Skip to content

CERT-in Direction April 2022

Definition

Direction issued under Section 70B(6) of the IT Act 2000 requiring 6-hour incident reporting, 180-day log retention in India, KYC retention by data centres/VPS providers/cloud providers/VPN providers, and synchronisation of system clocks to NPL or NIC time sources.

Legal authority
IT Act 2000, Section 70B(6)
Log retention period
180 days
KYC retention period (VPN/cloud)
5 years
Incident reporting timeframe
6 hours of detection

Common questions

What is CERT-In Direction April 2022?+

It is an Indian government directive issued under IT Act Section 70B(6) that sets cybersecurity and incident reporting requirements for service providers, data centres, VPN providers, and intermediaries. The directive mandates how long logs must be kept, how quickly incidents must be reported, and what information providers must retain about their users.

How quickly must an incident be reported under this direction?+

Service providers and data centres must report covered security incidents to CERT-In within 6 hours of detection. This applies to any incident that meets the directive's notification threshold.

How long must VPN and cloud providers keep logs and user data?+

Most logs must be retained for 180 days. VPN providers and cloud service providers also must retain KYC (Know Your Customer) subscriber information for 5 years. System clocks must be synchronized to NPL (National Physical Laboratory) or NIC time sources to ensure accurate logging.

Related terms

CloudTrail
AWS service that records every control-plane API call across an AWS account, with the principal, source IP, action, target resource and timestamp....
Control-Plane Log
A record of management API calls against cloud resources (create, delete, modify, attach IAM role). AWS CloudTrail, Azure Activity Log, and GCP...
Data-Plane Log
A record of operations on the data inside a resource: S3 object reads, KMS decrypts, database queries. Off by default in most...
EBS Snapshot
A point-in-time, block-level copy of an EBS volume stored in S3. Snapshots are incremental, encrypted if the source volume is encrypted, and...
Forensic Account
A dedicated cloud account, separate from the production account, that holds shared snapshots, the forensic analysis instance, and the chain-of-custody artefacts. Isolating...
IDS vs IPS
An intrusion detection system observes copied traffic and alerts. An intrusion prevention system sits inline on the data path and blocks. Snort...
IPSec AH and ESP
Authentication Header provides integrity and origin authentication only. Encapsulating Security Payload provides confidentiality plus optional integrity. Almost all modern IPSec deployments use...
Kerberos
An MIT-designed authentication protocol using a Key Distribution Centre, ticket-granting tickets and service tickets. The backbone of Active Directory authentication. Replay-protected via...
MLAT
Mutual Legal Assistance Treaty. The formal mechanism for cross-border evidence requests. India has bilateral MLATs with over 40 countries including the US,...
NGFW
Next-generation firewall: stateful packet inspection plus application identification, integrated IPS, TLS inspection and user-identity awareness. Palo Alto, Fortinet, Check Point and Cisco...
NIST IR 8006
The August 2020 NIST Interagency Report titled NIST Cloud Computing Forensic Science Challenges. Catalogues 65 challenges across nine categories: architecture, data collection,...
Service Control Policy
An AWS Organizations policy attached to an account or OU that constrains what IAM principals inside the account can do. Used in...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.