munotes®

The CERT-In Directions of 2022

Chapter Seventy-Seven

Syllabus topic 3.3, "Cyber Security"

Pages 475 to 481 of 948

In one line

Six directions issued on 28 April 2022 under section 70B(6), effective 27 June 2022, which fixed a six-hour reporting window, required 180 days of logs to be kept inside India, and imposed five-year customer records on the providers whose business model is not keeping them.

The instrument

No. 20(3)/2022-CERT-In, dated 28 April 2022, headed "Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe and Trusted Internet".

Three things to notice about its form before its content.

It is a direction, not a rule. No draft was published, no consultation was held, and it was not laid before Parliament. Section 70B(6) requires none of that. Chapter 1420 makes the general point about delegated legislation and its controls; this instrument shows what the absence of controls looks like.

Its recitals borrow the language of section 69. The operative recital says it is expedient "in the interest of the sovereignty or integrity of India, defence of India, security of the state, friendly relations with foreign states or public order or for preventing incitement to the commission of any cognizable offence using computer resource or for handling of any cyber incident". The last limb is the one section 70B actually supports; the rest is borrowed from the interception power, and critics say it is there to make the direction look better grounded than it is.

And it took effect after sixty days, so from 27 June 2022.

Direction (i): synchronised clocks

Every service provider, intermediary, data centre, body corporate and Government organisation shall connect to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or to servers traceable to them, for the synchronisation of all their systems clocks. An entity spanning multiple geographies may use another accurate standard source, provided it does not deviate from those two.

Why it is there. A log is evidence only if its timestamps can be correlated with another party's logs. Chapter 1270 on the certificate for electronic evidence makes the same point about admissibility. This is the least controversial of the six.

Direction (ii): the six-hour window

Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report the cyber incidents in Annexure I to CERT-In within 6 hours of noticing them or of being brought to notice of them, by email, telephone or fax.

Annexure I has twenty categories, the ten from the 2013 Annexure plus data breach; data leak; attacks on internet of things devices; attacks affecting digital payment systems; attacks through malicious mobile applications; fake mobile applications; unauthorised access to social media accounts; attacks affecting cloud systems; attacks affecting systems related to big data, blockchain, virtual assets, virtual asset exchanges, custodian wallets, robotics, 3D and 4D printing, additive manufacturing and drones; and attacks affecting systems related to artificial intelligence and machine learning.

munotes.in475

The rest of this chapter

Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.

You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.

Notes + Solved papers: ₹798 Already bought it? Sign in

Or notes only: ₹499
Or solved papers only: ₹499

Free either way: question papers, the syllabus, and module one of every subject.

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!