Statutory Basis and Control Mapping
IT Act 2000 — s.70B(6) CERT-In Directions No. 20(3)/2022 dated 28.04.2022 IT (CERT-In) Rules 2013 — Rule 12(1)(a) IT Act 2000 — s.70B(7) (penalty) This SOP operationalises the Directions issued by CERT-In under sub-section (6) of section 70B of the Information Technology Act, 2000 (No. 20(3)/2022-CERT-In, dated 28 April 2022, effective 27 June 2022). It is not legal advice; the CERT-In Directions and any amendments prevail in the event of conflict.
ACME TECHNOLOGIES PVT LTD CERT-IN CYBER INCIDENT REPORTING — STANDARD OPERATING PROCEDURE
Effective Date [Effective Date]
Version 1.0
Entity Classification body corporate
Registered Office Unit 4, Tech Park, Bengaluru, Karnataka 560103
Designated Point of Contact Ms. Priya Nair
Statutory Reporting Window 6 hours from noticing / being notified
Reporting Channel incident@cert-in.org.in · 1800-11-4949 · Fax 1800-11-6969 1. Purpose, Scope and Applicability
This Standard Operating Procedure establishes how Acme Technologies Pvt Ltd , as a body corporate, identifies, escalates, reports and records cyber security incidents in compliance with the CERT-In Directions dated 28 April 2022 issued under s.70B(6) of the Information Technology Act, 2000. It applies to all Information and Communication Technology (ICT) systems, personnel, contractors and managed-service providers of the organisation. The Directions have extra-territorial effect and apply irrespective of where infrastructure is hosted so long as services are offered to users in India.
2. Reportable Cyber Security Incidents (Annexure I)
The following twenty (20) types of cyber security incidents set out in Annexure I of the Directions [read with Rule 12(1)(a) of the IT (CERT-In) Rules, 2013] MUST be reported to CERT-In: (i) Targeted scanning/probing of critical networks/systems; (ii) Compromise of critical systems/information; (iii) Unauthorised access of IT systems/data; (iv) Defacement of website or intrusion into a website and unauthorised changes such as inserting malicious code, links to external websites etc.; (v) Malicious code attacks such as spreading of virus/worm/Trojan/Bots/Spyware/Ransomware/Cryptominers; (vi) Attack on servers such as Database, Mail and DNS and network devices such as Routers; (vii) Identity Theft, spoofing and phishing attacks; (viii) Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks; (ix) Attacks on Critical infrastructure, SCADA and operational technology systems and Wireless networks; (x) Attacks on Application such as E-Governance, E-Commerce etc.; (xi) Data Breach; (xii) Data Leak; (xiii) Attacks on Internet of Things (IoT) devices and associated systems, networks, software, servers; (xiv) Attacks or incident affecting Digital Payment systems; (xv) Attacks through Malicious mobile Apps; (xvi) Fake mobile Apps; (xvii) Unauthorised access to social media accounts; (xviii) Attacks or malicious/suspicious activities affecting Cloud computing systems/servers/software/applications; (xix) Attacks or malicious/suspicious activities affecting systems/servers/networks/software/applications related to Big Data, Blockchain, virtual assets, virtual asset exchanges, custodian wallets, Robotics, 3D and 4D Printing, additive manufacturing, Drones; and (xx) Attacks or malicious/suspicious activities affecting systems/servers/software/applications related to Artificial Intelligence and Machine Learning. Where there is doubt whether an event falls within Annexure I, the default position is to report.
3. Mandatory 6-Hour Reporting Timeline
Acme Technologies Pvt Ltd shall mandatorily report any cyber incident mentioned in Annexure I to CERT-In within SIX (6) HOURS of noticing such incident or of it being brought to notice. The six-hour clock starts at the point of awareness, not at the point of root-cause confirmation; an initial report shall be filed on the basis of information then available and supplemented as investigation progresses. The Designated Point of Contact is responsible for ensuring the report is despatched within the window on a 24x7 basis.
4. Reporting Channels and Template Fields
Incidents shall be reported to CERT-In via email at incident@cert-in.org.in, by telephone on the toll-free helpline 1800-11-4949, or by fax on 1800-11-6969, using the methods and formats published at www.cert-in.org.in (as updated from time to time). Each incident report shall, at minimum, capture: (a) reporting entity name and Point of Contact details; (b) date and time the incident was noticed; (c) Annexure I incident type(s); (d) affected systems, IP addresses, domains and their location; (e) a description of the incident and observed impact; (f) indicators of compromise and, where available, malware samples/hashes; (g) actions taken and mitigation status; and (h) relevant logs. Where full details are not yet known, the report shall be filed with available particulars within 6 hours and updated thereafter.
5. Designated Point of Contact (Annexure II)
Acme Technologies Pvt Ltd designates Ms. Priya Nair (Chief Information Security Officer ) as the Point of Contact to interface with CERT-In. The Point-of-Contact particulars — name, designation, office address, email, mobile and phone — shall be furnished to CERT-In in the format specified at Annexure II of the Directions and kept updated at all times. All communications from CERT-In seeking information or providing directions for compliance shall be routed to, and actioned by, this Point of Contact. Contactable email: ciso@acme.in ; mobile: +91 98xxxxxx00 .
6. Log Enablement and 180-Day Retention within Indian Jurisdiction
Acme Technologies Pvt Ltd shall mandatorily enable logs of all its ICT systems and maintain them securely for a rolling period of ONE HUNDRED AND EIGHTY (180) DAYS, and such logs shall be maintained WITHIN THE INDIAN JURISDICTION. Logs are retained at In-house SIEM, Mumbai region (ap-south-1) . These logs shall be provided to CERT-In along with the reporting of any incident, or as and when ordered/directed by CERT-In. Log integrity shall be protected against tampering, and access shall be restricted and itself logged.
7. ICT Clock Synchronisation to NIC / NPL NTP
Acme Technologies Pvt Ltd shall connect all its ICT system clocks to the NTP server of the National Informatics Centre (NIC), or to an NTP server traceable to these servers, for time synchronisation. Where ICT infrastructure spans multiple geographies, an accurate and standard time source other than NPL/NIC may be used, provided that source does not deviate from NPL and NIC. Accurate, synchronised timestamps are a precondition for the reliability of the 180-day logs and of every incident report filed under this SOP.
8. KYC and Records for Data Centre / VPS / Cloud / VPN Services
If Acme Technologies Pvt Ltd operates as a Data Centre, Virtual Private Server (VPS) provider, Cloud Service provider or Virtual Private Network (VPN) Service provider, it shall register and accurately maintain, for a period of FIVE (5) YEARS (or longer as mandated by law) after any cancellation or withdrawal of registration: (a) validated names of subscribers/customers hiring the services; (b) period of hire including dates; (c) IPs allotted to / being used by the members; (d) email address, IP address and time stamp used at the time of registration / on-boarding; (e) purpose for hiring services; (f) validated address and contact numbers; and (g) ownership pattern of the subscribers/customers hiring services.
9. KYC and Transaction Records for Virtual Asset Providers
If Acme Technologies Pvt Ltd is a virtual asset service provider, virtual asset exchange provider or custodian wallet provider (as defined by the Ministry of Finance from time to time), it shall mandatorily maintain all information obtained as part of Know Your Customer (KYC) and records of financial transactions for a period of FIVE (5) YEARS. KYC shall follow the RBI Directions 2016 / SEBI circular dated 24 April 2020 / DoT notice dated 21 September 2021 as applicable and amended. Transaction records shall be maintained so that each individual transaction can be reconstructed, including the identification of relevant parties, IP addresses with timestamps and time zones, transaction ID, public keys (or equivalent identifiers), addresses/accounts involved, and the nature, date and amount of the transaction.
10. Incident Response Workflow
On detection of a suspected event: (1) DETECT — any employee or system alert routes the event to the Security Operations team; (2) TRIAGE — the team classifies it against Annexure I and records the awareness timestamp, which starts the 6-hour clock; (3) CONTAIN — immediate containment and evidence-preservation measures are taken without destroying logs; (4) REPORT — the Point of Contact files the CERT-In report within 6 hours per Clauses 3-4; (5) COOPERATE — the organisation provides information, logs and assistance to CERT-In within any timeframe specified in a CERT-In order/direction (up to and including near real-time); (6) REMEDIATE & CLOSE — remediation is completed, a follow-up/closure report is sent to CERT-In, and lessons learned are recorded. Every step is timestamped using the synchronised clock of Clause 7.
11. Duty to Assist and Comply with CERT-In Orders
When required by order/direction of CERT-In for cyber incident response or protective/preventive action, Acme Technologies Pvt Ltd shall take action, provide information or render such assistance as directed, in the format specified (up to and including near real-time) and within the specified timeframe. Failure to adhere within the specified timeframe shall itself be treated as non-compliance with the Directions.
12. Penalties for Non-Compliance
Failure to furnish information called for by CERT-In, or non-compliance with the Directions, may invite punitive action under sub-section (7) of section 70B of the IT Act, 2000, and other laws as applicable. Under s.70B(7), any service provider, intermediary, data centre, body corporate or person who fails to comply with a direction of CERT-In may be punished with imprisonment for a term which may extend to one (1) year, or with a fine which may extend to one lakh rupees (Rs. 1,00,000), or with both.
13. Ownership, Review and Records
This SOP is owned by the Designated Point of Contact and approved by Rohan Mehta , Managing Director. It takes effect on [Effective Date] (version 1.0) and shall be reviewed at least annually and upon any amendment to the CERT-In Directions. Incident reports, acknowledgements, logs and correspondence with CERT-In shall be retained in accordance with Clauses 6, 8 and 9.
Approved by
Rohan Mehta
______________________
Point of Contact (CERT-In)
Ms. Priya Nair
______________________