National CERT
Definition
A government-operated or government-designated team responsible for coordinating cyber incident information at the national level. Examples include CERT-In (India), CISA (US), NCSC (UK), and BSI (Germany). They issue advisories, coordinate sector-wide responses, and may hold legal authority to receive breach notifications.
- Role
- Coordinates cyber incident information nationally
- Examples
- CERT-In (India), CISA (US), NCSC (UK), BSI (Germany)
- Function
- Issues advisories and coordinates sector-wide responses
- Legal role
- May hold authority to receive mandatory breach notifications
Common questions
Does every organisation's breach have to be reported to the national CERT?+
This depends on the jurisdiction's specific law; some countries, such as India under CERT-In directions, mandate reporting of certain categories of incidents within a defined timeframe, while others rely on sector-specific regulators or voluntary reporting, so obligations vary by country and by the type of entity involved.
What is the difference between a national CERT and a private incident response team?+
A national CERT coordinates at the country or sector level, issuing broad advisories, tracking trends across many organisations, and sometimes holding statutory authority, while a private or organisational CSIRT handles incident response for its own specific environment and may report relevant findings up to the national CERT.
Can a national CERT compel an organisation to take specific remediation actions?+
Authority varies by country; some national CERTs, like CERT-In, have statutory powers to direct certain actions or require compliance from regulated entities, while others operate purely in an advisory and coordination capacity without direct enforcement power.
Related terms
- CSIRT
- Computer Security Incident Response Team. The organisational unit responsible for preparing for, detecting, coordinating, and resolving security incidents. Sometimes called CERT (Computer...
- FIRST
- Forum of Incident Response and Security Teams. A global membership organisation that sets standards for CSIRT capability and facilitates trusted information sharing...
- Legal Liaison
- The CSIRT role responsible for advising on legal obligations during an incident: evidence preservation requirements, breach notification deadlines, law enforcement engagement, and...
- Retainer Agreement
- A contract between an organisation and an external IR firm that guarantees a defined response time and service scope in exchange for...
- Team Lead
- The person who owns the incident response process during an active incident. The team lead coordinates analyst tasks, manages escalation to leadership,...