Skip to content
purabalela

purabalela

purabalela

  • Home
  • Finance
  • Sports
  • Law
  • Music
  • Toggle search form

Everything You Need To Know About India’s New Guidelines Related To Cyber ​​Incident Reporting By CERT-In – IT and Internet

Posted on June 16, 2022 By admin No Comments on Everything You Need To Know About India’s New Guidelines Related To Cyber ​​Incident Reporting By CERT-In – IT and Internet

Ankura Consulting Group LLC


16 June 2022

Ankura Consulting Group LLC


To print this article, all you need is to be registered or login on Mondaq.com.

On April 28, 2022, the Indian Computer Emergency Response Team (CERT-In), a functional organization under the Ministry of Electronics and Information Technology (MeitY), Government of India issued directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet.1

The directions are issued to augment and strengthen cyber security in the country. The directions will be effective from June 27, 2022 (60 days from the date of issue).

  • Synchronization of time clocks to NTP servers of NIC – This is applicable to all service providers, intermediaries, data centers, body corporate and government organizations. For the servers and infrastructure hosted in India the time can be synced with the following:

    • National Informatics Center (NIC):

      • samay1.nic.in

      • samay2.nic.in


    • National Physical Laboratory (NPL):



  • For servers and infrastructure outside India the time can be synced with the nearest server having atomic time. You may use https://pool.ntp.org/

  • While storing the logs of any device, application, database, etc. make sure the local time as, as well as the UTC time, is recorded in separate columns, if possible, along with time zone details alongside the timestamp.

  • Reporting Cyber ​​Incidents in 6 hours to CERT-In – While many other developed countries expect the incidents to be reported in 48-72 hours, CERT-In has given a very aggressive time frame of 6 hours for reporting incidents. This means companies need to have a monitoring mechanism in place to identify cyber security incidents and a well-equipped incident response team along with an incident response plan must be in place. The relevant stakeholders should get immediate intimation in case of a suspected security breach, and they must be in a position to triage and avoid false positives. A readiness assessment can help check if the timeline can be met.

  • POC to Interact with CERT-In – Companies will need to assign a Point of Contact with whom CERT-In can communicate for any information. CERT-In has also provided a format in which such information needs to be provided to them.

  • Maintaining Logs for 180 Days – All companies need to maintain logs in India for a rolling period of 180 days. This means the companies need to look at their log management policies, logging capabilities of devices and applications, secure log storage, and accessibility. An assessment to validate these points is important for all organizations for ensuring compliance. Companies may have data related to India hosted in overseas data centers, in that case, the logs must be replicated in India.

    • It is also important to pass on such obligations to vendors and clients who are handling / storing data so that, in case of a breach, they may be able to comply with the directives.


  • Additional obligations for Data Centers, Virtual Private Server (VPS) providers, Cloud Service providers and Virtual Private Network Service (VPN Service) providers:

    • Apart from the requirements detailed above, CERT-In has provided a list of data points that needs to be maintained by data centers and server providers for a period of 5 years or more.

    • Virtual asset service providers, virtual asset exchange providers, and custodian wallet providers need to maintain KYC details for 5 years.

CERT-in has also provided a list of cyber security incidents and details such as email ID, phone, and fax number where incidents need to be reported.

With limited time in hand, it is important for companies to relook and validate at their IT infrastructure and logging capabilities so that they are in compliance with the guidelines.

1202576a.jpg

Footnote

1. https://www.cert-in.org.in/Directions70B.jsp

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

POPULAR ARTICLES ON: Media, Telecoms, IT, Entertainment from India

.

Law Tags:Corporate / Commercial Law, Corporate and Company Law, Entertainment, Everything You Need To Know About Indias New Guidelines Related To Cyber ​​Incident Reporting By CERT-In, IT, IT and Internet, Media, mondaq, Security, Technology, Telecoms

Post navigation

Previous Post: Park Tool PRS-25 bike repair stand review
Next Post: Trezor Trust.com Review: How to Make Safe Investments Using Trezor Trust.com

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • June 2022
  • May 2022

Categories

  • Finance
  • Law
  • Music
  • Sports

Recent Posts

  • PFAS Regulations Could Open Floodgates to Prop 65 Enforcement – Assess & Manage Your Exposure Now
  • BC Supreme Court Grants Injunction Preventing The Sale Of The Nasoga Lands To The Nisga’a Nation – Indigenous Peoples
  • EU countries with the regulation of cryptocurrencies
  • Privacy Just Took On a Whole New Meaning
  • QOZs Illustrate How Critical Tax Theory May Bolster Tax Policy Analysis – Capital Gains Tax

Recent Comments

No comments to show.
  • About us
  • Contact us
  • DMCA
  • Privacy policy
  • Terms and conditions

Copyright © 2022 purabalela.

Powered by PressBook WordPress theme