India CERT-In Cyber Security Directions 2022
CERT-In VASP Requirements (Dir 11-13)

India CERT-In Cyber Security Directions 2022 CERTIN-VASP-VirtualAsset-CryptoExchange-KYC-FinancialTransactionRecords-DigitalPayment-Dir11to13: CERT-In Directions 11-13 Virtual Asset Service Provider Requirements - KYC for Virtual Asset Exchanges/Custodian Wallets + Financial Transaction Records + Digital Payment System Incident Reporting

Directions 11-13 impose specific obligations on Virtual Asset (cryptocurrency) ecosystem + digital payment systems given the elevated cyber risk + financial crime risk. Direction 11: Virtual Asset Service providers (VASPs) + Virtual Asset Exchange providers and Custodian Wallet Providers (as defined by Ministry of Finance from time to time) shall mandatorily maintain all information obtained as part of Know Your Customer (KYC) and records of financial transactions for a period of five years so as to ensure cyber security in the area of payments and financial markets for citizens while protecting their data + fundamental rights + economic freedom in view of the growth of virtual assets. KYC includes: identity verification per Prevention of Money Laundering Act PMLA + Aadhaar + PAN + or alternative IDs + address proof + risk assessment + beneficial ownership + customer due diligence. Direction 12: With respect to transaction records + accurate information shall be maintained in such a way that individual transactions can be reconstructed along with the relevant elements comprising of but not limited to information relating to the identification of the relevant parties including IP addresses along with timestamps and time zones + transaction ID + the public keys (or equivalent identifiers) + addresses or accounts involved (or equivalent identifiers) + the nature and date of the transaction + and the amount transferred. Direction 13: Digital Payment Systems (UPI + IMPS + NEFT + RTGS + AePS + BHIM + Paytm + PhonePe + Google Pay + cards + wallets + Direct Debit) shall report cyber incidents in line with Direction 1-3 + with elevated visibility given the financial crime risk and consumer impact. Coordinates with Prevention of Money Laundering Act (PMLA) 2002 + Travel Rule FATF Recommendation 16 + RBI Master Directions on KYC + RBI Master Direction NBFC-AA (where AA-mediated for FIPs) + RBI Cyber Resilience for Payment Aggregators + SEBI VASP guidance + Cryptocurrency and Regulation of Official Digital Currency Bill (pending) + FIU-IND Financial Intelligence Unit + Income Tax Act Section 115BBH on virtual digital assets (30 percent tax + 1 percent TDS) + RBI Digital Rupee CBDC + Telecommunications Act 2023. Operational implementation: VASP onboarding workflow + PMLA KYC + Travel Rule compliance + transaction reconstruction capability + secure 5-year storage + India localisation + provision to CERT-In + FIU-IND + Income Tax + ED reporting + segregation of customer funds + cold/hot wallet controls + cyber resilience aligned with RBI/IRDAI/SEBI cyber frameworks. CERT-In Dir 11-13 VASP applies.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.