The direction
On 28 April 2022 the Indian Computer Emergency Response Team issued directions under Section 70B(6) of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents. They apply to service providers, intermediaries, data centres, body corporates and government organisations. They came into effect sixty days after issue.
What they require
- Report specified cyber incidents to CERT-In within six hours of noticing them or being brought to notice. The Annexure to the directions lists the reportable incident types, including targeted scanning of critical systems, compromise of critical systems, unauthorised access to IT systems or data, website defacement, malicious code attacks, identity theft, data breach, data leak and attacks on servers, IoT devices and cloud systems.
- Connect and synchronise all ICT system clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or servers traceable to them.
- Enable logs of all ICT systems, maintain them securely for a rolling period of 180 days, and maintain them within India.
- Designate a point of contact to interface with CERT-In and keep those details current.
- Data centres, virtual private server providers, cloud service providers and VPN service providers must register and retain subscriber and customer records for five years after cancellation or withdrawal of the registration.
- Virtual asset service providers, exchange providers and custodian wallet providers must maintain KYC and transaction records for five years.
Consequence of non-compliance
Section 70B(7) of the IT Act provides that failure to provide the information called for, or to comply with a direction under Section 70B(6), is punishable with imprisonment up to one year or a fine up to one lakh rupees, or both.
What to have ready before an incident
- The CERT-In incident reporting form filled to the point where only the incident facts are missing.
- A named person and an alternate who can send it within six hours, at any hour.
- Log retention configured to 180 days with storage located in India, verified rather than assumed.
- NTP configuration pointing at NIC or NPL.
- A parallel note of the DPDP breach-notification duty under Section 8(6), which is a separate obligation to a different body.
