India CERT-In Cyber Security Directions 2022
CERT-In Scope + Section 70B Authority

India CERT-In Cyber Security Directions 2022 CERTIN-Scope-Section70B-IT-Act-2000-Directions-28April2022-Effective-28June2022-MeitY-CERTIn-Applicability: CERT-In Directions Scope + Section 70B IT Act 2000 + Directions of 28 April 2022 + Effective 28 June 2022 + MeitY/CERT-In Governance + Applicability to All Entities + 17 Directions Structure

Indian Computer Emergency Response Team (CERT-In) Directions issued by Ministry of Electronics and Information Technology (MeitY) Government of India on 28 April 2022 (Notification No. 20(3)/2022-CERT-In) under sub-section (6) of section 70B of the Information Technology Act 2000 (IT Act 2000). Authority basis: Section 70B(1) of IT Act 2000 designates CERT-In as the national agency for cyber incident response since 27 October 2009 Gazette notification + Section 70B(4) lists CERT-In functions including collection + analysis + dissemination of cyber incident information + forecasts + emergency measures + coordination + guidelines + advisories + vulnerability notes + Section 70B(6) empowers CERT-In to call for information from service providers + intermediaries + data centres + body corporates + persons. IT (CERT-In and Manner of performing functions and duties) Rules 2013 (notified 16 January 2014) provide operational framework. Effective date: 28 June 2022 (60 days after publication; extended to 25 September 2022 for select provisions including Data Centre/VPS/VPN customer KYC + VASP KYC). Comprises 17 Directions structured in 6 sections: (A) Incident Reporting Requirements (Dir 1-4); (B) System Logging and Clock Synchronization (Dir 5-7); (C) Service Provider Obligations - Data Centre + VPS + VPN (Dir 8-10); (D) Virtual Asset and Financial Platform Requirements (Dir 11-13); (E) Compliance and Cooperation (Dir 14-17). Applicability: service providers + intermediaries (as defined under IT Act Section 2(1)(w) including ISPs + telecom + social media platforms + e-commerce + Bharat Stack participants) + data centres + body corporates (companies + firms + LLPs handling personal data per IT Act 43A) + Government organisations + virtual asset service providers (cryptocurrency exchanges + wallets + custodian wallet providers) + cloud service providers + financial intermediaries. Effectively all entities operating in or providing services to India touching ICT systems. Penalties for non-compliance: per IT Act Section 70B(7) - imprisonment up to 1 year or fine up to INR 1 lakh or both. Cyber Security Incidents covered: 20 categories including ransomware + data breach + DDoS + targeted scanning/probing + identity theft + cyber-physical incidents + critical infrastructure breaches + IoT breaches + supply chain compromise + APT groups + critical industrial systems breaches. Coordinates with IT Act 2000 + IT Rules 2013 + DPDP Act 2023 (breach reporting 72 hours to DPBI) + RBI Cyber Security Framework (RBI requires its own 2-6 hour incident reporting overlap with CERT-In) + SEBI System Audit Framework + IRDAI Information and Cyber Security Guidelines + Indian Cyber Crime Coordination Centre (I4C) + National Critical Information Infrastructure Protection Centre (NCIIPC) + DPI India Stack + sectoral CERTs (CERT-Fin + CERT-Power + CERT-Healthcare). Public + freely available via cert-in.org.in. CERT-In Directions + Scope + Section 70B + 28 April 2022 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.