Optimize IAS
  • Home
  • About Us
  • Courses
    • Prelims Test Series
      • LAQSHYA 2026 Prelims Mentorship
    • Mains Mentorship
      • Arjuna 2026 Mains Mentorship
    • Mains Master Notes
  • Portal Login
    • Home
    • About Us
    • Courses
      • Prelims Test Series
        • LAQSHYA 2026 Prelims Mentorship
      • Mains Mentorship
        • Arjuna 2026 Mains Mentorship
      • Mains Master Notes
    • Portal Login

    Reporting cyber incidents in 6 hrs mandatory

    • April 29, 2022
    • Posted by: OptimizeIAS Team
    • Category: DPN Topics
    No Comments

     

     

    Reporting cyber incidents in 6 hrs mandatory

    Subject: Science

    Section: National Organisation

    Context: The new guidelines issued by CERT-In to companies operating in India.

    New guidelines issued by CERT-In:

    • CERT-In has mandated that all cyber security incidents such as targeted scanning or probing of critical networks and systems, compromise of critical systems and information, unauthorised access of data and systems among others must be informed to it by the respective companies within six hours of either being made aware of the incident or becoming aware itself.
    • It says companies operating in India say that service providers, intermediaries, data centres, companies and government organisations must mandatorily report such incidents within six hours.
    • It has also mandated that virtual asset service providers, virtual asset exchange providers and custodian wallet service providers shall maintain all the information they have gathered as a part of the know your customer (KYC) process and records of financial transactions for a period of five years.
    • With respect to transaction records, accurate information shall be maintained in such a way that individual transaction can be reconstructed along with the relevant elements comprising of, but not limited to, information relating to the identification of the relevant parties including IP addresses along with timestamps and time zones, transaction ID, the public keys (or equivalent identifiers), addresses or accounts involved (or equivalent identifiers), the nature and date of the transaction, and the amount transferred
    • Data centres, virtual private server providers, cloud service providers, and VPN providers shall be required to keep details like customer’s validated name, period of the service, IP addresses allotted and used, purpose for which the service was sought, address and contact number as well as ownership pattern.

    Computer Emergency Response Team (CERT-In)

    https://optimizeias.com/computer-emergency-response-team-cert-in/

    Reporting cyber incidents in 6 hrs mandatory Science
    Footer logo
    Copyright © 2015 MasterStudy Theme by Stylemix Themes
        Search