CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
A Mumbai-based fintech company discovers that an attacker has gained unauthorised access to its customer database through a compromised server. The CISO wants to know the legal position on notifying CERT-In. Which statement is correct?
Reporting to CERT-In is mandatory, because data breach and unauthorised access to systems or data are specified reportable incidents and the obligation covers body corporates such as fintech firms, irrespective of complaints by customers or any monetary loss threshold.
- AReporting is needed only if customers complain to the police
- BReporting to CERT-In is mandatory for such an incident, as data breach and unauthorised access are among the specified reportable incident typesCorrect
- CReporting is voluntary because CERT-In only handles government systems
- DReporting is required only if financial loss exceeds a prescribed rupee threshold
Explanation
Data breach, data leak and unauthorised access to IT systems or data are listed among incidents reportable to CERT-In, and the obligation applies to body corporates. It does not depend on a complaint to the police, nor on a loss threshold. CERT-In's remit is not limited to government systems.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.
More Cyber Security questions
- A forensic examiner must collect evidence from a running server that is suspected to be compromised. Considering the order of volatility, wh…
- A company's risk register shows that a phishing attack on its payroll system has a high likelihood and a moderate impact. Management buys cy…
- A Mumbai-based firm's payment portal is flooded with millions of fake requests from many compromised computers, making it unavailable to gen…
- Under the CERT-In Directions issued in April 2022 under the Information Technology Act, 2000, within what time must a service provider, inte…
- During a forensic investigation, an examiner computes a hash value (such as SHA-256) of a seized disk image at acquisition and again before …
- Under the CERT-In Directions issued in April 2022 under the Information Technology Act, 2000, within what time must a service provider, inte…