Direction 2022
CERT-In Directions on Cyber Incident Reporting, April 2022
Issued by Indian Computer Emergency Response Team
Effective: 27 Jun 2022
Plain-English summary
The CERT-In Directions on Cyber Incident Reporting, 2022, continue to be valid and constitute the main statutory requirement for prompt cyber threat mitigation in India. According to the regulation, all individuals or organizations owning or controlling any computer resource must notify specific cyber threats within the very short period of 6 hours from their first identification. As for the reporting period, the regulatory framework mandates several operational requirements that are necessary to prevent any cyber threat – clock synchronization of all systems with NTP and national servers, maintaining system logs for 180 days, and storing all data for 5 years in case of cloud computing and virtual private network service providers. Violation of such directions constitutes a crime under section 70B(7) of the IT Act.
Who it applies to
Banking · Payments & Fintech · Crypto / VDA · Telecom & Tech
Topics
Cybersecurity & IT Risk
Latest news
No related news yet. We publish updates as regulators act.