Godwit AI Labs Talk to us

Home › Free tools › CERT-In readiness check

Could you report an incident in six hours?

CERT-In’s directions apply to almost every company in India: a six-hour report, a named contact, synchronised clocks, and 180 days of logs kept in India. Eight questions show where you stand, and what the logs would take.

Start the check
  • About three minutes
  • Your answers never leave this browser
  • No sign-up
THE CHECK

Where you stand

Yes, no or not sure. Then how many devices you have, for the log estimate.

Your devices, for the log estimate

Rough numbers are fine. Leave out anything you do not have.

QUESTIONS

Asked often

The questions people search for before they run the check.

What are CERT-In's 2022 directions?

Directions issued by CERT-In on 28 April 2022 under section 70B(6) of the IT Act, in force from 28 June 2022. They require incidents of the listed kinds to be reported within six hours, a Point of Contact to be named, system clocks to be synchronised to NIC or NPL time servers, and logs of all ICT systems to be kept for 180 days within India.

Do CERT-In's directions apply to my company?

They apply to service providers, intermediaries, data centres, body corporates and government organisations. In practice that is almost every company in India, whatever its size. Data centres, cloud, VPS and VPN providers have extra record-keeping duties.

What has to be reported to CERT-In within six hours?

The incident types in Annexure I to the directions, among them compromise of systems or data, ransomware and other malicious code, website defacement, phishing, attacks on servers and network devices, data breaches and leaks, and attacks on cloud and IoT systems.

How much storage do 180 days of logs need?

It depends on what is logged. As a rough guide, a small office with 60 computers, six servers and one firewall produces around 6 GB of logs a day, about 230 GB for 180 days once compressed. The check works it out for your own device counts, and shows the method.

Which time servers does CERT-In mean?

The NTP servers of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL), or servers traceable to them. A common set-up points one or two internal time servers at them, and every other device at the internal ones.

What is the penalty for not following CERT-In's directions?

Section 70B(7) of the IT Act: imprisonment of up to one year, a fine of up to ₹1 lakh, or both.

Rather we set it up with you?

Clocks, log collection and retention, and a six-hour reporting runbook rehearsed once, so the first real report is not the first attempt.