Compliance & Governance

What is CERT-In Cyber Security Directions (CERT-In)?

CERT-In Cyber Security Directions: Binding cybersecurity directives issued by the Indian Computer Emergency Response Team (CERT-In) mandating strict logging and 6-hour breach reporting.

Detailed Explanation

Issued under Section 70B of the IT Act, CERT-In’s cybersecurity directions require all service providers, intermediaries, data centers, and corporate entities in India to report cybersecurity incidents within 6 hours of discovery, synchronize system clocks with NTP servers, and maintain immutable system logs within Indian jurisdiction for a minimum of 180 days.

Why CERT-In Matters for Enterprise Security

  • Strict 6-hour incident disclosure mandate requires rapid, battle-tested DFIR capabilities.
  • Mandatory 180-day log retention demands secure, tamper-proof logging architectures.
  • Non-compliance can result in statutory sanctions and operational suspension.

Core Components & Architecture

6-Hour Incident Notification

Fast-track triage and technical notification to CERT-In upon cyber incident confirmation.

180-Day Secure Log Archival

Maintaining tamper-evident system and access logs within Indian jurisdiction.

NTP Time Synchronization

Synchronizing all infrastructure clocks to official Indian standard time servers.

The VayuX Systems Approach

VayuX DFIR and Managed SOC services are pre-configured to satisfy CERT-In reporting and retention protocols automatically, ensuring instant 6-hour readiness during security crises.