Loading Vaultize
Skip to main content

Compliance/India/CERT-In Directions

Six directions: three leave evidence in the file.

CERT-In wants incidents reported within six hours and logs kept for 180 days. Vaultize adds records that stay with the data.

iiiiiiivvvi
iClock sync0 outcomes
Read againstCERT-In Directions under section 70B(6) of the IT Act, 2000No. 20(3)/2022-CERT-In · 28 April 2022
  • No. 20(3)/2022-CERT-In · 28 Apr 2022
  • Effective 60 days from issue
  • Capability mapping, not legal advice
3of 6 directions, plus 3 Annexure I incident types

The answer in 30 seconds

Vaultize adds file-level records to three directions: six-hour incident reporting, information to CERT-In on order, and 180-day ICT logs. Clock synchronisation, service-provider registration and virtual-asset records belong to other owners.

The Directions in one view

Six directions. Three annexures. Where file evidence lands.

The Directions apply to service providers, intermediaries, data centres, body corporate and Government organisations, with two directions for specific sectors. Select a direction to see what a governed file can evidence.

iCLOCK SYNCiiSIX-HOURREPORTINGiiiASSISTANCEiv180-DAY LOGSvREGISTRATIONviVASP RECORDS

i

Clock sync

Direction (i). Synchronise all ICT system clocks with the NTP servers of NIC or NPL, or servers traceable to them.

Outcomes the file can evidence

None on this page.

    How Vaultize contributes
    Time sources belong to the infrastructure owner. A governed file adds no evidence here.
    Evidence to retain
    None from Vaultize.

    Direction by direction

    What each direction asks. What the file can answer.

    Direction and Annexure wording is quoted from the CERT-In Directions of 28 April 2022; longer directions are excerpted. Each row is a capability mapping, not legal advice.

    Using this page

    Where these rows fit under the Directions.

    The Directions took effect 60 days after issue. The rows above are evidence for the directions that touch documents.

    1. 1

      Confirm coverage

      Service provider, intermediary, data centre, body corporate or Government organisation. Directions (v) and (vi) apply to named sectors.

    2. 2

      Designate the Point of Contact

      Direction (iii) and Annexure II. Keep it updated with CERT-In.

    3. 3

      Enable and keep the logs

      Direction (iv). 180 days, securely, within India. These rows belong here.

      Bring the rows above as evidence of the logs kept and of what the records can say within six hours.

    4. 4

      Report within six hours

      Direction (ii) and Annexure I, by email, phone or fax to CERT-In.

    5. 5

      Assist on order

      Direction (iii). Provide information in the format and timeframe specified.

    Responsibility boundary

    Records support the report. They do not make it.

    Vaultize contributes file-level records for documents. It does not decide whether an event is a reportable incident, make the report, synchronise clocks, or keep every ICT system’s logs. Read the Directions, CERT-In’s FAQs and the IT Act, and take qualified advice before relying on this page.

    “This direction will become effective after 60 days from the date on which it is issued.”

    CERT-In Directions, 28 April 2022

    A practical next step

    Bring one document you would have to report on.

    We will show what the governed document’s records can say within six hours today. We will name the owner responsible for the rest.

    Request a compliance mapping session