(iii)When required by order/direction of CERT-In, for the purposes of cyber
incident response, protective and preventive actions related to cyber
incidents, the service provider/intermediary/data centre/body corporate is
mandated to take action or provide information or any such assistance to
CERT-In, which may contribute towards cyber security mitigation actions
and enhanced cyber security situational awareness. The order / direction
may include the format of the information that is required (up to and
including near real-time), and a specified timeframe in which it is required,
which should be adhered to and compliance provided to CERT-In, else it
would be treated as non-compliance of this direction. The service
providers, intermediaries, data centres, body corporate and Government
organisations shall designate a Point of Contact to interface with CERT-In.
The Information relating to a Point of Contact shall be sent to CERT-In in
the format specified at Annexure II and shall be updated from time to time.
All communications from CERT-In seeking information and providing
directions for compliance shall be sent to the said Point of Contact.
(iv) All service providers, intermediaries, data centres, body corporate and
Government organisations shall mandatorily enable logs of all their ICT
systems and maintain them securely for a rolling period of 180 days and
the same shall be maintained within the Indian jurisdiction. These should
be provided to CERT-In along with reporting of any incident or when
ordered / directed by CERT-In.
(v) Data Centres, Virtual Private Server (VPS) providers, Cloud Service
providers and Virtual Private Network Service (VPN Service) providers,
shall be required to register the following accurate information
which must be maintained by them for a period of 5 years or longer
duration as mandated by the law after any cancellation or withdrawal of
the registration as the case may be:
a.
b.
c.
d.
Validated names of subscribers/customers hiring the services
Period of hire including dates
IPs allotted to / being used by the members
Email address and IP address and time stamp used at the time of
registration / on-boarding
e. Purpose for hiring services
f. Validated address and contact numbers
g. Ownership pattern of the subscribers / customers hiring services
Page 3 of 8