Ravindra BagaleCourses & study guides

34. Indian Cyber Law and Cyber Crime Awareness

34.3 CERT-In Directions for Organisations

CERT-In (Indian Computer Emergency Response Team, under section 70B of the IT Act) issued directions dated 28 April 2022. Key points every IT and security team should know:

Requirement What it means
Report within 6 hours Specified cyber security incidents must be reported to CERT-In within 6 hours of noticing them
Types of incidents Include targeted scanning, compromise of systems, unauthorised access, website defacement, malware/ransomware, data breaches, attacks on cloud and IoT, and more (see the full list in the directions)
Log retention Keep ICT system logs securely for a rolling 180 days, within India, and provide them to CERT-In when asked
Time sync Synchronise system clocks with NTP servers of NIC or NPL (or servers traceable to them)
Point of contact Designate a point of contact to interact with CERT-In
Specific providers Data centres, VPS/cloud and VPN providers have extra record-keeping duties about customers

How to report: follow the current incident reporting instructions on cert-in.org.in (email and online form details are given there).

Ravindra Bagale's Tip

6 taas khup kami vel aahe! Incident zalyavar "kon report karnar, kasa, kuthlya format madhe" he tevha shodhat basle tar vel jato. Mhanun IR plan (Chapter 31) madhe aadhich CERT-In report cha template, contact person ani approval process lihun theva. Aani logs 180 divas thevle nasatil tar investigation pan hot nahi.

Practice task

Check your lab or AWS setup against the CERT-In points: Are logs kept for 180 days (CloudTrail bucket lifecycle, /etc/logrotate.conf)? Is time synced (chronyc sources)? Write a half-page CERT-In reporting procedure for a fictional company "Konkan Foods".