CERT-In Cyber Security Directions · vDirections dated 28 April 2…

CERT-In Cyber Security Directions

CERT-In Cyber Security Directions — 100% of in-scope requirements covered.

5 requirements · 2 in scope (2 enforced) · 3 out-of-scope (outside KYE’s authority layer). The 100% is weighted over the in-scope base.

Source: Indian Computer Emergency Response Team (CERT-In), Directions under sub-section (6) of section 70B of the Information Technology Act, 2000, dated 28 April 2022

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
CERT-In Cyber Security Directions 5 2 0 0 0 100%

Every requirement → the KYE artefact that enforces it

IDTitleStatusKYE enforcement
cert-in-directions-2022.SIX-HOUR-CLOCK Specified cyber incidents reported to CERT-In within six hours of noticing enforced audit_events: kye.resilience.availability_gap.v1, kye.evidence.pack.v1, kye.replay.context_seal.v1, kye.compliance.attestation.v1
constitution_refs: constitution/13-RESILIENCE-LOOP.md
cert-in-directions-2022.LOG-RETENTION ICT system logs maintained securely for a rolling 180-day period within Indian jurisdiction enforced audit_events: kye.evidence.pack.v1, kye.replay.context_seal.v1, kye.compliance.attestation.v1
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md, constitution/35-STREAMING-LOGS.md
cert-in-directions-2022.TIME-SYNC System clocks synchronised to NPL or NIC network time out-of-scope constitution_refs: constitution/13-RESILIENCE-LOOP.md
cert-in-directions-2022.INCIDENT-DETECTION Detection and triage of reportable cyber incidents across the estate out-of-scope constitution_refs: constitution/13-RESILIENCE-LOOP.md
cert-in-directions-2022.REGULATORY-FILING Submission of the incident report to CERT-In in the prescribed format out-of-scope constitution_refs: constitution/13-RESILIENCE-LOOP.md