India CERT-In Cyber Security Directions 2022
CERT-In Incident Reporting (Dir 1-4)

India CERT-In Cyber Security Directions 2022 CERTIN-IncidentReporting-6Hour-Mandatory-Format-POC-20Categories-Section70B-Dir1to4: CERT-In Directions 1-4 Incident Reporting - Mandatory 6-Hour Window + 20 Categories + Standardised Report Format + Designated Point of Contact + 24x7 Channel

Directions 1-4 establish the mandatory incident reporting regime - the highest-profile and most operationally demanding element of the 2022 Directions. Direction 1: Mandatory cyber incident reporting to CERT-In by service providers + intermediaries + data centres + body corporates + government organisations within 6 hours of noticing such incident or being brought to notice about such incident. Direction 2: Expanded list of 20 Cyber Incident Categories that must be reported - (1) Targeted scanning/probing of critical networks/systems; (2) Compromise of critical systems/information; (3) Unauthorised access of IT systems/data; (4) Defacement of website or intrusion into a website and unauthorised changes; (5) Malicious code attacks; (6) Attack on servers + databases + storage + critical infrastructure; (7) Identity Theft + spoofing + phishing attacks; (8) Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks; (9) Attacks on Critical Information Infrastructure + supervisory control and data acquisition (SCADA) and operational technology systems and Wireless networks; (10) Attacks on Cloud Computing; (11) Attacks/incident/breach pertaining to Big Data + Block chain + virtual assets + virtual asset exchanges + custodian wallets + Robotics + 3D and 4D Printing + additive manufacturing + Drones; (12) Attacks/breaches on systems running blockchain; (13) Attacks/incident/breach pertaining to AI/ML systems; (14) Attacks/breach related to Quantum Computing systems; (15) Data Breach; (16) Data Leak; (17) Attacks on Internet of Things (IoT) devices and associated systems/networks/software/servers; (18) Attacks/incidents affecting Safety of human beings; (19) Attack on social media accounts of individuals/organisations; (20) Other categories of cyber incidents based on emerging threats. Direction 3: Reports of cyber incidents shall be submitted in the format provided at Annexure I to CERT-In via incident@cert-in.org.in or by phone or by fax or by online portal at www.cert-in.org.in + Standard Annexure I structure (entity details + incident description + impact + actions taken + IOCs + logs). Direction 4: Designate Point of Contact for the purposes of these directions + Personnel name + Designation + 24x7 contact info (email + phone) + escalation hierarchy + communicate to CERT-In + update on changes. Operational implementation: 24x7 SOC + Cyber Incident Response Team (CIRT) + auto-alert pipeline + escalation triage + executive sponsor + legal + DPO + PR/communications + integration with RBI/SEBI/IRDAI reporting timelines. Coordinates with RBI Cyber Framework 2-6 hour reporting + SEBI System Audit Framework + DPDP Act 2023 Sec 8(6) 72-hour DPBI reporting + IRDAI Cyber Guidelines + sectoral CERTs + I4C (cyber crime + financial fraud). CERT-In Dir 1-4 Incident Reporting applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 143 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 6 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities

API 1164 · 5 controls

  • API1164-07 Remote Access
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • API1164-24 Vulnerability assessment for critical systems
  • FTC-Safeguards-EffectiveDate-Small-Institution Effective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6)
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-Risk-Assessment Written Risk Assessment (16 CFR 314.4(b))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment
  • GhCSA-Cybercrime-Lawful-Access-Preservation Cybercrime Offences, Lawful Access and Electronic Evidence Preservation
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement

Bahrain PDPL · 3 controls

FISMA · 3 controls

  • FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting
  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda
  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • IACS-UR-E26-Identify-Plan-Risk-Survey-Documentation IACS UR E26 Identify Goal - Ship Cyber Resilience Plan + CBS Risk Assessment + Survey + Documentation
  • IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned
  • IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-13 Board Accountability for Operational Risk Management

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • 4.3.1 Risk Assessment and Impact Analysis
  • 4.4.7 Emergency and Incident Response

FedRAMP Rev 5 · 2 controls

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)

GLBA · 2 controls

  • GLBA-Implementation-Roadmap-Examination GLBA Implementation Roadmap, Examination Readiness, Roles and Tooling
  • GLBA-Status-FTC-CFPB-SEC-NAIC-Enforcement GLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions
  • IATF16949-Clause6-Planning-Risk-Contingency-Objectives-Change IATF 16949 Clause 6 - Planning + Risks and Opportunities + Contingency Plans + Quality Objectives + Change
  • IATF16949-Clause8-Operation-APQP-Design-Production-ControlPlan-SpecialChars IATF 16949 Clause 8 - Operation Planning + APQP + Design + Special Characteristics + Production + Control Plan + Set-Up Verification
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

IEEE 1686 · 2 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team

India DPDP Act · 2 controls

  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update
  • CJIS-17 Risk Assessment

FDA 21 CFR Part 11 · 1 control

  • Part11.CSV Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
  • CAT-D5-1 Incident planning and strategy
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)
  • FSSC-Additional-Requirements-v6 FSSC 22000 Additional Requirements v6 (Food Defense + Food Fraud + Allergen + Environmental + Culture)
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety

HITECH Act · 1 control

  • HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors

HKMA SPM · 1 control

  • HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF

IEEE 7000 · 1 control

  • IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection
  • IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA

ISO/IEC 27010:2015 · 1 control

  • 27010-16.1 Continuity of Sharing

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture
  • DSOMM-1 Culture, Organization, Education, and Governance

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PSPF24-1 Security Culture, Governance, Risk Management
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • CPSC-RA.3 Lifecycle Risk Assessment
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 143 it maps to, and the evidence behind each claim, over MCP and REST.