🚂 RailGuruji
Information security and cyber lawसूचना सुरक्षा और साइबर कानून5 / 6

CERT-In, NCIIPC and the MHAसर्ट-इन, एनसीआईआईपीसी और गृह मंत्रालय

Updated अद्यतन 07 Oct 2026
This chapterयह अध्याय asked in 2 exams2 परीक्षाओं में पूछा गया
1
CERT-IN AND ITS FUNCTIONSसर्ट-इन और उसके कार्य
CERT-In has worked since January 2004, and was appointed under section 70B by notification of 27 October 2009. It sits under MeitY.
  • It collects, analyses and disseminates information on cyber incidents
  • It forecasts and alerts on cyber security incidents
  • It takes emergency measures, and coordinates the response to incidents
  • It issues guidelines, advisories, vulnerability notes and white papers
  • It empanels IT security auditors; audit data must be stored only on systems in India
You report an incident to incident@cert-in.org.in or on 1800-11-4949. So CERT-In is India's national agency for cyber incident response.
सर्ट-इन जनवरी 2004 से कार्यरत है, और 27 अक्टूबर 2009 की अधिसूचना से धारा 70बी के अंतर्गत नियुक्त हुआ। यह इलेक्ट्रॉनिकी और सूचना प्रौद्योगिकी मंत्रालय के अधीन है।
  • यह साइबर घटनाओं की जानकारी एकत्र, विश्लेषित और प्रसारित करता है
  • यह साइबर सुरक्षा घटनाओं का पूर्वानुमान और चेतावनी देता है
  • यह आपातकालीन उपाय करता है, और घटनाओं की प्रतिक्रिया का समन्वय करता है
  • यह दिशानिर्देश, परामर्श, भेद्यता नोट और श्वेत पत्र जारी करता है
  • यह आईटी सुरक्षा लेखा परीक्षकों को सूचीबद्ध करता है; लेखा परीक्षा डेटा केवल भारत में स्थित प्रणालियों पर रखा जाना चाहिए
आप घटना की सूचना incident@cert-in.org.in पर या 1800-11-4949 पर देते हैं। अर्थात् सर्ट-इन साइबर घटना प्रतिक्रिया की भारत की राष्ट्रीय एजेंसी है।
2
THE CERT-IN DIRECTIONS OF 28 APRIL 202228 अप्रैल 2022 के सर्ट-इन निर्देश
CERT-In issued these under section 70B(6), effective 60 days after issue.
  • Synchronise all system clocks with the NTP server of NIC or NPL
  • Report the listed cyber incidents to CERT-In within 6 HOURS of noticing them
  • Name a POINT OF CONTACT to deal with CERT-In
  • Keep the logs of all ICT systems for a rolling 180 DAYS, within India
  • Data centres, VPS, cloud and VPN providers keep validated subscriber details for 5 YEARS
  • Virtual asset providers keep KYC and transaction records for 5 years
For MSMEs, the directions took effect on 25 September 2022. So you report in 6 hours, and you keep logs for 180 days.
सर्ट-इन ने ये धारा 70बी(6) के अंतर्गत जारी किए, जारी होने के 60 दिन बाद से प्रभावी।
  • सभी प्रणालियों की घड़ियाँ एनआईसी या एनपीएल के एनटीपी सर्वर से मिलाएँ
  • सूचीबद्ध साइबर घटनाओं की सूचना ध्यान में आने के 6 घंटे के भीतर सर्ट-इन को दें
  • सर्ट-इन से संपर्क के लिए एक संपर्क बिंदु नामित करें
  • सभी आईसीटी प्रणालियों के लॉग 180 दिनों की चलती अवधि तक, भारत के भीतर रखें
  • डेटा केंद्र, वीपीएस, क्लाउड और वीपीएन प्रदाता सत्यापित ग्राहक विवरण 5 वर्ष तक रखें
  • वर्चुअल एसेट प्रदाता केवाईसी और लेनदेन अभिलेख 5 वर्ष तक रखें
एमएसएमई के लिए ये निर्देश 25 सितंबर 2022 से प्रभावी हुए। अर्थात् सूचना आप 6 घंटे में देते हैं, और लॉग 180 दिन तक रखते हैं।
3
THE INCIDENTS YOU MUST REPORTजिन घटनाओं की सूचना आपको देनी है
Annexure I of the 2022 directions lists twenty kinds of incident that you must report to CERT-In.
  • Targeted scanning of critical networks; compromise of critical systems; unauthorised access
  • Website defacement; malicious code such as viruses, worms, Trojans, bots, ransomware and cryptominers
  • Attacks on servers and routers; identity theft, spoofing and phishing; DoS and DDoS
  • Attacks on critical infrastructure, SCADA, wireless networks, e-governance and e-commerce
  • Data breaches and leaks; attacks on IoT, digital payments, cloud, AI and blockchain systems
  • Malicious or fake mobile apps, and unauthorised access to social media accounts
So a data leak and a hacked social media account must both be reported.
2022 के निर्देशों का अनुलग्नक I बीस प्रकार की घटनाएँ गिनाता है जिनकी सूचना आपको सर्ट-इन को देनी है।
  • महत्वपूर्ण नेटवर्कों की लक्षित स्कैनिंग; महत्वपूर्ण प्रणालियों से समझौता; अनधिकृत पहुँच
  • वेबसाइट विरूपण; वायरस, वर्म, ट्रोजन, बॉट, रैनसमवेयर और क्रिप्टोमाइनर जैसे दुर्भावनापूर्ण कोड
  • सर्वरों और राउटरों पर हमले; पहचान की चोरी, स्पूफिंग और फिशिंग; डीओएस और डीडीओएस
  • महत्वपूर्ण अवसंरचना, स्काडा, वायरलेस नेटवर्क, ई-गवर्नेंस और ई-कॉमर्स पर हमले
  • डेटा उल्लंघन और रिसाव; आईओटी, डिजिटल भुगतान, क्लाउड, एआई और ब्लॉकचेन प्रणालियों पर हमले
  • दुर्भावनापूर्ण या नकली मोबाइल ऐप, और सोशल मीडिया खातों तक अनधिकृत पहुँच
अर्थात् डेटा रिसाव और हैक हुआ सोशल मीडिया खाता, दोनों की सूचना देनी है।
4
NCIIPCएनसीआईआईपीसी
NCIIPC was created under section 70A by a gazette notification of 16 January 2014. It is a unit of the NTRO, under the Prime Minister's Office.
  • It is the national nodal agency for protecting CRITICAL INFORMATION INFRASTRUCTURE
  • Its critical sectors: power and energy; banking, financial services and insurance; telecom; transport; government; strategic and public enterprises
  • It identifies critical infrastructure, and advises how to reduce its vulnerabilities
  • The basic responsibility for protecting a system still lies with the agency that runs it
  • Its 24x7 help desk number is 1800-11-4430
So you think of NCIIPC for critical infrastructure, and CERT-In for everything else.
एनसीआईआईपीसी धारा 70ए के अंतर्गत 16 जनवरी 2014 की राजपत्र अधिसूचना से बना। यह प्रधानमंत्री कार्यालय के अधीन एनटीआरओ की एक इकाई है।
  • यह महत्वपूर्ण सूचना अवसंरचना की रक्षा के लिए राष्ट्रीय नोडल एजेंसी है
  • इसके महत्वपूर्ण क्षेत्र: ऊर्जा; बैंकिंग, वित्तीय सेवाएँ और बीमा; दूरसंचार; परिवहन; सरकार; सामरिक और सार्वजनिक उद्यम
  • यह महत्वपूर्ण अवसंरचना की पहचान करता है, और उसकी भेद्यताएँ घटाने की सलाह देता है
  • किसी प्रणाली की रक्षा का मूल दायित्व फिर भी उसे चलाने वाली एजेंसी का है
  • इसका 24x7 हेल्प डेस्क नंबर 1800-11-4430 है
अर्थात् महत्वपूर्ण अवसंरचना के लिए आप एनसीआईआईपीसी, और शेष सब के लिए सर्ट-इन सोचते हैं।
5
THE MHA GUIDELINES AND THE NISPGगृह मंत्रालय के दिशानिर्देश और एनआईएसपीजी
The MHA's CYBER AND INFORMATION SECURITY DIVISION deals with cyber security, cyber crime and the NISPG.
  • The NISPG, NATIONAL INFORMATION SECURITY POLICY AND GUIDELINES, set the security controls for government organisations
  • The division also handles NATGRID, the integrated intelligence database for counter-terrorism
  • Its monitoring unit handles lawful interception, and blocking websites with MeitY
  • I4C, the INDIAN CYBER CRIME COORDINATION CENTRE, runs the National Cybercrime Reporting Portal
You report a cyber crime as a citizen through that portal. So the NISPG come from the MHA, and the CERT-In directions from MeitY.
गृह मंत्रालय का साइबर और सूचना सुरक्षा प्रभाग साइबर सुरक्षा, साइबर अपराध और एनआईएसपीजी से संबंधित कार्य देखता है।
  • एनआईएसपीजी, अर्थात् राष्ट्रीय सूचना सुरक्षा नीति और दिशानिर्देश, सरकारी संगठनों के लिए सुरक्षा नियंत्रण तय करते हैं
  • यह प्रभाग नैटग्रिड, अर्थात् आतंकवाद-रोधी एकीकृत खुफिया डेटाबेस, भी देखता है
  • इसकी निगरानी इकाई वैध अवरोधन, और इलेक्ट्रॉनिकी मंत्रालय के साथ वेबसाइट अवरुद्ध करने का काम देखती है
  • आई4सी, अर्थात् भारतीय साइबर अपराध समन्वय केंद्र, राष्ट्रीय साइबर अपराध रिपोर्टिंग पोर्टल चलाता है
नागरिक के रूप में आप साइबर अपराध की सूचना उसी पोर्टल से देते हैं। अर्थात् एनआईएसपीजी गृह मंत्रालय से आते हैं, और सर्ट-इन निर्देश इलेक्ट्रॉनिकी मंत्रालय से।
Report an error on this pageइस पेज में गलती बताएँ
Read it — now test yourself. पढ़ लिया — अब खुद को परखें। Take the free Mock CBTफ्री Mock CBT दें