Skip to main content
Image coming soon

India CERT-In 2022 Cyber Security Directions Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
India CERT-In 2022 Cyber Security Directions · India cyber incident reporting, made adopt-ready · Evidence & Implementation Kit
Meet the CERT-In 2022 Directions, without decoding the Directions yourself.
Every requirement handed to you as an adopt-ready control, the point of contact and NTP time synchronisation through six-hour incident reporting to log retention and provider record-keeping duties, with the evidence CERT-In examines.
Ready in a weekend, not a quarter.

Here is the honest situation. The CERT-In Directions of 2022, issued under the Information Technology Act, require entities operating in India to synchronise clocks to NIC or NPL time, report specified cyber incidents to CERT-In within six hours, enable and retain ICT logs for 180 days within India, and, for data centres, cloud, VPS and VPN providers, maintain validated KYC and customer records. An entity with a generic incident process but no six-hour reporting or 180-day logging is exactly where organizations fall short.

This Kit removes the guesswork. It is the CERT-In 2022 Directions written as adopt-ready controls you personalize in a weekend, with the evidence CERT-In examines.

What you get, the moment you buy

18
Requirements as adopt-ready controls. Every requirement, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what CERT-In examines, plus where organizations fall short, so you close the gap first.
1
Control Matrix, pre-built. Every requirement in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each requirement and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the CERT-In 2022 Directions. Editable Word and Excel files.

Six hours is not a generic timeline
A standard incident process will miss the CERT-In six-hour reporting duty. This Kit builds the Directions into controls with the evidence CERT-In asks for.

What one control looks like

This is the opening control, where the program begins. All 18 are built to this depth.

CIN-1 Confirm applicability of the Directions SCOPE
Put this control in place

Determine and document how the CERT-In 2022 Directions apply to [your organization name], covering its status as a body corporate, service provider, intermediary, data centre or government entity operating in India, so scope is clear and the organization can evidence its determination.

Direction note.

The CERT-In Directions of 2022, issued under the Information Technology Act, apply broadly to service providers, intermediaries, data centres, body corporates and government organizations.

Evidence CERT-In examines
  • An applicability assessment against the Directions
  • Entity categories identified
  • Records of the determination
Common finding they raise: The applicability of the CERT-In Directions is not assessed.

Why this is not another template pack

  • The evidence is the point. A requirement you cannot evidence is a gap waiting to be found. This tells you what CERT-In examines and where organizations fall short, for every requirement.
  • The specifics built in. The direction's distinctive requirements are written into the controls, not left generic.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. This work shares its shape with related security and safety frameworks, so it feeds your wider program.

Who buys this

Service providers, intermediaries, data centres, cloud and VPN providers and body corporates operating in India, and their security and compliance teams. Whether it is a first alignment or a readiness pass, you save weeks and walk in with your six-hour reporting, logging, time synchronisation and KYC-record controls structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 requirements
✓  A completed control matrix
✓  The evidence CERT-In examines
✓  Your core controls in place
✓  A readiness percentage and a fix list
✓  The highest-risk gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Does a normal incident plan cover this? No. The Directions add a six-hour reporting duty, 180-day India-resident logging, NTP synchronisation and KYC records. This Kit covers the specifics.

Does it cover log retention? Yes. Enabling and retaining ICT logs for the mandated period within India is built as a control.

What if it is not for me? A 30-day money-back guarantee.

Do not face CERT-In with requirements you cannot show.
Every requirement is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com