified via OTP |
| Signature | Consent & legal declaration | Stored; matched at exam hall |
Candidate submits form; Aadhaar number verified against UIDAI in real time. Name and DOB must match exactly.
Marksheets pulled from DigiLocker. Photo checked for quality, liveness, and consistency with Aadhaar photo.
For high-stakes exams: candidate attends an enrolment centre. Fingerprints + iris captured and linked to their Examination Identity Number (EIN).
Time-limited digitally signed QR code (valid 24 hours before exam). Contains encrypted biometric reference. Cannot be forged or transferred.
QR scanned at gate. Fingerprint matched to enrolment record. Face verified by AI camera. Seat assigned by randomised system on exam morning only.
Each CCTV, biometric reader, and exam terminal is issued a unique device certificate from NE-PKI. Device must present this certificate to connect to NTA systems.
Cover attempts, power interruptions, or physical movement trigger an immediate Exam-SOC alert. Any camera offline >2 minutes on exam day triggers police notification.
Video feeds are checked for looping signatures and static image patterns. A looped recording from a compromised camera is detectable by frame-fingerprint analysis.
A security architecture is only credible if it is built from a clear picture of who the adversaries are, what they want, and what they can do. This is the analysis a government evaluation committee looks for first.
| Adversary | Motivation | Capability | Primary Vector |
|---|---|---|---|
| Malicious insider (setter / admin) | Financial gain, coercion | High — legitimate access | Exfiltrate content they can access |
| Organised leak syndicate | Profit (sell papers / proxies) | High — funded, persistent | Bribe insiders; impersonation rings |
| External cyber attacker | Profit, notoriety, disruption | Medium–High | Exploit systems, phishing, malware |
| Nation-state actor | Strategic institutional disruption | Very high | Supply chain, zero-days, persistence |
| Opportunist candidate | Personal advantage | Low | Devices, impersonation, copying |
| Compromised vendor | Varies (often unwitting) | Medium | Supply-chain implant, weak update |
| Category | Example Threat | Primary Mitigation |
|---|---|---|
| Spoofing | Proxy candidate; forged admit card; fake camera feed | Biometric + liveness; signed QR; device certs + anti-spoof |
| Tampering | Paper altered in transit; log manipulation | HSM signing; immutable WORM log; hash chain of custody |
| Repudiation | Insider denies accessing a paper | PAM session recording; non-repudiable digital signatures |
| Information Disclosure | Paper leak; PII exposure | AES-256-GCM; ZSP; geo/time-locked decryption; watermarking |
| Denial of Service | Exam-day outage; network attack | Offline HSM cache; DR failover; DDoS protection |
| Elevation of Privilege | Admin escalates to key access | Zero standing privileges; JIT + dual auth; M-of-N keys |
Likelihood (L) & Impact (I) scored 1–5. Inherent = before controls; Residual = after this architecture's controls.
| ID | Risk | L | I | Inherent | Key Control | Residual |
|---|---|---|---|---|---|---|
| R1 | Insider leaks pre-exam paper | 4 | 5 | 20 Critical | ZSP, PAM, watermarking, UEBA | 6 Medium |
| R2 | Paper intercepted in distribution | 3 | 5 | 15 High | End-to-end encryption, hash custody | 3 Low |
| R3 | Candidate impersonation | 4 | 4 | 16 High | Biometric + liveness at gate | 4 Low |
| R4 | Cyber intrusion into exam systems | 3 | 5 | 15 High | Zero Trust, SOC, segmentation | 4 Low |
| R5 | AI paper-tool manipulated | 3 | 5 | 15 High | Air-gap, human gates, output validation | 3 Low |
| R6 | Biometric data breach | 2 | 5 | 10 High | Encryption, DPDP controls, no export | 3 Low |
| R7 | Exam-day system outage | 3 | 4 | 12 High | Offline cache, DR, UPS | 4 Low |
| R8 | Supply-chain compromise | 2 | 5 | 10 High | SBOM, sovereign sourcing, audit | 4 Low |
| R9 | Physical breach at centre | 3 | 3 | 9 Medium | MEI, police, signal mgmt, CCTV | 3 Low |
| R10 | Collusion (multiple insiders) | 2 | 5 | 10 High | Separation of duties, M-of-N, red team | 4 Low |
Because AI assists paper creation, proctoring, and anomaly detection, AI itself is an attack surface. Any modern reviewer will ask how it is secured. Here is the answer.
Air-gapped model, sanitised templated prompts, no free-text external input, and output validation prevent the model being steered to leak or bias content.
The syllabus corpus is signed, version-controlled, and integrity-hashed. Every generated question is reviewed by human subject experts.
Liveness detection, multi-modal biometrics (fingerprint + iris + face), and challenge-response defeat synthetic face/voice attacks.
On-premise sovereign hosting, no public API, PAM-gated access, and query-rate monitoring prevent extraction of question patterns.
Mandatory dual-SME approval and a moderation gate mean no unreviewed AI question is ever used in a live paper.
AI assistance can be disabled instantly, reverting to a fully manual, human-only workflow with no loss of security.
| Control | Requirement |
|---|---|
| Model registry | Every model version registered, signed, and traceable with an approved-use record |
| Model risk assessment | Bias, fairness, robustness, and adversarial testing before deployment |
| Explainability | Proctoring and anomaly models must justify every flag in human-readable terms |
| Sovereign hosting | All models run on Govt of India (MeghRaj / GI Cloud) or NIC — no foreign cloud, no external LLM API |
| Continuous red-teaming | The AI paper tool is adversarially tested each cycle for injection and leakage |
| Audit logging | Every prompt, output, and human decision logged immutably for post-exam audit |
Aligned to the NIST AI Risk Management Framework and OWASP Top 10 for LLM Applications.
A three-tier governance structure with clear accountability at each level, independent oversight, and public transparency reporting.
| Body | Chair & Members | Authority | Cadence |
|---|---|---|---|
| National Examination Security Council (NESC) (proposed) | MoE Secretary (Chair), DG NTA, DG NIC, DG CERT-In, retired SC judge, 2 independent experts | Final policy authority; approves architecture changes; reviews audit reports | Quarterly + emergency |
| Programme Steering Committee | NTA Director General (Chair), NIC Programme Director, CERT-In rep | Operational decisions; budget releases; vendor approvals; escalation | Monthly |
| Technical Working Group | Lead architects (NTA + NIC), Exam-SOC lead, PAM admin | Technical design, configuration changes, playbook revisions | Weekly |
| State Security Coordinator | State-level officer liaising with NTA and district police | Centre compliance; local police coordination | Per exam cycle |
| Independent Oversight Board | 2 academics, 1 retired IPS, 1 civil society rep, 1 student rep | Watchdog; review annual audit; publish public transparency report | Annual |
| Audit Type | Timing | Auditor | Scope |
|---|---|---|---|
| Centre inspection | D-30 | NTA inspection team | MEI compliance, physical security, device certification |
| System readiness | D-1 | Exam-SOC | All systems green, HSM health, connectivity |
| Real-time monitoring | Exam day | Exam-SOC | All centres, all systems, all access events |
| Post-exam debrief | Within 4 hours | SOC + NTA ops | Incidents, near-misses, custody complete? |
| Chain of custody audit | Within 7 days | NTA Internal Audit | Every event in immutable log verified |
| Independent security audit | Annual | NABCB-accredited auditor | ISO 27001 surveillance; full system review |
| Red team exercise | Bi-annual | External red team | Full attempt to compromise system using real TTPs |
| Parliamentary transparency | Annual | Independent Oversight Board | Public KPI report; incident summary |
| Class | Examples | Controls |
|---|---|---|
| Top Secret | Question papers (pre-exam) | HSM-only; dual auth; zero standing access |
| Secret | Biometric data; PAM recordings | Encrypted; PAM-controlled; no export |
| Confidential | Candidate PII; staff identity | Encrypted; DPDP consent required |
| Internal | SOC logs; audit trails | Encrypted; 7-year WORM retention |
| Public | Exam schedules; results | Digitally signed; integrity-verified |
Candidates with identical wrong answers (beyond statistical probability) are flagged. Seat adjacency mapping identifies suspected copying rings.
Unusual registration clusters from a single locality, coaching centre, or IP address range are flagged as potential proxy rings.
Social network analysis of registration data identifies clusters linked by phone number, email domain, payment instrument, or device fingerprint — signals of organised fraud.
Candidates completing an exam in statistically abnormal time (too fast, or with suspiciously consistent response cadence) are flagged for review.
Statistically improbable score jumps between attempts, or scores inconsistent with prior academic record, trigger secondary identity verification.
ML models trained on historical leak incidents identify early warning signatures — access pattern changes in the weeks before an exam that preceded past leaks.
The decisive question for any government committee: is this certifiable and legally compliant? Every control maps to a recognised framework or statute — the system is designed to be audited, not just admired.
| Function | How This Architecture Satisfies It |
|---|---|
| Govern | NESC, Steering Committee, Oversight Board; documented policy and RACI |
| Identify | Threat model, risk register, asset & data classification |
| Protect | Zero Trust, PAM, HSM/PKI encryption, MEI hardening, ZSP |
| Detect | UEBA, SIEM, dark-web monitoring, 24×7 Exam-SOC |
| Respond | SOAR playbooks, breach-response scenarios, CERT-In notification |
| Recover | BCP/DR, backups, rollback checklist, re-examination protocol |
| Instrument | Obligation | How It Is Met |
|---|---|---|
| DPDP Act 2023 | Lawful processing of personal & biometric data | Consent, purpose limitation, minimisation, 6-hour breach notice, erasure at 3 years, DPIA |
| CERT-In Directions 2022 | 6-hour incident reporting; log retention | SOAR auto-notification; 180-day+ logs; ICT clock sync |
| IT Act 2000 | Legal validity of e-records & signatures | NE-PKI digital signatures; non-repudiation; Sec. 43A reasonable security |
| Public Examinations Act 2024 | Criminalises leaks & organised cheating | Watermark forensics + immutable logs give court-admissible evidence |
| Aadhaar Act & UIDAI regs | Lawful, minimal Aadhaar use | Authentication-only (no number storage beyond token); UIDAI-compliant APIs |
Closing the grey areas experienced reviewers probe: continuity when systems fail, a trusted supply chain, independent proof of security, privacy in law and practice, and inclusion of every eligible candidate.
| System | RTO | RPO | Resilience Measure |
|---|---|---|---|
| Paper decryption at centre | 0 (no downtime) | 0 | Offline local HSM cache; backup HSM device per centre |
| National HSM vault | < 15 min | 0 | Active-active primary + DR site; M-of-N key recovery |
| Exam-SOC | < 5 min | < 1 min | Redundant hot-standby SOC in second region |
| Identity / biometric service | < 10 min | < 5 min | Cached templates at centre; queued sync on recovery |
| Network (per centre) | < 5 min | N/A | VPN + LTE + VSAT failover by tier |
Backups follow a 3-2-1 strategy (3 copies, 2 media, 1 off-site, all encrypted). DR drills run quarterly with documented recovery-time evidence.
A mandatory Data Protection Impact Assessment before processing, refreshed annually. Data minimisation, purpose limitation, biometric templates deleted 3 years post-exam, consent at registration, and data localisation within India. A Data Protection Officer answers to the Oversight Board.
Persons with disabilities (Divyang) get vetted, biometrically-enrolled scribes, extra time, and assistive tech. Rural candidates use VSAT + offline cache. Multi-language papers are each separately watermarked. Every accommodation preserves full cryptographic control.
| Level | Stage | Milestone |
|---|---|---|
| 1 — Initial | Today | Procedural controls; no continuous monitoring |
| 2 — Managed | End of Phase 1 | SOC live; PAM & HSM deployed; pilot centres |
| 3 — Defined | End of Phase 2 | Standardised controls across 2,500 centres; universal watermarking |
| 4 — Quantified | End of Phase 3 | All 5,000 centres; measured KPIs; ISO 27001 certified |
| 5 — Optimising | Year 4+ | Continuous red-teaming; post-quantum crypto; predictive threat intel |
A phased programme with clear milestones, ₹1,419 crore budget, RACI accountability, and measurable KPIs.
₹385 crore
₹539 crore
₹495 crore
| Budget Line | Phase 1 (₹Cr) | Phase 2 (₹Cr) | Phase 3 (₹Cr) | Total (₹Cr) |
|---|---|---|---|---|
| National Exam-SOC | 80 | 40 | 20 | 140 |
| HSM / PKI infrastructure | 60 | 30 | 20 | 110 |
| PAM platform | 30 | 10 | 5 | 45 |
| SIEM / SOAR | 40 | 20 | 10 | 70 |
| UEBA platform | 25 | 10 | 5 | 40 |
| Biometric enrolment & devices | 20 | 60 | 40 | 120 |
| MEI — Tier A (500 centres) | 75 | 0 | 0 | 75 |
| MEI — Tier B (2,000 centres) | 0 | 240 | 0 | 240 |
| MEI — Tier C (2,500 centres) | 0 | 0 | 250 | 250 |
| Computer vision proctoring | 0 | 50 | 30 | 80 |
| Rural VSAT connectivity | 0 | 0 | 50 | 50 |
| Training & change management | 15 | 20 | 10 | 45 |
| Audits & red team | 5 | 10 | 10 | 25 |
| Contingency (10%) | 35 | 49 | 45 | 129 |
| TOTAL | 385 | 539 | 495 | 1,419 |
| KPI | Baseline | Year 1 | Year 3 |
|---|---|---|---|
| Paper leak incidents / year | 3–5 | ≤ 1 | 0 |
| Exam cancellations due to leaks | 1–2 / year | 0 | 0 |
| Mean time to detect anomaly | Unknown | < 30 min | < 5 min |
| Staff with zero standing privileges | 0% | 80% | 100% |
| Centres at MEI baseline | 0% | 20% | 100% |
| Papers with digital watermark | 0% | 100% | 100% |
| Biometric false rejection rate | N/A | < 0.5% | < 0.1% |
| System uptime on exam day | ~95% | 99.5% | 99.9% |
| Staff trained in security awareness | 0% | 70% | 100% |
| Annual independent audit completed | No | Yes | Yes |
| Activity | MoE | NTA | NIC | CERT-In | Centres | Auditors |
|---|---|---|---|---|---|---|
| Define security policy | A | R | C | C | I | I |
| Architecture design | C | A | R | C | I | C |
| Deploy HSM / NE-PKI | I | C | A/R | C | I | C |
| Operate Exam-SOC | I | A | R | C | I | I |
| Respond to cyber incidents | I | A | R | R | C | I |
| Centre MEI deployment | I | A | R | I | R | C |
| Annual security audits | A | C | C | C | C | R |
| SME selection & isolation | I | A/R | C | I | I | I |
| Police coordination | C | A | I | C | R | I |
| Public transparency report | A | R | I | I | I | C |
Security architecture cannot guarantee zero incidents — it guarantees a structured, fast, and documented response that limits damage, preserves evidence, and restores integrity. This plan covers human insiders, external attackers, and automated/AI threats.
| Severity | Description | Response Time | Decision Authority |
|---|---|---|---|
| P1 — Critical | Paper leak confirmed; HSM compromise; biometric system breach; active attacker in exam systems | Immediate (< 5 min) | Exam-SOC duty officer (auto-contain) + NTA DG notified |
| P2 — High | Suspected leak; credential theft; camera system outage; insider access anomaly above UEBA threshold 85 | < 15 min | Exam-SOC Tier 2 analyst + NTA security head |
| P3 — Medium | Single centre connectivity failure; device tamper alert; failed biometric above baseline; suspicious login | < 30 min | Exam-SOC Tier 1 analyst |
| P4 — Low | Individual access anomaly; failed login attempts below threshold; minor physical irregularity | < 2 hours | SOC alert queue |
| Step | Action | Owner | Time Target |
|---|---|---|---|
| 1 | SOAR playbook: suspend all active sessions for suspect user; revoke PAM credentials; preserve session recordings | Exam-SOC (auto) | T+0 min |
| 2 | Watermark extraction from leaked image to identify source centre and batch | Exam-SOC forensics | T+5 min |
| 3 | Notify NTA DG, MoE security cell, CERT-In duty officer | SOC duty officer | T+10 min |
| 4 | Police escalation: contact state SP and district police for suspect's location; begin FIR | NTA legal + police | T+15 min |
| 5 | Decision gate: Can exam continue with this paper? (rotate questions if pool available) or must be halted? | NTA DG + MoE | T+20 min |
| 6 | If exam halted: trigger re-examination protocol; notify candidates via official channels only | NTA communications | T+30 min |
| 7 | Forensic evidence package prepared for legal proceedings; chain of custody documented | NTA legal + forensics | T+4 hours |
| 8 | CERT-In incident report submitted (within 6-hour mandate) | Exam-SOC | T+6 hours |
| 9 | Root cause analysis and control gap remediation plan | Technical Working Group | Within 14 days |
| Step | Action | Owner | Time Target |
|---|---|---|---|
| 1 | SIEM detects anomalous network pattern; SOAR auto-isolates affected system segment from examination network | Exam-SOC (auto) | T+0 min |
| 2 | Activate network segmentation: exam centres switch to local HSM cache mode (offline-capable) | NIC network team | T+5 min |
| 3 | CERT-In cyber cell engaged for joint incident response; threat intelligence shared | Exam-SOC + CERT-In | T+10 min |
| 4 | Verify HSM integrity via tamper evidence logs; check for key exposure; initiate key rotation if any doubt | NIC HSM custodians | T+15 min |
| 5 | Forensic snapshot of all affected systems before any remediation (evidence preservation) | NIC forensics | T+20 min |
| 6 | Attacker TTPs documented against MITRE ATT&CK; IOCs shared with CERT-In | Exam-SOC Threat Intel | T+1 hour |
| 7 | Clean rebuild of compromised systems from verified images; credential rotation across all systems | NIC operations | T+4 hours |
| 8 | Exam continuation decision based on whether content or candidate data was accessed | NTA DG + MoE | T+2 hours |
| Situation | Rollback Action | Owner |
|---|---|---|
| Biometric reader failure at centre gate | Fallback: manual document check + photo verification by two invigilators; incident logged; device flagged for replacement | Centre administrator |
| UIDAI API unavailable (cannot verify Aadhaar) | Use locally cached enrolment biometric template (pre-loaded to centre HSM at D-1); admission proceeds with local match; sync queued | Centre HSM (auto) |
| Biometric system compromised (fake templates injected) | Halt biometric admission; revert to manual admit card + photo; escalate to Exam-SOC P1; notify UIDAI; forensic review of all admissions since compromise | Exam-SOC + NTA |
| AI proctoring system producing false positives at scale | Disable AI proctoring; human invigilators take over; log all AI flags for manual review post-exam | Exam-SOC duty officer |
| Threat | Response | Exam Decision |
|---|---|---|
| Prohibited device (phone) found in exam hall | Candidate excluded; device seized; SOC notified; dark web scan for paper content immediately | Exam continues; candidate barred |
| Camera offline / covered | SOC alerts centre immediately; flying squad dispatched; invigilator to visually verify hall; camera replaced if possible | Exam continues if visual supervision maintained |
| External mob / disturbance at centre | Police on-site respond; SOC puts centre on heightened alert; exam may be suspended at that centre only | Per NTA DG decision; re-exam at centre if disrupted |
| Physical paper packet seal broken before authorised time | Immediate halt; seal photo documented; police and flying squad to centre; forensic custody of packet | Exam cancelled at that centre; re-examination announced |
| Invigilator suspected of assisting candidate | Flying squad replaces invigilator immediately; statement taken; legal action initiated; answer scripts of proximate candidates reviewed | Exam continues under new invigilator |
| Situation | Decision | Authority |
|---|---|---|
| Paper leaked before exam starts (confirmed) | Cancel; rotate questions if pool available; otherwise reschedule | NTA DG + MoE Secretary |
| Paper leaked after exam has started (> 50% through) | Continue exam; enhanced monitoring; full post-exam statistical analysis for affected scores | NTA DG |
| Single centre disrupted (physical/connectivity) | Cancel at that centre; other centres unaffected; re-examination for affected candidates | NTA DG |
| Central system outage (SOC, HSM) lasting > 2 hours on exam day | Suspend all decryptions; delay exam by 3 hours maximum; if unresolved, reschedule | NTA DG + Programme Director |
| Insider access confirmed but no evidence of leak | Continue exam; suspect suspended; forensic investigation; result held pending clearance | NTA DG |
| External attacker in system but no paper access confirmed | Continue exam in local HSM mode; online connectivity severed; results not released until forensics complete | NTA DG + CERT-In |
| Term | Definition |
|---|---|
| Aadhaar | India's national biometric identity system (UIDAI). 12-digit unique identity backed by fingerprint and iris biometrics for ~1.3 billion residents. |
| AES-256-GCM | Advanced Encryption Standard, 256-bit key, Galois/Counter Mode — symmetric encryption providing confidentiality and integrity. |
| CERT-In | Indian Computer Emergency Response Team — national cyber incident response authority under MeitY. |
| CRYSTALS-Kyber | Post-quantum key encapsulation mechanism standardised by NIST (FIPS 203). Quantum-resistant alternative to RSA/ECDH. |
| CRYSTALS-Dilithium | Post-quantum digital signature algorithm standardised by NIST (FIPS 204). Quantum-resistant alternative to RSA/ECDSA. |
| DPDP Act 2023 | Digital Personal Data Protection Act 2023 — India's primary data protection legislation covering biometrics and personal data processing. |
| EIN | Examination Identity Number — unique identifier assigned to every person in the examination ecosystem, linked to Aadhaar. |
| Exam-SOC | National Examination Security Operations Centre — 24x7 facility monitoring all examination systems. |
| Geo-fencing | A virtual geographic boundary. Decryption of papers is permitted only when the requesting device is within the authorised boundary. |
| HSM | Hardware Security Module — FIPS 140-2 Level 3 device that generates, stores, and manages cryptographic keys in hardware. Keys never exist in plaintext outside the HSM. |
| IGA | Identity Governance & Administration — platform managing the lifecycle of user identities, roles, and access rights. |
| JIT Access | Just-In-Time Access — access rights granted only at the moment needed, for the minimum duration, automatically revoked thereafter. |
| MEI | Managed Exam Infrastructure — the security baseline all NTA-approved examination centres must meet. |
| NE-PKI | National Examination PKI — dedicated Public Key Infrastructure hierarchy for the examination security programme. |
| NIC | National Informatics Centre — Government of India's primary IT infrastructure organisation under MeitY. |
| NIST SP 800-207 | NIST Special Publication on Zero Trust Architecture — the definitive guide to ZTA principles and implementation. |
| NTA | National Testing Agency — autonomous examination authority conducting national entrance and recruitment examinations in India. |
| PAM | Privileged Access Management — security platform governing access by privileged users to sensitive systems and data. |
| SIEM | Security Information & Event Management — platform aggregating and correlating logs to detect threats. |
| SOAR | Security Orchestration, Automation & Response — platform automating security response actions (session suspension, alerting, forensics). |
| UEBA | User and Entity Behaviour Analytics — AI/ML technology establishing behaviour baselines and alerting on deviations. |
| VSAT | Very Small Aperture Terminal — satellite communications for rural examination centres where broadband is unavailable. |
| Zero Trust | "Never trust, always verify." All access requests are authenticated and authorised regardless of network location or user seniority. |
| ZSP | Zero Standing Privileges — no account holds permanent access; all privileges are time-limited and automatically revoked. |