Appendix H — Program Atlas · The People's Model — Manifesto v2026

Appendix H — Program Atlas

Each sheet to the 8-section template + 4-point QA bar (defined inline in Vol III App H Education, the format-reference sector).

Read this chapter in the interactive reader, or download the full 601-page manifesto (PDF).


The People’s Model

Manifesto v2026

Volume III — Implementation Handbook

Appendix H — Program Atlas

Cybersecurity & DPI sector — sheets H.145–H.162 + H.230–H.233 (v1.0)

Each sheet to the 8-section template + 4-point QA bar (defined inline in Vol III App H Education, the format-reference sector).

Problem

Karnataka’s spine + departmental systems lack a centralised, 24/7 SOC. Incidents are detected late and responded to slowly.

Program design

Owning agency

Lead: Department of IT, BT & Science (Cyber wing) + Karnataka State Wide Area Network team

Backup: CERT-In partnership

Funding model

Annual cost band: ₹80-150 cr / year

Source: State Budget; central cybersecurity-modernisation share.

Payment trigger: Per-incident detection / containment evidence.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka government IT procurements often lack consistent security standards. Vendor-side breaches become state breaches.

Program design

Owning agency

Lead: Department of IT, BT & Science

Backup: Karnataka State SOC

Funding model

Annual cost band: ₹50-90 cr / year (standards + audit capacity)

Source: State Budget; convergence with KPPP procurement reforms.

Payment trigger: Per-procurement audit + post-deployment compliance evidence.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka residents have no continuous visibility / control over what data the state holds and shares about them. The Consent Vault is the operating expression of Vol I Ch 6 governance.

Program design

Owning agency

Lead: Department of IT, BT & Science + Citizen Data Trust

Backup: ABDM / ABHA integration (where applicable)

Funding model

Annual cost band: ₹60-100 cr / year

Source: State Budget; convergence with Account Aggregator framework.

Payment trigger: Per-consent grant / revoke event + audit-trail evidence.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka spine + departmental systems have unknown vulnerabilities. External researcher engagement is informal and sometimes adversarial.

Program design

Owning agency

Lead: Karnataka State SOC

Backup: Department of IT, BT & Science

Funding model

Annual cost band: ₹30-60 cr / year (bounties + admin)

Source: State Budget; CERT-In convergence.

Payment trigger: Per-disclosure triage + patch evidence.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka government cybersecurity incidents are inconsistently disclosed. Trust is eroded by opacity more than by incidents themselves.

Program design

Owning agency

Lead: Karnataka State SOC + Citizen Data Trust

Backup: KIC (transparency oversight)

Funding model

Annual cost band: ₹20-40 cr / year

Source: State Budget; convergence with Public Information Charter.

Payment trigger: Per-incident disclosure + post-incident publication.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka cybercrime volume grows faster than investigation capability. Citizen victims of fraud, harassment, identity theft wait long for action.

Program design

Owning agency

Lead: Karnataka State Police (Cyber Crime wing)

Backup: Centre for Cyber-Forensic Sciences

Funding model

Annual cost band: ₹120-180 cr / year

Source: State Budget; Centre share.

Payment trigger: Per-case enrolment + investigation stage evidence.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka residents face rising digital-fraud exposure (UPI fraud, phishing, deepfake, account-takeover). Literacy is uneven.

Program design

Owning agency

Lead: Department of IT, BT & Science + Department of School Education

Backup: Karnataka State Civic Network (sheet H.142)

Funding model

Annual cost band: ₹100-160 cr / year

Source: State Budget; CERT-In + RBI awareness convergence.

Payment trigger: Per-module participation + reported-fraud trend.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka departments integrate identity (Aadhaar, DigiLocker, ABHA) ad-hoc. Inconsistent integration creates seams that residents and vendors exploit.

Program design

Owning agency

Lead: Department of IT, BT & Science

Backup: Citizen Data Trust

Funding model

Annual cost band: ₹30-60 cr / year

Source: State Budget; ABDM convergence.

Payment trigger: Per-integration audit + library-release evidence.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka residents carry the burden of producing the same documents to multiple departments. DigiLocker exists nationally but state integration is uneven.

Program design

Owning agency

Lead: Department of IT, BT & Science

Backup: Citizen Data Trust

Funding model

Annual cost band: ₹50-90 cr / year

Source: State Budget; DigiLocker convergence.

Payment trigger: Per-document issuance + consent event.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka government payments (welfare, refund, subsidy) still bottleneck on legacy rails. UPI / Account Aggregator integration is uneven.

Program design

Owning agency

Lead: Department of Finance + Department of IT

Backup: RBI / NPCI partnership

Funding model

Annual cost band: ₹60-100 cr / year

Source: State Budget; convergence with PFMS + DBT.

Payment trigger: Per-transaction event + audit-trail evidence.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka public-sector cybersecurity cadre is thin and uncompetitive against private sector. Cadre churn compounds vulnerability.

Program design

Owning agency

Lead: Department of IT, BT & Science (HR cell)

Backup: Karnataka State SOC

Funding model

Annual cost band: ₹80-130 cr / year

Source: State Budget; convergence with central cyber-skill schemes.

Payment trigger: Per-cadre member onboarding + retention data.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka departments + private sector face overlapping threats but share intelligence informally. Pattern-detection is delayed.

Program design

Owning agency

Lead: Karnataka State SOC

Backup: Department of IT, BT & Science

Funding model

Annual cost band: ₹30-60 cr / year

Source: State Budget; CERT-In convergence.

Payment trigger: Per-IoC publication + downstream-action evidence.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka’s critical infrastructure (power, water, transport, health) faces sophisticated cyber threats. Resilience standards are uneven.

Program design

Owning agency

Lead: Karnataka State SOC + NCIIPC liaison

Backup: Sector regulators (ESCOMs, BWSSB, etc.)

Funding model

Annual cost band: ₹100-160 cr / year

Source: State Budget; sector regulator capex.

Payment trigger: Per-CII audit + exercise completion.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka department IT deployments use varied cloud / on-prem patterns. Security defaults are uneven; configuration drift is common.

Program design

Owning agency

Lead: Department of IT, BT & Science

Backup: Karnataka State SOC

Funding model

Annual cost band: ₹40-80 cr / year

Source: State Budget; convergence with MeghRaj.

Payment trigger: Per-deployment pattern adoption + audit evidence.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka faces growing demand for cross-dataset analysis (health × education × welfare) but privacy risks rise with each join. Privacy-enhancing computation (PEC) — differential privacy, secure enclaves, federated learning — is under-piloted.

Program design

Owning agency

Lead: Department of IT, BT & Science + Citizen Data Trust

Backup: Karnataka State Statistics Department

Funding model

Annual cost band: ₹30-60 cr / year

Source: State Budget; partnership funding.

Payment trigger: Per-pilot enrolment + outcome publication.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka government services have uneven API surfaces for citizen-tech developers to build on. Civic-tech ecosystem is constrained.

Program design

Owning agency

Lead: Department of IT, BT & Science

Backup: Karnataka Innovation Authority

Funding model

Annual cost band: ₹60-100 cr / year

Source: State Budget; convergence with sheet H.130 Open Data.

Payment trigger: Per-API publication + developer-engagement data.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka digital service assisted-access (PSC, kiosk, operator) is a critical reliability layer. When it fails, the resident has nowhere to go.

Program design

Owning agency

Lead: Department of IT, BT & Science + Department of Rural Development

Backup: Department of Urban Development (ward kiosks)

Funding model

Annual cost band: ₹80-130 cr / year

Source: State Budget; convergence with PSC funding.

Payment trigger: Per-channel uptime + per-transaction success-rate.

KPIs

Standard risk controls

Dependencies

Problem

Karnataka children and youth face online harms (CSAM, cyberbullying, grooming, dark-pattern manipulation). Response capacity is thin.

Program design

Owning agency

Lead: Karnataka State Commission for Protection of Child Rights + KSP Cybercrime

Backup: Department of School Education & Literacy

Funding model

Annual cost band: ₹60-100 cr / year

Source: State Budget; Centre child-protection convergence.

Payment trigger: Per-report response + curriculum-delivery data.

KPIs

Standard risk controls

Dependencies

Sheet H.230 — Karnataka State Service Log (KSSL): cryptographic anchoring layer

Problem

Karnataka’s digital state generates millions of records every day across hundreds of systems — service requests, payment instructions, AI decisions, log entries. Without a single anchoring layer, integrity of these records depends on trust in each operating department. Tampering is hard to detect; cross-system reconciliation is manual; civil-society audit is bounded by what each department chooses to expose.

Program design

KSSL is the state’s single mediation and logging layer. Every inter-system call across state digital services routes through KSSL, generating a log entry: actor, time, action, data fields accessed, reason. Entries are hashed, batched at defined cadence, and anchored into a publicly verifiable append-only structure. Built on open standards used across software-supply-chain transparency tooling; published under open licence; reproducible by any party. KSSL is the integrity floor for the Open Ledger (financial), the AI-Use Register, the Karnataka Open Data Portal, the Citizen Data Trust, the Karnataka Digital Twin raw store, and every sector operational system.

Second pass: KSSL additionally provides citizen transaction receipts (inclusion proofs against published anchors), independent witness co-signing of anchors with Karnataka Gazette publication, a published key-rotation and compromise-recovery protocol, and a degraded-mode rule — citizen services continue on locally signed queues when mediation is down, with every gap window logged and published.

Owning agency

Lead: Department of IT, BT & Science (DPI wing)

Backup: Karnataka Cyber Security Operations Centre (sheet H.231) for security; Independent Audit Board (Vol I Ch 6) for civil-society oversight

Statutory backing: Karnataka State Digital Infrastructure Act (App I)

Funding model

Annual cost band: ₹600-900 cr / year (capex front-loaded, opex sustaining)

Source: Cybersecurity + DPI line, App J (bumped from ~₹3.7k cr to ~₹9.5k cr over 5 years to accommodate KSSL build-out, HSM fleet with PQC-capable signing, threshold-cryptography signing, and the cryptography-engineering capacity that keeps every new system quantum-safe from inception — PQC algorithms themselves are open-source and free, so this line funds the HSM and engineering capacity, not a separate PQC migration project)

Payment trigger: Per-anchor publication cycle + per-incident verification

KPIs

Standard risk controls

Dependencies

Sheet H.231 — Karnataka Cyber Security Operations Centre (CSOC, statutory): the operating authority

Problem

The existing State SOC (sheet H.145) is an administrative body that depends on departmental cooperation to investigate, patch, or isolate non-compliant systems. When a department resists, the SOC has no compel-power. Incident timelines stretch; vendor problems persist; security floor erodes.

Program design

CSOC is established as a statutory body (App I — Karnataka Cyber Security and Citizen Consent Act). It has audit access to every state digital system, authority to compel patching, authority to mandate a vendor change, and authority to isolate a non-compliant system pending remediation. CSOC reports to the Civil-society Independent Audit Board (Vol I Ch 6), not to the department it is auditing. Funding is ring-fenced from departmental control. CSOC runs a continuous bug-bounty programme open to all citizens, a separate continuous red-team programme against state systems on a rolling basis, threat-intelligence ingestion + dissemination, and statutory incident-disclosure to the Audit Board, the Lokayukta, and the public.

Owning agency

Lead: Statutory body — Karnataka Cyber Security Operations Centre, reporting to the Civil-society Independent Audit Board

Backup: CERT-In national liaison; sector regulators on cross-cutting events

Statutory backing: Karnataka Cyber Security and Citizen Consent Act (App I)

Funding model

Annual cost band: ₹400-700 cr / year (core team + bug-bounty pool + red-team contracts + threat-intel)

Source: Cybersecurity + DPI line, App J — ring-fenced from departmental control

Payment trigger: Per-audit-cycle completion + per-incident response + per-disclosure milestone

KPIs

Standard risk controls

Dependencies

Sheet H.232 — Citizen Consent Ledger: citizen-controlled consent for every state data flow

Problem

Today, citizen data flows across state systems by implication — once a citizen interacts with one department, that interaction’s data can be queried by others without granular consent. The citizen has no way to see who accessed their data, why, or to revoke that access. The Citizen Data Trust (Vol I Ch 6) provides the storage and rights frame; the Consent Ledger is the operating instrument for granting and revoking permissions in real time.

Program design

The Citizen Consent Ledger is the citizen-controlled record of which data flow has been authorised for which purpose. Every state system that wants to read a resident’s personal data must hold a valid consent token from the Ledger — time-bound, purpose-bound, revocable. The Ledger is itself anchored on KSSL (sheet H.230): every grant, revocation, and access event generates an anchored log entry. Citizens query their own Ledger through JANATA; the four front doors (Vol I Ch 2) all integrate with it. Revocation propagates across systems within a defined window. Statutory revocation rights are guaranteed under the Karnataka Cyber Security and Citizen Consent Act (App I).

Second pass: every data class carries a published retention schedule; citizens hold a statutory deletion right, with deletion events verifiable through the Ledger; a Year-3 zero-knowledge eligibility pilot lets a citizen prove entitlement to one scheme without revealing the underlying records.

Owning agency

Lead: Citizen Data Trust (statutory body, Vol I Ch 6)

Backup: CSOC (sheet H.231) for security audit

Statutory backing: Karnataka Cyber Security and Citizen Consent Act (App I)

Funding model

Annual cost band: ₹150-250 cr / year (gateway infrastructure + citizen-support cells + dispute resolution)

Source: Cybersecurity + DPI line, App J

Payment trigger: Per-million-tokens-issued + dispute-resolution-cycle + JANATA-integration milestones

KPIs

Standard risk controls

Dependencies

Sheet H.233 — Karnataka Open Data Portal: time-series and dataset publishing surface

Problem

Vol I Ch 2’s six-publishing-surfaces frame separates financial flows (Open Ledger) from time-series and dataset content (this Portal). Earlier the Open Ledger was conflated with all open publication, which made the financial-spine harder to audit and the dataset surface less discoverable. The Portal is the standalone surface for sector dashboards, time-series outcome data, statistical content, and machine-readable datasets.

Program design

The Karnataka Open Data Portal publishes time-series and dataset content from every sector — Education (Learning State outcomes), Health (UMRS + KPHDA outcome data), Cities (digital-twin layers), Agriculture (KAIA price/yield/booking series), Justice, Environment, all of Vol II’s sectors. Every publication is anchored on KSSL (sheet H.230). Datasets are published under open licence (CC-BY by default), with machine-readable API access, defined update cadence, and the Civil Society Interface (one of the four front doors, Vol I Ch 2) provides queryable access for journalists, researchers, and audit bodies. The Portal does not carry personal data — that lives in the Citizen Data Trust under the Consent Ledger.

Second pass: every aggregate published from citizen-level data passes the published statistical-disclosure standard (minimum cell sizes + formal noise addition) before it appears on the Portal.

Owning agency

Lead: Department of IT, BT & Science + Karnataka State Statistics Department

Backup: Civil-society Independent Audit Board (Vol I Ch 6) for civil-society oversight

Statutory backing: Karnataka State Digital Infrastructure Act (App I)

Funding model

Annual cost band: ₹80-140 cr / year (Portal infrastructure + dataset curation + API capacity)

Source: Cybersecurity + DPI line, App J + sector-data convergence

Payment trigger: Per-dataset publication + per-API-availability cycle + per-developer-engagement milestone

KPIs

Standard risk controls

Dependencies

Architecture sheet-set summary

Sheets H.230–H.233 together implement the operating architecture at App H level. KSSL (H.230) is the cryptographic floor under everything; CSOC (H.231) is the operating authority with statutory teeth; the Citizen Consent Ledger (H.232) is the citizen-controlled consent instrument; the Karnataka Open Data Portal (H.233) is the time-series and dataset publishing surface separated cleanly from the financial-spine Open Ledger. Cross-references to Vol I Ch 2 (architecture frame), Vol I Ch 6 (statutory institutions), Vol II Ch 15 (Cybersecurity & DPI), App I (statutory backing), and App J (finance line) are wired through.

Existing sheets H.145 (State SOC), H.147 (Consent Vault), H.154 (Account Aggregator rails), H.130 (early Open Data) describe earlier-architecture forms of these systems. They remain in the Atlas as the operational legacy that the current architecture extends and consolidates. Where there is conflict, sheets H.230–H.233 are the canonical form.

H.145 — CYBER — State Security Operations Centre (SOC) 24/7

H.146 — CYBER — Secure-by-Design Standards & Vendor Rules

H.147 — CYBER — Consent Vault (Operating)

H.148 — CYBER — Public Bug Bounty Programme

H.149 — CYBER — Incident Transparency Reporting

H.150 — CYBER — Cybercrime Investigation Capacity

H.151 — CYBER — Citizen Digital Literacy Programme

H.152 — CYBER — Identity Layer Integration Library

H.153 — CYBER — Document Vault for Residents

H.154 — CYBER — Payment Rails Integration (UPI/Account Aggregator)

H.155 — CYBER — Public-Sector Cyber Workforce

H.156 — CYBER — Threat-intelligence Sharing Network

H.157 — CYBER — Critical-Infrastructure Cyber Resilience

H.158 — CYBER — Secure Default Cloud & On-prem Patterns

H.159 — CYBER — Privacy-enhancing Computation Pilots

H.160 — CYBER — Open APIs Programme (Citizen Tech)

H.161 — CYBER — Assisted Access Resilience

H.162 — CYBER — Children & Youth Online Safety


← Appendix H — Program Atlas · Appendix H — Program Atlas →

This is a chapter of The People's Model manifesto for Karnataka — published in full for public review. Every claim may be challenged: write to [email protected].