1
CERT-IN AND ITS FUNCTIONSसर्ट-इन और उसके कार्य
CERT-In has worked since January 2004, and was appointed under section 70B by notification of 27 October 2009. It sits under MeitY.
- It collects, analyses and disseminates information on cyber incidents
- It forecasts and alerts on cyber security incidents
- It takes emergency measures, and coordinates the response to incidents
- It issues guidelines, advisories, vulnerability notes and white papers
- It empanels IT security auditors; audit data must be stored only on systems in India
- यह साइबर घटनाओं की जानकारी एकत्र, विश्लेषित और प्रसारित करता है
- यह साइबर सुरक्षा घटनाओं का पूर्वानुमान और चेतावनी देता है
- यह आपातकालीन उपाय करता है, और घटनाओं की प्रतिक्रिया का समन्वय करता है
- यह दिशानिर्देश, परामर्श, भेद्यता नोट और श्वेत पत्र जारी करता है
- यह आईटी सुरक्षा लेखा परीक्षकों को सूचीबद्ध करता है; लेखा परीक्षा डेटा केवल भारत में स्थित प्रणालियों पर रखा जाना चाहिए
2
THE CERT-IN DIRECTIONS OF 28 APRIL 202228 अप्रैल 2022 के सर्ट-इन निर्देश
CERT-In issued these under section 70B(6), effective 60 days after issue.
- Synchronise all system clocks with the NTP server of NIC or NPL
- Report the listed cyber incidents to CERT-In within 6 HOURS of noticing them
- Name a POINT OF CONTACT to deal with CERT-In
- Keep the logs of all ICT systems for a rolling 180 DAYS, within India
- Data centres, VPS, cloud and VPN providers keep validated subscriber details for 5 YEARS
- Virtual asset providers keep KYC and transaction records for 5 years
- सभी प्रणालियों की घड़ियाँ एनआईसी या एनपीएल के एनटीपी सर्वर से मिलाएँ
- सूचीबद्ध साइबर घटनाओं की सूचना ध्यान में आने के 6 घंटे के भीतर सर्ट-इन को दें
- सर्ट-इन से संपर्क के लिए एक संपर्क बिंदु नामित करें
- सभी आईसीटी प्रणालियों के लॉग 180 दिनों की चलती अवधि तक, भारत के भीतर रखें
- डेटा केंद्र, वीपीएस, क्लाउड और वीपीएन प्रदाता सत्यापित ग्राहक विवरण 5 वर्ष तक रखें
- वर्चुअल एसेट प्रदाता केवाईसी और लेनदेन अभिलेख 5 वर्ष तक रखें
3
THE INCIDENTS YOU MUST REPORTजिन घटनाओं की सूचना आपको देनी है
Annexure I of the 2022 directions lists twenty kinds of incident that you must report to CERT-In.
- Targeted scanning of critical networks; compromise of critical systems; unauthorised access
- Website defacement; malicious code such as viruses, worms, Trojans, bots, ransomware and cryptominers
- Attacks on servers and routers; identity theft, spoofing and phishing; DoS and DDoS
- Attacks on critical infrastructure, SCADA, wireless networks, e-governance and e-commerce
- Data breaches and leaks; attacks on IoT, digital payments, cloud, AI and blockchain systems
- Malicious or fake mobile apps, and unauthorised access to social media accounts
- महत्वपूर्ण नेटवर्कों की लक्षित स्कैनिंग; महत्वपूर्ण प्रणालियों से समझौता; अनधिकृत पहुँच
- वेबसाइट विरूपण; वायरस, वर्म, ट्रोजन, बॉट, रैनसमवेयर और क्रिप्टोमाइनर जैसे दुर्भावनापूर्ण कोड
- सर्वरों और राउटरों पर हमले; पहचान की चोरी, स्पूफिंग और फिशिंग; डीओएस और डीडीओएस
- महत्वपूर्ण अवसंरचना, स्काडा, वायरलेस नेटवर्क, ई-गवर्नेंस और ई-कॉमर्स पर हमले
- डेटा उल्लंघन और रिसाव; आईओटी, डिजिटल भुगतान, क्लाउड, एआई और ब्लॉकचेन प्रणालियों पर हमले
- दुर्भावनापूर्ण या नकली मोबाइल ऐप, और सोशल मीडिया खातों तक अनधिकृत पहुँच
4
NCIIPCएनसीआईआईपीसी
NCIIPC was created under section 70A by a gazette notification of 16 January 2014. It is a unit of the NTRO, under the Prime Minister's Office.
- It is the national nodal agency for protecting CRITICAL INFORMATION INFRASTRUCTURE
- Its critical sectors: power and energy; banking, financial services and insurance; telecom; transport; government; strategic and public enterprises
- It identifies critical infrastructure, and advises how to reduce its vulnerabilities
- The basic responsibility for protecting a system still lies with the agency that runs it
- Its 24x7 help desk number is 1800-11-4430
- यह महत्वपूर्ण सूचना अवसंरचना की रक्षा के लिए राष्ट्रीय नोडल एजेंसी है
- इसके महत्वपूर्ण क्षेत्र: ऊर्जा; बैंकिंग, वित्तीय सेवाएँ और बीमा; दूरसंचार; परिवहन; सरकार; सामरिक और सार्वजनिक उद्यम
- यह महत्वपूर्ण अवसंरचना की पहचान करता है, और उसकी भेद्यताएँ घटाने की सलाह देता है
- किसी प्रणाली की रक्षा का मूल दायित्व फिर भी उसे चलाने वाली एजेंसी का है
- इसका 24x7 हेल्प डेस्क नंबर 1800-11-4430 है
5
THE MHA GUIDELINES AND THE NISPGगृह मंत्रालय के दिशानिर्देश और एनआईएसपीजी
The MHA's CYBER AND INFORMATION SECURITY DIVISION deals with cyber security, cyber crime and the NISPG.
- The NISPG, NATIONAL INFORMATION SECURITY POLICY AND GUIDELINES, set the security controls for government organisations
- The division also handles NATGRID, the integrated intelligence database for counter-terrorism
- Its monitoring unit handles lawful interception, and blocking websites with MeitY
- I4C, the INDIAN CYBER CRIME COORDINATION CENTRE, runs the National Cybercrime Reporting Portal
- एनआईएसपीजी, अर्थात् राष्ट्रीय सूचना सुरक्षा नीति और दिशानिर्देश, सरकारी संगठनों के लिए सुरक्षा नियंत्रण तय करते हैं
- यह प्रभाग नैटग्रिड, अर्थात् आतंकवाद-रोधी एकीकृत खुफिया डेटाबेस, भी देखता है
- इसकी निगरानी इकाई वैध अवरोधन, और इलेक्ट्रॉनिकी मंत्रालय के साथ वेबसाइट अवरुद्ध करने का काम देखती है
- आई4सी, अर्थात् भारतीय साइबर अपराध समन्वय केंद्र, राष्ट्रीय साइबर अपराध रिपोर्टिंग पोर्टल चलाता है