Compliance Node Overview
Service providers, intermediaries, data centres, body corporates, and government organisations operating in India must, under the Indian Computer Emergency Response Team (CERT-In) Directions issued on 28 April 2022 under section 70B of the Information Technology Act 2000, mandatorily report cyber incidents to CERT-In within 6 hours of noticing them or being notified, enable logs of all ICT systems and maintain them securely for 180 days within Indian jurisdiction, and (for Data Centres, Virtual Private Server (VPS) providers, Cloud Service providers, and Virtual Private Network (VPN) Service providers) register subscriber information including names, period of hire, and IP addresses for at least 5 years after cancellation or withdrawal, with non-compliance penalties including fines up to one lakh rupees or imprisonment up to one year.
Pillar: Cybersecurity · Authority: Indian Computer Emergency Response Team (CERT-In) / Ministry of Electronics and Information Technology (MeitY) · Version: 1.0.0 · Last updated:
Primary source: https://www.cert-in.org.in/
SHA-256 integrity: a7c5686332f3e88c4245ed79ecf7cc2126242f9ac816037d46101abd21d8220e
Primary Citations — 6 traced to source
- On 28 April 2022, the Indian Computer Emergency Response Team (CERT-In) issued new cybersecurity directions under section 70B of the Information Technology Act, 2000, which relate to information security practices, procedure, prevention, response, and reporting of cybersecurity incidents.
- The directions require any service provider, intermediary, data center, body corporate and government organization to mandatorily report cyber incidents to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents.
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access