Appendix H — Program Atlas
Each sheet to the 8-section template + 4-point QA bar (defined inline in Vol III App H Education, the format-reference sector).
Read this chapter in the interactive reader, or download the full 601-page manifesto (PDF).
The People’s Model
Manifesto v2026
Volume III — Implementation Handbook
Appendix H — Program Atlas
Cybersecurity & DPI sector — sheets H.145–H.162 + H.230–H.233 (v1.0)
Each sheet to the 8-section template + 4-point QA bar (defined inline in Vol III App H Education, the format-reference sector).
Problem
Karnataka’s spine + departmental systems lack a centralised, 24/7 SOC. Incidents are detected late and responded to slowly.
Program design
- State SOC at the Chief Secretary’s office (logical extension of Mission Control).
- 24/7 monitoring; MTTD / MTTC published.
- Tier-3 escalation to CERT-In + state forensics.
- Tabletop exercises monthly; annual cross-dept exercise.
Owning agency
Lead: Department of IT, BT & Science (Cyber wing) + Karnataka State Wide Area Network team
Backup: CERT-In partnership
Funding model
Annual cost band: ₹80-150 cr / year
Source: State Budget; central cybersecurity-modernisation share.
Payment trigger: Per-incident detection / containment evidence.
KPIs
- • MTTD on the spine — baseline: (new); F: ≤24h; B: ≤4h; C: ≤1h.
- • MTTC on the spine — baseline: (new); F: ≤72h; B: ≤24h; C: ≤8h.
- • Tabletop / exercise cadence — baseline: (new); F: Monthly tabletop + annual full-scale; B: Cross-state participation; C: Sustained capability.
Standard risk controls
- • Risk: Vendor lock-in on SOC tooling. Safeguard: Open standards; multi-vendor stack; tech-portability clause.
- • Risk: SOC capture / staffing gap. Safeguard: Cadre framework (sheet H.155); rotation; competitive compensation.
- • Risk: Incident-data leak. Safeguard: Strict access controls; criminal liability; Citizen Data Trust review.
Dependencies
- • Vol II Ch 15; App H sheets H.148, H.149, H.155, H.156, H.157.
Problem
Karnataka government IT procurements often lack consistent security standards. Vendor-side breaches become state breaches.
Program design
- Published secure-coding + procurement-time security standards.
- Mandatory pre-procurement security audit.
- Vendor breach-disclosure obligations + liability.
- Periodic re-audit.
Owning agency
Lead: Department of IT, BT & Science
Backup: Karnataka State SOC
Funding model
Annual cost band: ₹50-90 cr / year (standards + audit capacity)
Source: State Budget; convergence with KPPP procurement reforms.
Payment trigger: Per-procurement audit + post-deployment compliance evidence.
KPIs
- • New procurements with pre-audit completion — baseline: (new); F: ≥80%; B: 100%; C: 100% with continuous audit.
- • Vendor compliance rate (post-deployment) — baseline: (new); F: Baselined; B: ≥90%; C: ≥98%.
- • Vendor breach-disclosure within 72h — baseline: (new); F: Baselined; B: 100%; C: 100% with audit.
Standard risk controls
- • Risk: Vendor lobbying for relaxed standards. Safeguard: Statutory standards; transparent revision process; independent peer review.
- • Risk: Audit capacity bottleneck. Safeguard: Empanelled audit panels; rotation; published audit-completion data.
- • Risk: Vendor breach concealment. Safeguard: Contractual liability; vendor blacklist; whistleblower protection.
Dependencies
- • Vol II Ch 15; App H sheets H.145, H.149.
Problem
Karnataka residents have no continuous visibility / control over what data the state holds and shares about them. The Consent Vault is the operating expression of Vol I Ch 6 governance.
Program design
- Resident-visible consent vault (granular per-purpose consent).
- Revocation propagates to downstream systems.
- Audit log accessible to the resident.
- Citizen Data Trust certification.
Owning agency
Lead: Department of IT, BT & Science + Citizen Data Trust
Backup: ABDM / ABHA integration (where applicable)
Funding model
Annual cost band: ₹60-100 cr / year
Source: State Budget; convergence with Account Aggregator framework.
Payment trigger: Per-consent grant / revoke event + audit-trail evidence.
KPIs
- • Residents with active consent record — baseline: (new); F: Baselined; B: ≥70%; C: ≥95%.
- • Revocation-propagation time (median) — baseline: (new); F: ≤24h; B: ≤1h; C: Real-time.
- • Audit-trail-access (residents per month) — baseline: (new); F: Baselined; B: Material engagement; C: Routine reference.
Standard risk controls
- • Risk: Consent-fatigue → blanket consents. Safeguard: Per-purpose granular UI; Trust review of UX; sample audits.
- • Risk: Downstream system non-honour of revocation. Safeguard: Statutory propagation requirement; penalty for non-compliance; sample audit.
- • Risk: Vault itself becomes attack surface. Safeguard: SOC monitoring; strict access controls; independent annual audit.
Dependencies
- • Vol I Ch 6; App H sheets H.035 (DHR), H.151, H.158.
Problem
Karnataka spine + departmental systems have unknown vulnerabilities. External researcher engagement is informal and sometimes adversarial.
Program design
- Coordinated vulnerability disclosure programme.
- Bounty-paid pathway for the spine + flagship systems.
- Triage + patch + verification cycle on a published SLA.
- Public summary of vulnerabilities found and closed.
Owning agency
Lead: Karnataka State SOC
Backup: Department of IT, BT & Science
Funding model
Annual cost band: ₹30-60 cr / year (bounties + admin)
Source: State Budget; CERT-In convergence.
Payment trigger: Per-disclosure triage + patch evidence.
KPIs
- • Vulnerabilities responsibly disclosed per year — baseline: (new); F: Baselined; B: Material volume; C: Mature researcher community.
- • Median time-to-patch (high severity) — baseline: (new); F: ≤14 days; B: ≤7 days; C: ≤72h.
- • Public summary publication rate — baseline: (new); F: 100% closed cases; B: 100% within window; C: Continuous.
Standard risk controls
- • Risk: Researcher prosecution under cyber-laws. Safeguard: Statutory safe-harbour for participants; criminal-immunity for good-faith disclosure.
- • Risk: Bounty fraud. Safeguard: Triage verification; reputation scoring; vendor blacklist.
- • Risk: Patch delays compounding. Safeguard: SLA enforcement; dashboard publication; escalation pathway.
Dependencies
- • App H sheets H.145, H.146, H.149.
Problem
Karnataka government cybersecurity incidents are inconsistently disclosed. Trust is eroded by opacity more than by incidents themselves.
Program design
- Quarterly incident transparency report (state-level aggregate).
- Major-incident disclosure within 72h of containment.
- Post-incident report within 30 days.
- Independent verification of reported data.
Owning agency
Lead: Karnataka State SOC + Citizen Data Trust
Backup: KIC (transparency oversight)
Funding model
Annual cost band: ₹20-40 cr / year
Source: State Budget; convergence with Public Information Charter.
Payment trigger: Per-incident disclosure + post-incident publication.
KPIs
- • Major-incident disclosure within 72h — baseline: (new); F: 100%; B: 100% with audit; C: Continuous.
- • Post-incident reports published within 30d — baseline: (new); F: 100%; B: 100% with quality; C: Continuous.
- • Independent-verification pass rate — baseline: (new); F: Baselined; B: ≥90%; C: ≥98%.
Standard risk controls
- • Risk: Pressure to delay / dilute disclosure. Safeguard: Statutory requirement; Citizen Data Trust independence; whistleblower protection.
- • Risk: Disclosure causing secondary attacks. Safeguard: Sensitive-detail redaction protocol; phased technical-detail release post-patch.
- • Risk: Verification gaming. Safeguard: Independent verifier rotation; published methodology.
Dependencies
- • App H sheets H.145, H.181.
Problem
Karnataka cybercrime volume grows faster than investigation capability. Citizen victims of fraud, harassment, identity theft wait long for action.
Program design
- Cybercrime cells expansion at district + state level.
- Trained cyber-investigator cadre.
- Live platform-cooperation channels.
- Victim-support pathway.
Owning agency
Lead: Karnataka State Police (Cyber Crime wing)
Backup: Centre for Cyber-Forensic Sciences
Funding model
Annual cost band: ₹120-180 cr / year
Source: State Budget; Centre share.
Payment trigger: Per-case enrolment + investigation stage evidence.
KPIs
- • District units operational — baseline: Partial; F: All 31; B: All 31 + capacity scaled; C: Continuous refresh.
- • Median investigation completion time — baseline: Long; F: Baselined; B: Material reduction; C: At/below national benchmark.
- • Victim-grievance resolution within SLA — baseline: Variable; F: ≥70%; B: ≥90%; C: ≥95% with appeal.
Standard risk controls
- • Risk: Cadre churn to private sector. Safeguard: Competitive pay; career-path; sheet H.155 cadre framework.
- • Risk: Platform non-cooperation. Safeguard: Statutory framework; published cooperation data; escalation.
- • Risk: Misuse against legitimate dissent. Safeguard: Independent review of high-profile cases; Trust oversight.
Dependencies
- • Vol II Ch 15; App H sheets H.092, H.101.
Problem
Karnataka residents face rising digital-fraud exposure (UPI fraud, phishing, deepfake, account-takeover). Literacy is uneven.
Program design
- Statewide adult digital-literacy modules at PSC / library.
- School curriculum integration (convergence with sheet H.187).
- Targeted outreach to vulnerable cohorts (seniors, new internet users).
- Reporting + recovery pathway for victims.
Owning agency
Lead: Department of IT, BT & Science + Department of School Education
Backup: Karnataka State Civic Network (sheet H.142)
Funding model
Annual cost band: ₹100-160 cr / year
Source: State Budget; CERT-In + RBI awareness convergence.
Payment trigger: Per-module participation + reported-fraud trend.
KPIs
- • Adults trained per year — baseline: (new); F: Baselined; B: Material reach; C: Sustained universal coverage.
- • Reported digital-fraud incident response time — baseline: Slow; F: ≤72h acknowledgement; B: ≤24h; C: ≤8h.
- • Victim-recovery rate (where applicable) — baseline: (new); F: Baselined; B: Material recovery; C: Sustained capability.
Standard risk controls
- • Risk: Generic content with low impact. Safeguard: Local-context modules; voice + visual; periodic refresh.
- • Risk: Misuse for surveillance (training-data harvesting). Safeguard: Minimum-data principle; Trust review.
- • Risk: Exclusion of low-literacy. Safeguard: Voice + visual; trusted-intermediary delivery.
Dependencies
- • App H sheets H.109, H.142, H.187.
Problem
Karnataka departments integrate identity (Aadhaar, DigiLocker, ABHA) ad-hoc. Inconsistent integration creates seams that residents and vendors exploit.
Program design
- State-maintained Identity Integration Library — open-source SDK + reference patterns.
- Mandatory use for new departmental systems.
- Audit of legacy integrations.
- Citizen Data Trust certification of the Library.
Owning agency
Lead: Department of IT, BT & Science
Backup: Citizen Data Trust
Funding model
Annual cost band: ₹30-60 cr / year
Source: State Budget; ABDM convergence.
Payment trigger: Per-integration audit + library-release evidence.
KPIs
- • New systems using the Library — baseline: (new); F: ≥80%; B: 100%; C: 100% with audit.
- • Library security audit completion — baseline: (new); F: Annual; B: Continuous; C: Continuous + community review.
- • Legacy-integration migration rate — baseline: (new); F: Baselined; B: Material migration; C: 100% migrated.
Standard risk controls
- • Risk: Library bug becoming statewide vulnerability. Safeguard: Continuous audit; bug bounty extension; rapid-patch process.
- • Risk: Departmental work-around (ignoring Library). Safeguard: Procurement-time mandate; compliance audit; sanctions for circumvention.
- • Risk: Library lock-in to single national identity provider. Safeguard: Provider-agnostic abstraction; fallback patterns.
Dependencies
- • Vol I Ch 2; App H sheets H.146, H.147, H.153.
Problem
Karnataka residents carry the burden of producing the same documents to multiple departments. DigiLocker exists nationally but state integration is uneven.
Program design
- Resident Document Vault on the spine, DigiLocker-integrated.
- Granular per-document sharing consent.
- Issuer-side integration (e.g., e-Aasthi, marks-card, caste certificate).
- Consent-based, audit-logged access by departments.
Owning agency
Lead: Department of IT, BT & Science
Backup: Citizen Data Trust
Funding model
Annual cost band: ₹50-90 cr / year
Source: State Budget; DigiLocker convergence.
Payment trigger: Per-document issuance + consent event.
KPIs
- • Residents with active Vault use — baseline: (new); F: Baselined; B: ≥70%; C: ≥95%.
- • State-issued documents available digitally — baseline: Partial; F: ≥60% types; B: ≥95%; C: 100% with audit.
- • Document-sharing consent events per month — baseline: (new); F: Baselined; B: Material adoption; C: Routine resident-led use.
Standard risk controls
- • Risk: Issuer-side document forgery / duplication. Safeguard: Cryptographic signature; revocation registry; sample audit.
- • Risk: Privacy creep through consent fatigue. Safeguard: Granular consent; Trust review; sample audit on de-facto blanket consent patterns.
- • Risk: Vault availability gap. Safeguard: Failover + DR; published uptime; assisted-access via PSC.
Dependencies
- • App H sheets H.147, H.152, H.158.
Problem
Karnataka government payments (welfare, refund, subsidy) still bottleneck on legacy rails. UPI / Account Aggregator integration is uneven.
Program design
- Universal UPI receipt + disbursement for state transactions.
- Account Aggregator-based eligibility checks (consent-protected).
- Real-time disbursement to spine-linked beneficiary accounts.
- Audit-trail on Open Ledger.
Owning agency
Lead: Department of Finance + Department of IT
Backup: RBI / NPCI partnership
Funding model
Annual cost band: ₹60-100 cr / year
Source: State Budget; convergence with PFMS + DBT.
Payment trigger: Per-transaction event + audit-trail evidence.
KPIs
- • Welfare disbursement via UPI / direct rails — baseline: Partial; F: ≥70%; B: ≥95%; C: 100% with audit.
- • Median disbursement delay — baseline: Variable; F: ≤72h; B: ≤24h; C: Same-day where feasible.
- • Beneficiary account-anomaly detection rate — baseline: (new); F: Baselined; B: Material accuracy; C: Sustained capability.
Standard risk controls
- • Risk: Beneficiary-account fraud (account-change attack). Safeguard: Multi-factor + supervisor approval (Vol I Sec. 1.7); detection via App C RF-P-03.
- • Risk: AA-integration data overreach. Safeguard: Per-purpose consent; minimum-data principle; sample audit.
- • Risk: Bank-side payment failure. Safeguard: Retry + failover; transparent failure publication; alternate-route.
Dependencies
- • App H sheets H.147, H.022 (Cashless), H.005 (Scholarship).
Problem
Karnataka public-sector cybersecurity cadre is thin and uncompetitive against private sector. Cadre churn compounds vulnerability.
Program design
- Cyber-cadre framework with published career path.
- Competitive compensation + retention bonus structure.
- Continuous training + certification.
- Inter-state / Centre rotation pathways.
Owning agency
Lead: Department of IT, BT & Science (HR cell)
Backup: Karnataka State SOC
Funding model
Annual cost band: ₹80-130 cr / year
Source: State Budget; convergence with central cyber-skill schemes.
Payment trigger: Per-cadre member onboarding + retention data.
KPIs
- • Active cyber-cadre size — baseline: (new); F: Baselined; B: Material growth; C: Sustained capacity.
- • Vacancy rate — baseline: (new); F: Baselined; B: ≤15%; C: ≤5%.
- • Annual retention rate — baseline: (new); F: Baselined; B: ≥75%; C: ≥85%.
Standard risk controls
- • Risk: Compensation-gap pressure. Safeguard: Competitive pay tied to market benchmark; retention bonus; non-monetary benefits.
- • Risk: Skill-obsolescence. Safeguard: Continuous training; certification refresh cycle.
- • Risk: Cadre capture by single vendor. Safeguard: Rotation; vendor-neutral training; conflict-of-interest register.
Dependencies
- • Vol I Ch 5 (Cadre pattern); App H sheets H.145, H.148.
Problem
Karnataka departments + private sector face overlapping threats but share intelligence informally. Pattern-detection is delayed.
Program design
- State-anchored threat-intel sharing platform.
- Department + critical-private-sector participation.
- Anonymised indicator-of-compromise sharing.
- CERT-In + national-level upward link.
Owning agency
Lead: Karnataka State SOC
Backup: Department of IT, BT & Science
Funding model
Annual cost band: ₹30-60 cr / year
Source: State Budget; CERT-In convergence.
Payment trigger: Per-IoC publication + downstream-action evidence.
KPIs
- • Participating departments / orgs — baseline: (new); F: All major; B: + critical private sector; C: Continuous expansion.
- • IoCs shared per month — baseline: (new); F: Baselined; B: Material volume; C: Mature ecosystem.
- • Downstream detection rate — baseline: (new); F: Baselined; B: Material rise; C: Sustained collective defence.
Standard risk controls
- • Risk: Privacy leakage through IoC sharing. Safeguard: Anonymisation protocol; Trust review; sample audit.
- • Risk: Free-rider problem (consume but don’t contribute). Safeguard: Membership compact; usage-vs-contribution data.
- • Risk: Critical-infra exposure via intel-sharing. Safeguard: Tiered access; need-to-know enforcement.
Dependencies
- • App H sheets H.145, H.148, H.157.
Problem
Karnataka’s critical infrastructure (power, water, transport, health) faces sophisticated cyber threats. Resilience standards are uneven.
Program design
- Critical Infrastructure Protection Framework (CII designation).
- Mandatory audit + exercise cycle per CII operator.
- Sector-specific incident-response protocols.
- Cooperation with NCIIPC.
Owning agency
Lead: Karnataka State SOC + NCIIPC liaison
Backup: Sector regulators (ESCOMs, BWSSB, etc.)
Funding model
Annual cost band: ₹100-160 cr / year
Source: State Budget; sector regulator capex.
Payment trigger: Per-CII audit + exercise completion.
KPIs
- • Designated CIIs audited annually — baseline: (new); F: ≥80%; B: 100%; C: Continuous + audit.
- • Sector exercises conducted per year — baseline: (new); F: ≥4; B: ≥8 sector + 1 statewide; C: Sustained capability.
- • CII incident response time (median) — baseline: (new); F: Baselined; B: Material reduction; C: At/below benchmark.
Standard risk controls
- • Risk: Operator non-cooperation. Safeguard: Statutory framework; published compliance; penalty for non-compliance.
- • Risk: Audit cherry-picking. Safeguard: Independent auditor rotation; published findings (subject to security redaction).
- • Risk: Exercise-fatigue. Safeguard: Varied scenarios; cross-sector participation; lessons-learned publication.
Dependencies
- • App H sheets H.145, H.146, H.156.
Problem
Karnataka department IT deployments use varied cloud / on-prem patterns. Security defaults are uneven; configuration drift is common.
Program design
- State-curated secure-default architectures (Cloud / On-prem / Hybrid).
- Reference implementations on open-source stacks where feasible.
- Mandatory adoption for new deployments.
- Audit of legacy deployments.
Owning agency
Lead: Department of IT, BT & Science
Backup: Karnataka State SOC
Funding model
Annual cost band: ₹40-80 cr / year
Source: State Budget; convergence with MeghRaj.
Payment trigger: Per-deployment pattern adoption + audit evidence.
KPIs
- • New deployments using secure-default — baseline: (new); F: ≥80%; B: 100%; C: 100% with audit.
- • Configuration-drift incident rate — baseline: (new); F: Baselined; B: Material decline; C: Sustained low.
- • Legacy-deployment migration rate — baseline: (new); F: Baselined; B: Material migration; C: 100% migrated.
Standard risk controls
- • Risk: Vendor lock-in via reference architectures. Safeguard: Open-source preference; tech-portability clause; multi-vendor patterns.
- • Risk: Pattern obsolescence. Safeguard: Annual refresh cycle; community review.
- • Risk: Departmental deviation. Safeguard: Procurement-time mandate; sanctions for circumvention.
Dependencies
- • App H sheets H.146, H.152, H.155.
Problem
Karnataka faces growing demand for cross-dataset analysis (health × education × welfare) but privacy risks rise with each join. Privacy-enhancing computation (PEC) — differential privacy, secure enclaves, federated learning — is under-piloted.
Program design
- State pilots in PEC for high-value cross-dataset use-cases.
- Citizen Data Trust governance per pilot.
- Published methodology + outcomes.
- Open-source where feasible.
Owning agency
Lead: Department of IT, BT & Science + Citizen Data Trust
Backup: Karnataka State Statistics Department
Funding model
Annual cost band: ₹30-60 cr / year
Source: State Budget; partnership funding.
Payment trigger: Per-pilot enrolment + outcome publication.
KPIs
- • PEC pilots in production — baseline: (new); F: ≥3; B: ≥10; C: Routine application.
- • Cross-dataset analyses using PEC vs raw-join — baseline: (new); F: Baselined; B: Material shift; C: PEC as default.
- • Independent privacy-audit pass rate — baseline: (new); F: ≥80%; B: ≥95%; C: ≥98%.
Standard risk controls
- • Risk: Method opacity reducing trust. Safeguard: Open methodology; community review; sample audits.
- • Risk: Vendor lock-in on PEC tooling. Safeguard: Open-source preference; tech-portability.
- • Risk: False sense of privacy. Safeguard: Trust certification; periodic privacy-loss analysis.
Dependencies
- • Vol I Ch 6; App H sheets H.147, H.130.
Problem
Karnataka government services have uneven API surfaces for citizen-tech developers to build on. Civic-tech ecosystem is constrained.
Program design
- Documented, versioned APIs for key citizen services.
- Developer portal with sandbox + key issuance.
- Rate-limiting + usage tracking.
- Citizen Data Trust review of high-risk APIs.
Owning agency
Lead: Department of IT, BT & Science
Backup: Karnataka Innovation Authority
Funding model
Annual cost band: ₹60-100 cr / year
Source: State Budget; convergence with sheet H.130 Open Data.
Payment trigger: Per-API publication + developer-engagement data.
KPIs
- • Documented production APIs — baseline: (new); F: Baselined; B: Material breadth; C: Sustained coverage.
- • Active developers per month — baseline: (new); F: Baselined; B: Material community; C: Sustained ecosystem.
- • Citizen-tech apps in routine public use — baseline: (new); F: Baselined; B: ≥10 with material user base; C: Sustained pipeline.
Standard risk controls
- • Risk: API abuse for harvesting / surveillance. Safeguard: Rate-limiting; usage transparency; Trust review of high-risk APIs.
- • Risk: Developer-side data resale. Safeguard: Terms of use; vendor blacklist for breach; usage audit.
- • Risk: Single-developer concentration. Safeguard: Open onboarding; rotation; representation in developer programmes.
Dependencies
- • App H sheets H.130, H.147, H.158.
Problem
Karnataka digital service assisted-access (PSC, kiosk, operator) is a critical reliability layer. When it fails, the resident has nowhere to go.
Program design
- SLA-bound uptime for assisted-access channels.
- Failover when self-service App fails.
- Operator-cadre training + audit.
- Convergence with PSC (sheet H.109) and ward kiosks (sheet H.169).
Owning agency
Lead: Department of IT, BT & Science + Department of Rural Development
Backup: Department of Urban Development (ward kiosks)
Funding model
Annual cost band: ₹80-130 cr / year
Source: State Budget; convergence with PSC funding.
Payment trigger: Per-channel uptime + per-transaction success-rate.
KPIs
- • Assisted-access channel uptime — baseline: (new); F: ≥95%; B: ≥99%; C: ≥99.5%.
- • Median transaction-completion time — baseline: (new); F: Parity SLA App+15%; B: Parity SLA App+5%; C: Sustained parity.
- • Operator-action audit pass rate — baseline: (new); F: ≥90%; B: ≥97%; C: ≥99%.
Standard risk controls
- • Risk: Operator-side rent-seeking. Safeguard: Operator log; cross-verification; complaint pathway.
- • Risk: Hardware failure leaving rural blocks dark. Safeguard: Maintenance SLA; redundant hardware; backup-paper pathway.
- • Risk: Operator capacity gap. Safeguard: Cadre framework; rotation; training audit.
Dependencies
- • App H sheets H.109, H.169.
Problem
Karnataka children and youth face online harms (CSAM, cyberbullying, grooming, dark-pattern manipulation). Response capacity is thin.
Program design
- Online-safety curriculum integration (sheet H.187).
- Reporting + response pathway with priority handling.
- Platform-cooperation protocols.
- Parent / educator support resources.
Owning agency
Lead: Karnataka State Commission for Protection of Child Rights + KSP Cybercrime
Backup: Department of School Education & Literacy
Funding model
Annual cost band: ₹60-100 cr / year
Source: State Budget; Centre child-protection convergence.
Payment trigger: Per-report response + curriculum-delivery data.
KPIs
- • Schools covering online-safety curriculum — baseline: (new); F: ≥70%; B: ≥95%; C: 100%.
- • Reported online-harm response time — baseline: (new); F: ≤72h; B: ≤24h; C: ≤8h.
- • Platform-cooperation cases handled — baseline: (new); F: Pilot scale; B: Routine cooperation; C: Sustained capability.
Standard risk controls
- • Risk: Surveillance creep under safety framing. Safeguard: Citizen Data Trust review; minimum-data principle; sunset clauses on monitoring.
- • Risk: Platform non-cooperation. Safeguard: Statutory framework; published cooperation data; escalation.
- • Risk: Over-policing reducing youth digital autonomy. Safeguard: Age-appropriate framework; appeal pathway; youth-voice consultation.
Dependencies
- • App H sheets H.101, H.150, H.103, H.144.
Sheet H.230 — Karnataka State Service Log (KSSL): cryptographic anchoring layer
Problem
Karnataka’s digital state generates millions of records every day across hundreds of systems — service requests, payment instructions, AI decisions, log entries. Without a single anchoring layer, integrity of these records depends on trust in each operating department. Tampering is hard to detect; cross-system reconciliation is manual; civil-society audit is bounded by what each department chooses to expose.
Program design
KSSL is the state’s single mediation and logging layer. Every inter-system call across state digital services routes through KSSL, generating a log entry: actor, time, action, data fields accessed, reason. Entries are hashed, batched at defined cadence, and anchored into a publicly verifiable append-only structure. Built on open standards used across software-supply-chain transparency tooling; published under open licence; reproducible by any party. KSSL is the integrity floor for the Open Ledger (financial), the AI-Use Register, the Karnataka Open Data Portal, the Citizen Data Trust, the Karnataka Digital Twin raw store, and every sector operational system.
Second pass: KSSL additionally provides citizen transaction receipts (inclusion proofs against published anchors), independent witness co-signing of anchors with Karnataka Gazette publication, a published key-rotation and compromise-recovery protocol, and a degraded-mode rule — citizen services continue on locally signed queues when mediation is down, with every gap window logged and published.
Owning agency
Lead: Department of IT, BT & Science (DPI wing)
Backup: Karnataka Cyber Security Operations Centre (sheet H.231) for security; Independent Audit Board (Vol I Ch 6) for civil-society oversight
Statutory backing: Karnataka State Digital Infrastructure Act (App I)
Funding model
Annual cost band: ₹600-900 cr / year (capex front-loaded, opex sustaining)
Source: Cybersecurity + DPI line, App J (bumped from ~₹3.7k cr to ~₹9.5k cr over 5 years to accommodate KSSL build-out, HSM fleet with PQC-capable signing, threshold-cryptography signing, and the cryptography-engineering capacity that keeps every new system quantum-safe from inception — PQC algorithms themselves are open-source and free, so this line funds the HSM and engineering capacity, not a separate PQC migration project)
Payment trigger: Per-anchor publication cycle + per-incident verification
KPIs
- • Anchor publication cadence — baseline: (new); F: Daily anchors; B: Hourly anchors; C: Streaming anchors with defined publication window.
- • Anchor verification success rate — baseline: (new); F: ≥99%; B: ≥99.9%; C: ≥99.99%.
- • Inter-system call coverage through KSSL — baseline: 0% (new); F: ≥50% of state systems; B: ≥85%; C: ≥99%.
- • Civil-society independent verification rate — baseline: (new); F: ≥1 independent verifier per quarter; B: ≥5 per quarter; C: ≥20 per quarter with weekly reports.
- • Post-quantum adoption — baseline: (new); F: 100% of new/procured systems quantum-safe (hybrid) from inception; B: + all long-secret-data systems hybrid by Year 4; C: + last legacy cryptography retired within the fifteen-year outer bound.
Standard risk controls
- • Risk: Single-point-of-failure on anchoring infrastructure. Safeguard: Geographic redundancy across at least two independent state data centres; active-active deployment; defined failover RTO.
- • Risk: Vendor lock-in on HSM fleet. Safeguard: Vendor diversity mandate (App I — Karnataka State Digital Infrastructure Act); multi-vendor procurement; portability tests quarterly.
- • Risk: Administrative-key compromise. Safeguard: Threshold cryptography for any operation touching ≥1 lakh records or any signing of a state-anchored batch; HSM-resident key material; quorum holders public.
- • Risk: Cryptographic-floor obsolescence. Safeguard: quantum-safe (hybrid) by default from Day 1 for all new and procured systems; long-secret data hybrid first (Year 4); legacy retires within a fifteen-year outer bound, progress published annually on the Karnataka Open Data Portal.
Dependencies
- • Vol I Ch 2 Sec 2.2 (architecture frame); Vol I Ch 3 Sec 3.2 (Mission Control reads from KSSL); Vol I Ch 4 (Open Ledger anchored through KSSL); Vol II Ch 15 (Cybersecurity & DPI); App I (statutory backing); App J (finance line); App H sheets H.231 (CSOC), H.232 (Consent Ledger), H.233 (Open Data Portal).
Sheet H.231 — Karnataka Cyber Security Operations Centre (CSOC, statutory): the operating authority
Problem
The existing State SOC (sheet H.145) is an administrative body that depends on departmental cooperation to investigate, patch, or isolate non-compliant systems. When a department resists, the SOC has no compel-power. Incident timelines stretch; vendor problems persist; security floor erodes.
Program design
CSOC is established as a statutory body (App I — Karnataka Cyber Security and Citizen Consent Act). It has audit access to every state digital system, authority to compel patching, authority to mandate a vendor change, and authority to isolate a non-compliant system pending remediation. CSOC reports to the Civil-society Independent Audit Board (Vol I Ch 6), not to the department it is auditing. Funding is ring-fenced from departmental control. CSOC runs a continuous bug-bounty programme open to all citizens, a separate continuous red-team programme against state systems on a rolling basis, threat-intelligence ingestion + dissemination, and statutory incident-disclosure to the Audit Board, the Lokayukta, and the public.
Owning agency
Lead: Statutory body — Karnataka Cyber Security Operations Centre, reporting to the Civil-society Independent Audit Board
Backup: CERT-In national liaison; sector regulators on cross-cutting events
Statutory backing: Karnataka Cyber Security and Citizen Consent Act (App I)
Funding model
Annual cost band: ₹400-700 cr / year (core team + bug-bounty pool + red-team contracts + threat-intel)
Source: Cybersecurity + DPI line, App J — ring-fenced from departmental control
Payment trigger: Per-audit-cycle completion + per-incident response + per-disclosure milestone
KPIs
- • Audit-cycle completion across state systems — baseline: (new); F: Annual audit of every system; B: Continuous audit on critical systems + annual on others; C: Continuous across all + statutory recurring.
- • Mean Time to Patch on compelled-patching orders — baseline: (new); F: ≤30 days; B: ≤7 days; C: ≤72 hours.
- • Bug-bounty disclosure response time — baseline: (new); F: ≤7 days triage; B: ≤72 hours triage; C: ≤24 hours triage.
- • Incident-disclosure timeliness (statutory) — baseline: (new); F: ≥90% within statutory window; B: ≥99%; C: 100%.
- • Red-team finding closure rate — baseline: (new); F: ≥80% of critical findings closed within 30 days; B: ≥95%; C: 100% within defined SLO by severity.
Standard risk controls
- • Risk: Executive capture of CSOC. Safeguard: Statutory reporting line to Independent Audit Board (not Chief Secretary); funding ring-fenced; appointment and removal of CSOC head requires Audit Board concurrence.
- • Risk: Bug-bounty researcher liability. Safeguard: Statutory safe-harbour provisions (App I); defined disclosure terms; defined reward structure.
- • Risk: Department resistance to compel-patching. Safeguard: Statutory authority to isolate non-compliant systems; financial penalty path for repeated non-compliance; public disclosure of resistance events.
- • Risk: CSOC staff insider threat. Safeguard: Threshold-cryptography quorum (sheet H.230) for any high-impact action; rotation of duties; continuous monitoring by Audit Board.
Dependencies
- • Vol I Ch 6 (statutory institutions); Vol II Ch 15 Sec on CSOC + bug-bounty + red-team; App I (Karnataka Cyber Security and Citizen Consent Act); App J (Cybersecurity + DPI line, ring-fenced share); sheet H.230 (KSSL audit access); sheet H.232 (Consent Ledger oversight).
Sheet H.232 — Citizen Consent Ledger: citizen-controlled consent for every state data flow
Problem
Today, citizen data flows across state systems by implication — once a citizen interacts with one department, that interaction’s data can be queried by others without granular consent. The citizen has no way to see who accessed their data, why, or to revoke that access. The Citizen Data Trust (Vol I Ch 6) provides the storage and rights frame; the Consent Ledger is the operating instrument for granting and revoking permissions in real time.
Program design
The Citizen Consent Ledger is the citizen-controlled record of which data flow has been authorised for which purpose. Every state system that wants to read a resident’s personal data must hold a valid consent token from the Ledger — time-bound, purpose-bound, revocable. The Ledger is itself anchored on KSSL (sheet H.230): every grant, revocation, and access event generates an anchored log entry. Citizens query their own Ledger through JANATA; the four front doors (Vol I Ch 2) all integrate with it. Revocation propagates across systems within a defined window. Statutory revocation rights are guaranteed under the Karnataka Cyber Security and Citizen Consent Act (App I).
Second pass: every data class carries a published retention schedule; citizens hold a statutory deletion right, with deletion events verifiable through the Ledger; a Year-3 zero-knowledge eligibility pilot lets a citizen prove entitlement to one scheme without revealing the underlying records.
Owning agency
Lead: Citizen Data Trust (statutory body, Vol I Ch 6)
Backup: CSOC (sheet H.231) for security audit
Statutory backing: Karnataka Cyber Security and Citizen Consent Act (App I)
Funding model
Annual cost band: ₹150-250 cr / year (gateway infrastructure + citizen-support cells + dispute resolution)
Source: Cybersecurity + DPI line, App J
Payment trigger: Per-million-tokens-issued + dispute-resolution-cycle + JANATA-integration milestones
KPIs
- • Citizen-consent coverage of state data flows — baseline: 0%; F: ≥50% of state-held personal-data flows have explicit consent tokens; B: ≥85%; C: ≥99%.
- • Revocation propagation time — baseline: (new); F: ≤72 hours; B: ≤24 hours; C: ≤1 hour.
- • Citizen-initiated consent-audit query response time — baseline: (new); F: ≤7 days; B: ≤24 hours; C: real-time via JANATA.
- • Statutory revocation compliance rate — baseline: (new); F: ≥95%; B: ≥99%; C: 100% with anchored audit trail.
- • Citizen Consent Ledger uptime — baseline: (new); F: ≥99%; B: ≥99.9%; C: ≥99.99% with active-active geographic redundancy.
Standard risk controls
- • Risk: Departmental override of revocation. Safeguard: Cryptographic anchoring of every access event on KSSL; revocation-blocking detected by CSOC; statutory penalty.
- • Risk: Coercive consent at point of service. Safeguard: Statutory framing of consent as voluntary; defined purposes-of-use; service-denial-on-non-consent ban for survival-essential services.
- • Risk: Consent UX overload — citizens click-through. Safeguard: Purpose-bundling with citizen-friendly explanations; defined limit on consent requests per session; civil-society review of consent UX.
- • Risk: Mass-consent revocation cascade. Safeguard: Defined operational protocols for mass-revocation events; graceful degradation in dependent systems; Audit Board oversight.
Dependencies
- • Vol I Ch 2 Sec 2.2 (six publishing surfaces); Vol I Ch 6 (Citizen Consent Ledger as statutory institution); Vol II Ch 15 (Consent Ledger integration with operational systems); App I (statutory backing); sheet H.230 (KSSL anchoring); sheet H.231 (CSOC security audit).
Sheet H.233 — Karnataka Open Data Portal: time-series and dataset publishing surface
Problem
Vol I Ch 2’s six-publishing-surfaces frame separates financial flows (Open Ledger) from time-series and dataset content (this Portal). Earlier the Open Ledger was conflated with all open publication, which made the financial-spine harder to audit and the dataset surface less discoverable. The Portal is the standalone surface for sector dashboards, time-series outcome data, statistical content, and machine-readable datasets.
Program design
The Karnataka Open Data Portal publishes time-series and dataset content from every sector — Education (Learning State outcomes), Health (UMRS + KPHDA outcome data), Cities (digital-twin layers), Agriculture (KAIA price/yield/booking series), Justice, Environment, all of Vol II’s sectors. Every publication is anchored on KSSL (sheet H.230). Datasets are published under open licence (CC-BY by default), with machine-readable API access, defined update cadence, and the Civil Society Interface (one of the four front doors, Vol I Ch 2) provides queryable access for journalists, researchers, and audit bodies. The Portal does not carry personal data — that lives in the Citizen Data Trust under the Consent Ledger.
Second pass: every aggregate published from citizen-level data passes the published statistical-disclosure standard (minimum cell sizes + formal noise addition) before it appears on the Portal.
Owning agency
Lead: Department of IT, BT & Science + Karnataka State Statistics Department
Backup: Civil-society Independent Audit Board (Vol I Ch 6) for civil-society oversight
Statutory backing: Karnataka State Digital Infrastructure Act (App I)
Funding model
Annual cost band: ₹80-140 cr / year (Portal infrastructure + dataset curation + API capacity)
Source: Cybersecurity + DPI line, App J + sector-data convergence
Payment trigger: Per-dataset publication + per-API-availability cycle + per-developer-engagement milestone
KPIs
- • Datasets published — baseline: (new); F: ≥500 datasets; B: ≥2,000; C: ≥10,000 with monthly refresh cycles.
- • Update cadence reliability — baseline: (new); F: ≥90% of datasets on schedule; B: ≥99%; C: ≥99.9% with public dashboard of refresh status.
- • Portal uptime — baseline: (new); F: ≥99%; B: ≥99.9%; C: ≥99.99%.
- • API call success rate — baseline: (new); F: ≥99%; B: ≥99.9%; C: ≥99.99% with defined rate-limit policy.
- • KSSL anchoring coverage of Portal publications — baseline: (new); F: 100% of publications anchored within publication window; B: anchored within 1 hour; C: real-time anchoring.
Standard risk controls
- • Risk: De-anonymisation through dataset cross-referencing. Safeguard: K-anonymity / differential-privacy mandates on every personal-data-adjacent dataset; pre-publication civil-society review for high-risk datasets.
- • Risk: Selective publication (departments publish only flattering data). Safeguard: Statutory publication cadence per Karnataka State Digital Infrastructure Act; civil-society standing to file non-publication complaints; Audit Board annual non-publication report.
- • Risk: Portal downtime erodes audit access. Safeguard: Geographic redundancy; defined SLA + financial penalty for breach; bulk-download paths so external archives stay current.
- • Risk: API abuse / DDOS. Safeguard: Defined rate-limit policy; CSOC monitoring; identified-developer tiers with elevated limits.
Dependencies
- • Vol I Ch 2 Sec 2.2 (six publishing surfaces); Vol I Ch 4 (separation of financial Open Ledger from time-series Open Data Portal); Vol II Ch 15 (Portal as architectural component); App I (statutory cadence backing); sheet H.230 (KSSL anchoring); sheet H.231 (CSOC monitoring).
Architecture sheet-set summary
Sheets H.230–H.233 together implement the operating architecture at App H level. KSSL (H.230) is the cryptographic floor under everything; CSOC (H.231) is the operating authority with statutory teeth; the Citizen Consent Ledger (H.232) is the citizen-controlled consent instrument; the Karnataka Open Data Portal (H.233) is the time-series and dataset publishing surface separated cleanly from the financial-spine Open Ledger. Cross-references to Vol I Ch 2 (architecture frame), Vol I Ch 6 (statutory institutions), Vol II Ch 15 (Cybersecurity & DPI), App I (statutory backing), and App J (finance line) are wired through.
Existing sheets H.145 (State SOC), H.147 (Consent Vault), H.154 (Account Aggregator rails), H.130 (early Open Data) describe earlier-architecture forms of these systems. They remain in the Atlas as the operational legacy that the current architecture extends and consolidates. Where there is conflict, sheets H.230–H.233 are the canonical form.
H.145 — CYBER — State Security Operations Centre (SOC) 24/7
H.146 — CYBER — Secure-by-Design Standards & Vendor Rules
H.147 — CYBER — Consent Vault (Operating)
H.148 — CYBER — Public Bug Bounty Programme
H.149 — CYBER — Incident Transparency Reporting
H.150 — CYBER — Cybercrime Investigation Capacity
H.151 — CYBER — Citizen Digital Literacy Programme
H.152 — CYBER — Identity Layer Integration Library
H.153 — CYBER — Document Vault for Residents
H.154 — CYBER — Payment Rails Integration (UPI/Account Aggregator)
H.155 — CYBER — Public-Sector Cyber Workforce
H.156 — CYBER — Threat-intelligence Sharing Network
H.157 — CYBER — Critical-Infrastructure Cyber Resilience
H.158 — CYBER — Secure Default Cloud & On-prem Patterns
H.159 — CYBER — Privacy-enhancing Computation Pilots
H.160 — CYBER — Open APIs Programme (Citizen Tech)
H.161 — CYBER — Assisted Access Resilience
H.162 — CYBER — Children & Youth Online Safety
← Appendix H — Program Atlas · Appendix H — Program Atlas →
This is a chapter of The People's Model manifesto for Karnataka — published in full for public review. Every claim may be challenged: write to [email protected].