Directions 5-7 establish the technical baseline for evidence preservation + forensic readiness + time integrity. Direction 5: All service providers + intermediaries + data centres + body corporates + government organisations shall mandatorily enable logs of all their ICT systems + maintain them securely for a rolling period of 180 days. Logs to be maintained within the Indian jurisdiction (data localisation). Log scope: system logs + access logs + audit logs + firewall logs + IDS/IPS logs + WAF logs + endpoint logs + cloud service logs + DNS logs + email logs + authentication logs + API logs + database logs + privileged session logs + network flow logs. Log integrity: tamper-evident + WORM storage where feasible + cryptographic hash + chain of custody preparation + log forensics readiness. Direction 6: Connect to Network Time Protocol (NTP) Server of National Informatics Centre (NIC) or National Physical Laboratory (NPL) or with NTP servers traceable to these NTP servers for synchronisation of all their ICT systems clocks. Entities having ICT infrastructure spanning multiple geographies may also use accurate and standard time source other than NPL and NIC however it is to be ensured that their time source shall not deviate from NPL and NIC. Clock skew detection + drift monitoring + audit trail. Direction 7: Logs maintained pursuant to Direction 5 shall be provided to CERT-In along with reporting of any incident or when ordered/directed by CERT-In + provision of access on incident-by-incident basis + or systemic basis under Section 70B(6) IT Act 2000 + format per CERT-In requirements + accessibility for forensic examination + cooperation with CERT-In personnel. Operational implementation: centralised log management + SIEM + log forwarder architecture + India-region storage (AWS Mumbai + Azure India + GCP India regions) + WORM + tamper-evident + cryptographic + NTP infrastructure + clock-sync verification + log retrieval workflow + forensic chain of custody. Coordinates with IT Act 2000 Sec 70B(6) + DPDP Act 2023 + Sahamati 7-year financial log retention + RBI Cyber Framework + Section 91 CrPC (production of documents) + Indian Evidence Act 1872 Section 65B (electronic evidence) + ISO 27001 + NIST SP 800-92. CERT-In Dir 5-7 Logging applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.