34. Indian Cyber Law and Cyber Crime Awareness
34.3 CERT-In Directions for Organisations
CERT-In (Indian Computer Emergency Response Team, under section 70B of the IT Act) issued directions dated 28 April 2022. Key points every IT and security team should know:
| Requirement | What it means |
|---|---|
| Report within 6 hours | Specified cyber security incidents must be reported to CERT-In within 6 hours of noticing them |
| Types of incidents | Include targeted scanning, compromise of systems, unauthorised access, website defacement, malware/ransomware, data breaches, attacks on cloud and IoT, and more (see the full list in the directions) |
| Log retention | Keep ICT system logs securely for a rolling 180 days, within India, and provide them to CERT-In when asked |
| Time sync | Synchronise system clocks with NTP servers of NIC or NPL (or servers traceable to them) |
| Point of contact | Designate a point of contact to interact with CERT-In |
| Specific providers | Data centres, VPS/cloud and VPN providers have extra record-keeping duties about customers |
How to report: follow the current incident reporting instructions on cert-in.org.in (email and online form details are given there).
Ravindra Bagale's Tip
6 hours is very little time! If you start figuring out "who will report, how, and in which format" only after an incident, time is lost. So write the CERT-In report template, the contact person and the approval process into the IR plan (Chapter 31) in advance. And if logs were not kept for 180 days, the investigation can't happen either.
Ravindra Bagale's Tip – मराठी
6 तास खूप कमी वेळ आहे! Incident झाल्यावर "कोण report करणार, कसा, कुठल्या format मध्ये" हे तेव्हा शोधत बसले तर वेळ जातो. म्हणून IR plan (Chapter 31) मध्ये आधीच CERT-In report चा template, contact person आणि approval process लिहून ठेवा. आणि logs 180 दिवस ठेवले नसतील तर investigation पण होत नाही.
Ravindra Bagale's Tip – हिंदी
6 घंटे बहुत कम समय है! Incident के बाद "कौन report करेगा, कैसे, किस format में" यह तब ढूँढने बैठे तो समय निकल जाता है. इसलिए IR plan (Chapter 31) में पहले से CERT-In report का template, contact person और approval process लिखकर रखो. और logs 180 दिन नहीं रखे तो investigation भी नहीं हो पाता.
Practice task
Check your lab or AWS setup against the CERT-In points: Are logs kept for 180 days (CloudTrail bucket lifecycle, /etc/logrotate.conf)? Is time synced (chronyc sources)? Write a half-page CERT-In reporting procedure for a fictional company "Konkan Foods".