Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security

A Mumbai-based fintech company discovers that an attacker has gained unauthorised access to its customer database through a compromised server. The CISO wants to know the legal position on notifying CERT-In. Which statement is correct?

Reporting to CERT-In is mandatory, because data breach and unauthorised access to systems or data are specified reportable incidents and the obligation covers body corporates such as fintech firms, irrespective of complaints by customers or any monetary loss threshold.

  1. AReporting is needed only if customers complain to the police
  2. BReporting to CERT-In is mandatory for such an incident, as data breach and unauthorised access are among the specified reportable incident typesCorrect
  3. CReporting is voluntary because CERT-In only handles government systems
  4. DReporting is required only if financial loss exceeds a prescribed rupee threshold

Explanation

Data breach, data leak and unauthorised access to IT systems or data are listed among incidents reportable to CERT-In, and the obligation applies to body corporates. It does not depend on a complaint to the police, nor on a loss threshold. CERT-In's remit is not limited to government systems.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.

More Cyber Security questions