- 1. The Mandatory 6-Hour Incident Notification Rule
- The 20 Mandatory Reportable Incident Categories:
- 2. Mandatory NTP Clock Synchronization Architecture
- Production Chrony Configuration (/etc/chrony/chrony.conf):
- 3. The 180-Day Secure Log Retention Pipeline
- 4. Production CERT-In Reporting Incident Template
- 5. Engaging Cyberfact Security for Incident Response & VAPT Audits
The Indian Computer Emergency Response Team (CERT-In), operating under the Ministry of Electronics and Information Technology (MeitY), issued cyber security directions under sub-section (6) of section 70B of the Information Technology Act, 2000. These directives impose non-negotiable statutory obligations on all service providers, intermediaries, data centers, body corporates, and digital business entities operating within the Indian sovereign cyber territory.
Chief Technology Officers (CTOs) and Chief Information Security Officers (CISOs) who fail to establish continuous compliance run direct legal risk, including statutory penalties and imprisonment under Section 70B(7) of the IT Act.
This playbook provides the definitive engineering architecture, logging pipelines, and operational runbooks required to maintain 100% compliance with CERT-In directives.
1. The Mandatory 6-Hour Incident Notification Rule
Under Annexure I of the CERT-In Directions, any covered entity must report specified cybersecurity incidents to CERT-In within six (6) hours of noticing or being brought to notice of such events.
[ Security Event Occurs ]
β
βΌ
[ Detection & Triage ] ββββββββββ (SIEM / SOC Alert Triggered)
β
βΌ (Clock Starts: < 6 Hours Window)
[ Initial Severity Assessment ] β (Incident Commander Mobilized)
β
βΌ
[ CERT-In Incident Dispatch ] ββ (Email to incident@cert-in.org.in or Portal)
β
βΌ
[ Containment & Remediation ] ββ (Network isolation, forensic memory capture)
β
βΌ
[ Final Root Cause Analysis (RCA) ] ββ (Submitted within statutory review cycle)
The 20 Mandatory Reportable Incident Categories:
- Targeted scanning/probing of critical networks and systems.
- Compromise of critical systems or information assets.
- Unauthorized access of IT systems, databases, or cloud accounts.
- Defacement of website or intrusion into network perimeter.
- Malicious code attacks (ransomware, worms, spyware, trojans).
- Attack on servers such as Database, Mail and DNS and network devices such as Routers.
- Identity theft, spoofing and phishing attacks.
- Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks.
- Attacks on Critical Information Infrastructure (CII), SCADA and operational technology systems.
- Data breaches, data leaks, and unintended exposure of customer records.
2. Mandatory NTP Clock Synchronization Architecture
CERT-In mandates that all ICT systemsβincluding physical bare-metal hosts, virtual hypervisors, cloud containers, network switches, firewalls, and database clustersβmust synchronize their system clocks strictly to designated time servers:
- National Informatics Centre (NIC) NTP Servers:
samay1.nic.in,samay2.nic.in - National Physical Laboratory (NPL) NTP Servers:
time.nplindia.org
Production Chrony Configuration (/etc/chrony/chrony.conf):
# CERT-In Compliant NTP Configuration
server samay1.nic.in iburst minpoll 4 maxpoll 6
server samay2.nic.in iburst minpoll 4 maxpoll 6
server time.nplindia.org iburst minpoll 4 maxpoll 6
# Reject unverified time sources
maxdistance 1.0
driftfile /var/lib/chrony/drift
makestep 1.0 3
rtcsync
logchange 0.5
Verifying active synchronization on production Linux nodes:
# Verify upstream synchronization status
chronyc sources -v
chronyc tracking
3. The 180-Day Secure Log Retention Pipeline
Organizations must maintain complete, immutable, tamper-evident logs of all ICT systems for a rolling window of not less than 180 days within Indian jurisdiction.
| Log Stream | Mandatory Fields | Storage Tier & Retention |
|---|---|---|
| Edge & WAF Logs | Source IP, User-Agent, Request URI, HTTP Status, TLS Cipher | S3 Glacier (Mumbai / Hyderabad), 180 Days |
| Authentication Logs | User ID, Source IP, Timestamp (UTC+05:30), Auth Result (Success/Fail) | OpenSearch / Elastic, Hot 30d, Cold 150d |
| Database Audit Logs | Query execution, schema mutations, admin connections | Append-only encrypted bucket, 180 Days |
| Operating System Syslog | Sudo escalations, SSH sessions, kernel security alerts | Rsyslog forwarding to central SIEM cluster |
[ Microservices / EC2 / Cloud ]
β
βΌ
[ FluentBit / Vector Agent ] ββββ (Local cryptographic hashing)
β
βΌ
[ Apache Kafka Ingestion Stream ]
β
βΌ
[ Immutable S3 Bucket (ap-south-1) ] ββ (WORM Object Lock, 180-day retention)
4. Production CERT-In Reporting Incident Template
When dispatching the initial notification to incident@cert-in.org.in, the reporting email must adhere to standardized structured data formatting:
To: incident@cert-in.org.in
Subject: STATUTORY INCIDENT REPORT: [Entity Name] - [Incident Classification] - [Date]
1. Contact Details of Organization:
- Organization Name: [Legal Entity Name]
- Designated Incident Officer: [Name, Designation, Phone, Email]
- Physical Location / Registered Office: [City, State, India]
2. Incident Chronology:
- Time of Detection: YYYY-MM-DD HH:MM:SS IST (UTC+05:30)
- Estimated Time of Inception: YYYY-MM-DD HH:MM:SS IST
- Time of Initial Containment: YYYY-MM-DD HH:MM:SS IST
3. Impacted Systems & Perimeter:
- Affected IP Addresses / Domains: [Public IPv4/IPv6, FQDNs]
- Asset Classification: [Production Database / Auth Microservice / Public Web]
- Nature of Exploitation: [e.g. Unauthenticated Remote Code Execution / Ransomware]
4. Summary of Observed Indicators of Compromise (IoCs):
- Malicious IP Addresses: [List IPs]
- Payload Hashes (SHA-256): [Hashes of captured artifacts]
- User Accounts Involved: [Redacted identifiers]
5. Containment Actions Executed:
- Network isolation of affected nodes completed.
- Credentials revoked and session tokens invalidated globally.
- Forensic memory dump captured for evidentiary preservation.
5. Engaging Cyberfact Security for Incident Response & VAPT Audits
Under the guidance of Saket Choudhary, Cyberfact Security delivers end-to-end CERT-In readiness audits, periodic mandated VAPT certifications, and emergency incident triage across Indian tech ecosystems.
- Emergency Incident Desk: 24/7 technical hotline for containment and regulatory notifications.
- Pre-Audit Gap Assessments: Evaluating your existing logging architecture and NTP topology against CERT-In checklists.
- Empanelled VAPT Testing: Certified reports satisfying banking, fintech, and regulatory audit mandates.
Founder and Lead Security Architect at Cyberfact Security. Specializing in offensive penetration testing (VAPT), distributed cloud architectures, and hardened full-stack engineering for high-growth enterprises.
Initiate a Technical Audit or Custom Engineering Scope
Cyberfact Security delivers certified VAPT audits, source code reviews, and enterprise software engineering for institutions across India. Direct technical engagements with Founder Saket Choudhary.




