iTnews Asia
  • Home
  • News
  • Security

India mandates data breach notification within six hours

India mandates data breach notification within six hours

Also requires VPN customer registration.

By Richard Chirgwin on May 4, 2022 6:28AM

Companies that experience cyber security breaches in India will have just six hours to notify authorities under sweeping new regulations declared by the country’s Computer Emergency Response Team, CERT-In.

The regulation [pdf] applies to “service providers, intermediaries, data centres, body corporate and government organisations” and will come into force 60 days from April 28.

These bodies will have to make their reports to CERT-In “within six hours of noticing such
incidents or being brought to notice about such incidents”.

The regulation also requires organisations to provide assistance to CERT-In, as well as “information or any such assistance to CERT-In, which may contribute towards cyber security mitigation actions and enhanced cyber security situational awareness.”

Organisations are also instructed to appoint a single point of contact for communicating with CERT-In, and to maintain logs on all ICT systems, which must be kept in a secure form for 180 days.

The regulation also imposes wide-ranging recordkeeping on services, including data centres, virtual private server (VPS) providers, cloud service providers, and VPN services.

Data these services will have to store for five years include customer identity, when subscriptions were in force, IP addresses assigned to them, contact numbers, and other information.

The declaration also brings virtual assets under financial regulations administered by the Ministry of Finance.

To maintain system synchronisation India-wide, the declaration mandates that systems administrators connect to Network Time Protocol servers run by the National Informatics Centre or the National Physical Laboratory, “or with NTP servers traceable to these NTP servers.”

Anyone opting to use other NTP servers has to ensure that “their time source shall not deviate from NPL and NIC.”

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
breach cyber security india notification privacy security vpn

Related Articles

  • Best practice tips for secure password management
  • Are third-party blind spots the weakest link in enterprise cybersecurity chain?
  • Five tips a CIO or CSO should know to stop employee-driven IP theft
  • StarHub launches app to protect customers from scam calls and SMS
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Are third-party blind spots the weakest link in enterprise cybersecurity chain?

Are third-party blind spots the weakest link in enterprise cybersecurity chain?

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippine education ministry hit by data leak exposing 210,020 records

Philippine education ministry hit by data leak exposing 210,020 records

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.