Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security

Under the CERT-In Directions issued in April 2022 under the Information Technology Act, 2000, within what time must a service provider, intermediary, data centre or body corporate report specified cyber incidents to CERT-In after noticing them?

The CERT-In Directions of April 2022 require reporting of specified cyber incidents within 6 hours of noticing them or being informed. Longer windows such as 72 hours belong to other regimes like the GDPR, not to these Indian directions.

  1. AWithin 6 hoursCorrect
  2. BWithin 24 hours
  3. CWithin 72 hours
  4. DWithin 7 days

Explanation

The 2022 CERT-In Directions require covered entities to report specified cyber incidents within 6 hours of noticing them or being brought to notice. The 72-hour period is associated with breach notification under other regimes such as the GDPR, so it is the tempting but wrong choice here.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.

More Cyber Security questions