{"id":20394,"date":"2026-06-12T16:08:35","date_gmt":"2026-06-12T10:38:35","guid":{"rendered":"https:\/\/banitoday.com\/iit-audit-reveals-vulnerabilities-in-cbses-osm-system-did-oversight-fail-indias-largest-school-board\/"},"modified":"2026-06-12T16:08:35","modified_gmt":"2026-06-12T10:38:35","slug":"iit-audit-reveals-vulnerabilities-in-cbses-osm-system-did-oversight-fail-indias-largest-school-board","status":"publish","type":"post","link":"https:\/\/banitoday.com\/hi\/iit-audit-reveals-vulnerabilities-in-cbses-osm-system-did-oversight-fail-indias-largest-school-board\/","title":{"rendered":"IIT audit reveals vulnerabilities in CBSE&#8217;s OSM system: Did oversight fail India&#8217;s largest school board?"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<div class=\"e9jwa\">\n<div class=\"vdo_embedd\">\n<div class=\"GfdvZ\">\n<section class=\"_bIDB  clearfix id-r-component leadmedia undefined undefined  E9tg9 \" style=\"top:0px\">\n<div class=\"_bIDB\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"ypVvZ\">\n<div class=\"WGttI\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-131681549,imgsize-1614550,width-400,height-225,resizemode-4\/iit-audit-puts-cbse39s-osm-portal-under-the-lens-are-india39s-digital-exam-systems-ready-for-the-risks-they-face.jpg\" alt=\"IIT audit reveals vulnerabilities in CBSE's OSM system: Did oversight fail India's largest school board?\" title=\"The controversy surrounding CBSE's On-Screen Marking portal has evolved into a larger debate on cybersecurity, accountability and digital governance. As an IIT-led panel prepares its final report, the episode highlights the challenges of securing high-stakes examination systems and raises important questions about how public institutions manage and monitor critical digital infrastructure.\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<div class=\"Ta7d_ img_cptn\"><span title=\"The controversy surrounding CBSE's On-Screen Marking portal has evolved into a larger debate on cybersecurity, accountability and digital governance. As an IIT-led panel prepares its final report, the episode highlights the challenges of securing high-stakes examination systems and raises important questions about how public institutions manage and monitor critical digital infrastructure.\">The controversy surrounding CBSE&#8217;s On-Screen Marking portal has evolved into a larger debate on cybersecurity, accountability and digital governance. As an IIT-led panel prepares its final report, the episode highlights the challenges of securing high-stakes examination systems and raises important questions about how public institutions manage and monitor critical digital infrastructure.<\/span><\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p>The controversy around the Central Board of Secondary Education&#8217;s (CBSE) On-Screen Marking (OSM) portal is no longer just about a software glitch. It has opened up a much larger debate about accountability, digital governance, and the risks of relying on technology that may not have been thoroughly tested before being introduced into a system that affects millions of students.<span class=\"id-r-component br\" data-pos=\"3\"\/>As an IIT-led audit panel prepares to submit its report to the Ministry of Education, the findings emerging from the investigation raise serious concerns. The key issue is not that the portal was launched without any audit. Rather, according to a member of the IIT panel who spoke to ANI on condition of anonymity, the system was audited, but the checks were not comprehensive enough to detect several vulnerabilities that surfaced later.<span class=\"id-r-component br\" data-pos=\"7\"\/><\/p>\n<p><h2 style=\"line-height:1.38;margin-top:18pt;margin-bottom:6pt;\">Audited, yet vulnerable<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"9\"\/>The distinction is significant. This was not a matter of lack of security testing, but rather the potential inadequacy of the security testing procedures for a portal managing such sensitive exam results.<span class=\"id-r-component br\" data-pos=\"11\"\/>As cybersecurity professionals will attest, there is indeed a big difference between compliance testing and thorough security tests that simulate a realistic cyberattack scenario. In this case, it seems that even if an audit was performed on the portal, it did not undergo a thorough test.<span class=\"id-r-component br\" data-pos=\"14\"\/><\/p>\n<p><h2 style=\"line-height:1.38;margin-top:18pt;margin-bottom:6pt;\">The questions raised by an ethical hacker<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"16\"\/>One of the most talked-about aspects of the controversy is the role played by 19-year-old ethical hacker Nisarga Adhikary from West Bengal.<span class=\"id-r-component br\" data-pos=\"18\"\/>The vulnerabilities reportedly identified by Adhikary, including alleged OTP bypass methods, examiner account access through a hardcoded master password and possible access routes to answer-sheet data, were later found to be broadly similar to issues observed during the IIT panel&#8217;s assessment.<span class=\"id-r-component br\" data-pos=\"21\"\/>The larger concern is not that a young ethical hacker discovered these weaknesses. The concern is that vulnerabilities identified outside official security systems were not flagged during earlier audits. The episode has raised questions about how robust existing security review mechanisms really are.<span class=\"id-r-component br\" data-pos=\"23\"\/><\/p>\n<p><h2 style=\"line-height:1.38;margin-top:18pt;margin-bottom:6pt;\">Digitalisation brings new challenges<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"25\"\/>India&#8217;s education system has rapidly moved online over the past decade. Whereas the processes of examination, admission, evaluation, scholarship, and others were traditionally done manually, they can now be handled through digital channels.<span class=\"id-r-component br\" data-pos=\"28\"\/>Whereas technologies have helped make these processes easy and fast, the case of OSM reveals how dangerous it becomes when there is no appropriate measure to match the digital expansion.<span class=\"id-r-component br\" data-pos=\"30\"\/>The difference between examination systems and other commercial platforms is that while the failure of an e-commerce platform may cause inconveniences. A security lapse in an examination system can raise doubts about fairness, credibility and public trust.<span class=\"id-r-component br\" data-pos=\"33\"\/>For students, parents and educators, confidence in the examination process is as important as the process itself.<span class=\"id-r-component br\" data-pos=\"35\"\/><\/p>\n<p><h2 style=\"line-height:1.38;margin-top:18pt;margin-bottom:6pt;\">Technology can be outsourced, accountability cannot<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"37\"\/>The OSM portal was developed and managed by Coempt Eduteck, the private technology company that has come under scrutiny following the controversy.<span class=\"id-r-component br\" data-pos=\"39\"\/>However, as per the views expressed by the member of IIT panel, this seems to be not just the problem with one particular vendor.<span class=\"id-r-component br\" data-pos=\"41\"\/>The government agencies prefer private companies for technological needs because building and maintaining such systems is not an easy task and requires technical expertise. <!-- -->The expert from the IIT panel admitted that it may be hard for CBSE to do all alone.<span class=\"id-r-component br\" data-pos=\"45\"\/>But experts believe that even if the services are outsourced, there is no way to outsource accountability for proper functioning of such systems.<span class=\"id-r-component br\" data-pos=\"47\"\/><\/p>\n<p><h2 style=\"line-height:1.38;margin-top:18pt;margin-bottom:6pt;\">A temporary fix, not a permanent solution<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"49\"\/>Once these vulnerabilities were highlighted, representatives of IIT Madras and IIT Kanpur, along with CBSE and the Digital India Corporation, came together to look for weaknesses and develop another system of platforms for examiners.<span class=\"id-r-component br\" data-pos=\"52\"\/>Currently, this new platform is being used for the process of verification and reevaluation. However, according to the representative from IIT, this can be considered \u201ckind of patchwork,&#8221; implying that it could be a temporary solution.<span class=\"id-r-component br\" data-pos=\"54\"\/>The above observation raises an important issue regarding how policymakers should view the upgrading process of critical systems of examinations. Should there always be a need to wait until something goes wrong before fixing it, or should a more strategic view of the issue be developed?<span class=\"id-r-component br\" data-pos=\"56\"\/>That observation raises an important question for policymakers. Should critical examination infrastructure continue to be upgraded only after problems emerge, or is it time for a more comprehensive and future-ready approach to educational technology?<span class=\"id-r-component br\" data-pos=\"58\"\/><\/p>\n<p><h2 style=\"line-height:1.38;margin-top:18pt;margin-bottom:6pt;\">Security must be built in, not added later<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"60\"\/>One of the major recommendations expected from the IIT panel is the adoption of stronger cybersecurity practices before platforms are deployed.<span class=\"id-r-component br\" data-pos=\"63\"\/>According to the panel member, systems of this scale should undergo vulnerability assessments, penetration testing and Red Team-Blue Team exercises designed to simulate real cyberattacks.<span class=\"id-r-component br\" data-pos=\"65\"\/>These practices are standard in mature cybersecurity environments. Their purpose is simple: identify weaknesses before malicious actors can exploit them.<span class=\"id-r-component br\" data-pos=\"67\"\/>The emphasis on such measures suggests that cybersecurity may not yet be fully embedded into the design process of some public digital platforms. <!-- -->Instead, it often receives attention only after concerns are raised.<span class=\"id-r-component br\" data-pos=\"71\"\/><\/p>\n<p><h2 style=\"line-height:1.38;margin-top:18pt;margin-bottom:6pt;\">No evidence of misuse, but concerns persist<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"73\"\/>The IIT panel member told ANI that investigators found no evidence that student records were leaked or misused.<span class=\"id-r-component br\" data-pos=\"75\"\/>According to the assessment, the ethical hacker accessed and downloaded certain data but later deleted it, and there is no indication that examination records were distributed or exploited.<span class=\"id-r-component br\" data-pos=\"77\"\/>That finding is likely to reassure students and parents. However, experts caution that the absence of actual damage does not eliminate concern. <!-- -->The larger issue is that vulnerabilities existed in a system handling highly sensitive academic information in the first place.<span class=\"id-r-component br\" data-pos=\"81\"\/><\/p>\n<p><h2 style=\"line-height:1.38;margin-top:18pt;margin-bottom:6pt;\">A wake-up call for public digital systems<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"83\"\/>The OSM controversy is about much more than one portal or one security audit. It highlights the challenges public institutions face as governance increasingly depends on digital infrastructure.<span class=\"id-r-component br\" data-pos=\"85\"\/>As CBSE awaits the IIT panel&#8217;s final report, one message is becoming clear: Institutions must maintain stronger control over sensitive data and ensure that critical platforms undergo exhaustive security testing before they are rolled out.<span class=\"id-r-component br\" data-pos=\"88\"\/>The lesson extends beyond the education sector. As more public services move online, trust in institutions will increasingly depend on the strength and reliability of the technology supporting them.<span class=\"id-r-component br\" data-pos=\"90\"\/>The OSM episode serves as a reminder that in today&#8217;s digital world, security is not just a technical requirement. It is essential to maintaining public confidence in the institutions people rely on every day.<span class=\"id-r-component br\" data-pos=\"92\"\/><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">(With inputs from ANI)<\/span><span class=\"id-r-component br\" data-pos=\"94\"\/><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/education\/news\/iit-audit-reveals-vulnerabilities-in-cbses-osm-system-did-oversight-fail-indias-largest-school-board\/articleshow\/131681427.cms\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The controversy surrounding CBSE&#8217;s On-Screen Marking portal has evolved into a larger debate on cybersecurity, accountability and digital governance. As an IIT-led panel prepares its final report, the episode highlights the challenges of securing high-stakes examination systems and raises important questions about how public institutions manage and monitor critical digital infrastructure. The controversy around the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":20395,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[264],"tags":[],"class_list":["post-20394","post","type-post","status-publish","format-standard","has-post-thumbnail","category-education"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts\/20394","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/comments?post=20394"}],"version-history":[{"count":0,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts\/20394\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/media\/20395"}],"wp:attachment":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/media?parent=20394"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/categories?post=20394"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/tags?post=20394"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}