Consider the following statements with reference to the latest guidelines issued by the Indian Computer Emergency Response Team (CERT-In): 1. Data centres and service providers shall compulsorily report cyber security breaches within 24 hours. 2. Virtual Private Network providers shall retain user data for at least five years and share records with authorities when required. Which of the statements given above is/are correct?
- (a)1 only
- (b)2 only
- (c)Both 1 and 2
- (d)Neither 1 nor 2
Correct — B, 2 only. The CERT-In directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000, set the reporting deadline at six hours, not twenty-four: a service provider, intermediary, data centre, body corporate or government organisation 'shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents'. Statement 2 is right — data centres, virtual private server providers, cloud service providers and VPN service providers must register the specified subscriber information and maintain it 'for a period of 5 years or longer duration as mandated by the law' after a registration is cancelled or withdrawn.
- (a)1 only — Statement 1 is the false one. Twenty-four hours was widely reported at the time and is the figure candidates remember, but the direction says six.
- (c)Both 1 and 2 — Cannot be, because the reporting window in statement 1 is wrong by eighteen hours.
- (d)Neither 1 nor 2 — Statement 2 reproduces the five-year retention requirement accurately, so rejecting both is wrong.
CERT-In is the national nodal agency for cyber-security incidents, appointed under section 70B of the IT Act, 2000. The 2022 directions tightened three things at once: the speed of reporting, the retention of records, and the traceability of users behind anonymising services. They also required every entity to synchronise its system clocks to the NIC or NPL time servers, so that logs from different organisations can be compared during an investigation.
The VPN clause is what made the directions contentious. Several international providers withdrew their Indian servers rather than keep subscriber records, arguing that a no-logs service cannot comply. Reading the direction closely repays the effort: it also requires ICT system logs to be kept for a rolling 180 days within Indian jurisdiction, and virtual-asset and exchange providers to keep KYC and transaction records for five years.
- Directions No. 20(3)/2022-CERT-In, dated 28 April 2022, issued under section 70B(6) of the IT Act, 2000.
- Cyber incidents in Annexure I must be reported within 6 hours of being noticed.
- ICT system logs must be maintained for a rolling period of 180 days within Indian jurisdiction.
- Data centres, VPS, cloud and VPN providers must keep the registered subscriber information for 5 years after cancellation or withdrawal of registration.
Statement 1 fails on the first row; statement 2 matches the third.
- Reaching for twenty-four hours; the direction says six.
- Assuming the five-year rule covers everyone — it applies to data centre, VPS, cloud and VPN providers and, separately, to virtual-asset providers.
As two statements with one deadline altered, which is the standard way a current-affairs regulation is tested.
In India, it is legally mandatory for which of the following to report on cyber security incidents? 1. Service providers 2. Data centres 3. Body corporate Select the correct answer using the code given below:
- (a) 1 only
- (b) 1 and 2 only
- (c) 3 only
- (d) 1, 2 and 3
Answer(d) 1, 2 and 3
The obligation before it was tightened. That item establishes who must report a cyber-security incident — service providers, data centres and body corporate alike — and the 2022 directions add the six-hour clock to exactly that set of entities.
- practice — not a real PYQ
Under the CERT-In directions of April 2022, ICT system logs must be maintained for a rolling period of
- (a)30 days
- (b)90 days
- (c)180 days
- (d)365 days
Answer(c) 180 days — and within Indian jurisdiction, so they can be produced to CERT-In on demand.
- practice — not a real PYQ
CERT-In is the national nodal agency for cyber-security incidents under which law?
- (a)The Indian Telegraph Act, 1885
- (b)The Information Technology Act, 2000
- (c)The Indian Penal Code
- (d)The Disaster Management Act, 2005
Answer(b) The Information Technology Act, 2000 — section 70B appoints and empowers it.