Consider the following statements with reference to the latest guideli

Consider the following statements with reference to the latest guidelines issued by the Indian Computer Emergency Response Team (CERT-In):

  • Data centres and service providers shall compulsorily report cyber security breaches within 24 hours.
  • Virtual Private Network providers shall retain user data for at least five years and share records with authorities when required.

Which of the statements given above is/are correct?

1 only
2 only
Both 1 and 2
Neither 1 nor 2
This question was previously asked in
UPSC CAPF – 2022
The latest guidelines issued by the Indian Computer Emergency Response Team (CERT-In) in April 2022 mandate specific requirements for entities like data centers, cloud service providers, Virtual Private Network (VPN) providers, etc.
Statement 1 says data centres and service providers shall report cyber security breaches within 24 hours. The CERT-In direction requires reporting of cyber security incidents within 6 hours of noticing the incident or being informed about it. Thus, statement 1 is incorrect.
Statement 2 says Virtual Private Network providers shall retain user data for at least five years and share records with authorities when required. The guidelines require VPN providers and other entities to retain certain user data for a period of five years and provide it to CERT-In when mandated. Thus, statement 2 is correct.
The CERT-In directions aim to improve India’s cyber security posture by enhancing incident reporting mechanisms and enabling better tracing of malicious activities.
The types of data to be retained by VPN providers include validated name, address, email, and phone number of the subscriber, along with the IP address and email address used for registration, timestamp of registration, and the IP address and timestamp used for connecting to the service.
Exit mobile version