CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
Under the CERT-In Directions issued in April 2022 under the Information Technology Act, 2000, within what time must a service provider, intermediary, data centre or body corporate report specified cyber incidents to CERT-In after noticing them?
The CERT-In Directions of April 2022 require reporting of specified cyber incidents within 6 hours of noticing them or being informed. Longer windows such as 72 hours belong to other regimes like the GDPR, not to these Indian directions.
- AWithin 6 hoursCorrect
- BWithin 24 hours
- CWithin 72 hours
- DWithin 7 days
Explanation
The 2022 CERT-In Directions require covered entities to report specified cyber incidents within 6 hours of noticing them or being brought to notice. The 72-hour period is associated with breach notification under other regimes such as the GDPR, so it is the tempting but wrong choice here.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.
More Cyber Security questions
- A bank sets its recovery time objective (RTO) for its internet banking platform at 2 hours. What does this mean?
- During an internal investigation at an Indian company, the IT team must copy the hard disk of a suspect employee's laptop for later analysis…
- Under the IT Act, 2000, which of the following is the legal function of a digital signature certificate issued by a Certifying Authority?
- A company's security team states that a former employee's login still worked three months after resignation and was used to download client …
- An attacker silently positions himself between a customer's device and a bank's server on an unsecured public Wi-Fi network, reading and pos…
- Employees of a Pune logistics firm receive an email that appears to come from the company's CEO, with a link to a page that imitates the cor…