Indian Computer Emergency Response Team: Difference between revisions

Created by Tharun S Yadla
Last edited March 22, 2026
m Updated the article +/-
Page updated with additional details
Line 1: Line 1:
{{Short description|Indian government cybersecurity agency}}
{{Short description|Indian government cybersecurity agency}}
{{use dmy dates|date=October 2013}}
{{Prose|date=July 2024}}
{{Use dmy dates|date=July 2024}}
{{Infobox government agency
{{Infobox government agency
| agency_name    = Indian Computer Emergency Response Team (CERT-In)
| agency_name    = Indian Computer Emergency Response Team (CERT-In)
| type            =  
| type            =  
| nativename      =  
| nativename      =  
| nativename_a    =  
| nativename_a    = {{lang|hi|भारतीय कंप्यूटर आपातकालीन प्रतिक्रिया टीम}}
| nativename_r    =  
| nativename_r    =  
| logo            = CERT-In logo.png
| logo            = CERT-In 2023.png
| logo_width      =  
| logo_width      =  
| logo_caption    =  
| logo_caption    =  
Line 16: Line 17:
| picture_width  =  
| picture_width  =  
| picture_caption =  
| picture_caption =  
| formed          = {{Start date and age|2004|01|19|df=y}}<ref name="tt.in">{{cite web | url=http://searchsecurity.techtarget.in/definition/CERT-In | title=techtarget.in | access-date=21 October 2013}}</ref><ref name="fir">{{cite web | url=http://www.first.org/members/teams/cert-in | title=first.org- About CERT-In | access-date=23 October 2013}}</ref>
| formed          = {{Start date and age|2004|01|19|df=y}}&lt;ref name="tt.in"&gt;{{cite web | url=http://searchsecurity.techtarget.in/definition/CERT-In | title=techtarget.in | access-date=21 October 2013 | archive-date=21 October 2013 | archive-url=https://web.archive.org/web/20131021183527/http://searchsecurity.techtarget.in/definition/CERT-In | url-status=dead }}&lt;/ref&gt;&lt;ref name="fir"&gt;{{cite web | url=http://www.first.org/members/teams/cert-in | title=first.org- About CERT-In | access-date=23 October 2013}}&lt;/ref&gt;
| preceding1      =  
| preceding1      = [[Ministry of Electronics and Information Technology]]
| preceding2      =  
| preceding2      = &lt;!-- (etc.) --&gt;
<!-- (etc.) -->
| dissolved      =  
| dissolved      =  
| superseding    =  
| superseding    =  
| jurisdiction    =  
| jurisdiction    = [[Government of India]]
| headquarters    = [[New Delhi]], [[India]]<ref name="meity -- icert">{{cite web | url=http://meity.gov.in/content/icert | title=meity.gov.in -- CERT-In | access-date=21 October 2013}}</ref>
| headquarters    = [[New Delhi]], [[India]]&lt;ref name="meity -- icert"&gt;{{cite web | url=http://meity.gov.in/content/icert | title=meity.gov.in -- CERT-In | access-date=21 October 2013}}&lt;/ref&gt;
| coordinates    = {{coord|28|35|11|N|77|14|22|E|type:landmark_region:IN|display=inline,title}}
| coordinates    = {{coord|28|35|11|N|77|14|22|E|type:landmark_region:IN|display=inline,title}}
| motto          = Handling Cyber Security Incidents
| motto          = Handling Cyber Security Incidents
Line 31: Line 31:
| minister1_pfo  =  
| minister1_pfo  =  
| minister2_name  =  
| minister2_name  =  
| minister2_pfo  =  
| minister2_pfo  = &lt;!-- (etc.) --&gt;
<!-- (etc.) -->
| deputyminister1_name =  
| deputyminister1_name =  
| deputyminister1_pfo =  
| deputyminister1_pfo =  
| deputyminister2_name =  
| deputyminister2_name =  
| deputyminister2_pfo =  
| deputyminister2_pfo = &lt;!-- (etc.) --&gt;
<!-- (etc.) -->
| chief1_name    = [[Dr. Sanjay Bahl]]
| chief1_name    = Sanjay Bahl
| chief1_position = Director General&lt;ref&gt;{{cite web|title=Who's who|url=http://meity.gov.in/about-meity/who-is-who|work=[[Ministry of Electronics and Information Technology]] |access-date=31 May 2017}}&lt;/ref&gt;
| chief1_position = Director General<ref>{{cite web|title=Who's who|url=http://meity.gov.in/about-meity/who-is-who|work=[[Ministry of Electronics and Information Technology]] |access-date=31 May 2017}}</ref>
| chief2_name    =  
| chief2_name    =  
| chief2_position =  
| chief2_position = &lt;!-- (etc.) --&gt;
<!-- (etc.) -->
| agency_type    =  
| agency_type    =  
| parent_department = [[Ministry of Electronics and Information Technology (India)|Ministry of Electronics and Information Technology]]
| parent_department = [[Ministry of Electronics and Information Technology (India)|Ministry of Electronics and Information Technology]]
| parent_agency  =  
| parent_agency  =  
| child1_agency  =  
| child1_agency  =  
| child2_agency  =  
| child2_agency  = &lt;!-- (etc.) --&gt;
<!-- (etc.) -->
| keydocument1    = &lt;!-- (etc.) --&gt;
| keydocument1    =  
| website        = {{URL|सर्ट-इन.भारत}} ,  {{URL|www.cert-in.org.in}},  {{URL|www.सीएसके.सरकार.भारत}} , {{URL|www.csk.gov.in}}
<!-- (etc.) -->
| website        = {{url|cert-in.org.in}}
| footnotes      =  
| footnotes      =  
| map            =  
| map            =  
Line 57: Line 52:
| map_caption    =  
| map_caption    =  
}}
}}
The '''Indian Computer Emergency Response Team''' ('''CERT-In''' or '''ICERT''') is an office within the [[Ministry of Electronics and Information Technology]] of the [[Government of India]].<ref name="meity -- icert"/> It is the nodal agency to deal with cyber security threats like [[hacker|hacking]] and [[phishing]]. It strengthens security-related defence of the Indian Internet domain.  
The '''Indian Computer Emergency Response Team''' ('''CERT-In''' or '''IN-CERT''') is an office within the [[Ministry of Electronics and Information Technology]] of the [[Government of India]].&lt;ref name="meity -- icert"/&gt; It is the nodal agency to deal with cyber security incidents. It strengthens security-related defence of the Indian Internet domain.&lt;ref&gt;{{Cite web |date=2025-05-10 |title=During Operation Sindoor, let’s not forget about digital warfare |url=https://indianexpress.com/article/opinion/columns/during-operation-sindoor-lets-not-forget-about-digital-warfare-9993233/ |access-date=2025-05-13 |website=The Indian Express |language=en}}&lt;/ref&gt;


== Background ==
== Background ==
CERT-IN was formed in 2004 by the Government of India under [[Information Technology Act, 2000]] Section (70B) under the Ministry of Communications and Information Technology. CERT-IN has overlapping responsibilities with other agencies such as [[National Critical Information Infrastructure Protection Centre|National Critical Information Infrastructure Protection Centre (NCIIPC)]] which is under the National Technical Research Organisation (NTRO) that comes under the Prime Minister's Office and the National Disaster Management Authority (NDMA) which is under Ministry of Home Affairs.<ref>{{Cite web|title=India's Cyber Security Policy and Organisation – A Critical Assessment|url=https://www.indiannavy.nic.in/sites/default/themes/indiannavy/images/pdf/resources/article_6.pdf|url-status=live}}</ref>
CERT-In, an acronym for 'Indian Computer Emergency Response Team', is the National Incident Response Centre for major computer security incidents in its constituency i.e. Indian cyber community. It was formed in 2004 by the Government of India under [[Information Technology Act, 2000]] Section (70B) under the Ministry of Communications and Information Technology. CERT-In is a functional organisation of Ministry of Electronics and Information, Govt. of India, with an objective of securing Indian cyber space.&lt;ref name=":0"&gt;{{Cite web |title=Explained {{!}} What is CERT-In? |url=https://www.onmanorama.com/news/india/2023/11/03/cert-in-explained.html |access-date=2024-06-20 |website=Onmanorama}}&lt;/ref&gt;
 
CERT-In's primary role is to raise security awareness among Indian cyber community and to provide technical assistance and advise them to help them recover from computer security incidents.&lt;ref name=":0" /&gt;  It provides technical advice to System Administrators and users to respond to computer security incidents. It also identifies trends in intruder activity, works with other similar institutions &amp; organisations to resolve major security issues, and disseminates information to the Indian cyber community.
It also enlightens its constituents about the security awareness and best practices for various systems; networks by publishing advisories, guidelines and other technical document.&lt;ref&gt;{{Cite web |last=www.ETCISO.in |title=Cyber security handbook released to empower women - ET CISO |url=https://ciso.economictimes.indiatimes.com/news/cybercrime-fraud/cyber-security-handbook-released-to-empower-women/118797854 |access-date=2025-05-13 |website=ETCISO.in |language=en}}&lt;/ref&gt;
 
CERT-In's vision is to proactively contribution in securing India's cyber space and building safe and trusted cyber ecosystem for the citizen. Its mission is to enhance the security of India's Communications and Information Infrastructure through proactive action and effective collaboration.&lt;ref&gt;{{Cite web |title=The Indian Computer Emergency Response Team (CERT-In) releases "Cyber Security Handbook for Mahila Suraksha" Booklet on International Women's Day |url=https://www.pib.gov.in/PressReleasePage.aspx?PRID=2109192 |archive-url=https://web.archive.org/web/20250312194158/https://www.pib.gov.in/PressReleasePage.aspx?PRID=2109192 |archive-date=12 March 2025 |access-date=2025-05-13 |website=www.pib.gov.in |url-status=live }}&lt;/ref&gt;


== Functions ==
== Functions ==
In December 2013, CERT-In reported there was a rise in cyber attacks on Government organisations like [[banking]] and [[finance]], oil and gas and emergency services. It issued a list of security guidelines to all critical departments.<ref>{{cite news|title=As cyber attacks rise, government sounds alert|url=http://www.thehindu.com/news/national/as-cyber-attacks-rise-government-sounds-alert/article5501672.ece|newspaper=The Hindu|date=26 December 2013|location=New Delhi, India}}</ref> It liaisons with the Office of National Cyber Security Coordinator, National Security Council and National Information Board in terms of the nation's cyber security and threats. As a nodal entity, India’s Computer Emergency Response Team (CERT-in) plays a crucial role under the Ministry of Electronics and Information Technology(MeitY).
In December-2013, CERT-In reported there was a rise in cyber attacks on Government organisations like [[bank]]ing and [[finance]], oil and gas and emergency services. It issued a list of security guidelines to all critical departments.&lt;ref&gt;{{cite news|title=As cyber attacks rise, government sounds alert|url=http://www.thehindu.com/news/national/as-cyber-attacks-rise-government-sounds-alert/article5501672.ece|newspaper=The Hindu|date=26 December 2013|location=New Delhi, India}}&lt;/ref&gt; It liaisons with the Office of National Cyber Security Coordinator, National Security Council and National Information Board in terms of the nation's cyber security and threats. As a nodal entity, India's Computer Emergency Response Team (CERT-In) plays a crucial role under the Ministry of Electronics and Information Technology(MeitY).


September 2022, CERT-In hosted exercise 'Synergy'  in collaboration with Cyber Security Agency, Singapore. It had a participation of 13 countries and was conducted as a part of the International Counter Ransomware Initiative-Resilience Working Group.<ref>{{Cite web |title=CERT-In hosts Cyber Security Exercise "Synergy" for 13 countries as part of International Counter Ransomware Initiative- Resilience Working Group |url=https://pib.gov.in/pib.gov.in/Pressreleaseshare.aspx?PRID=1855771 |access-date=2023-01-23 |website=pib.gov.in}}</ref>
Indian Computer Emergency Response Team (CERT-In) launched Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre) on 21-February-2017 as part of the Government of India's [[Digital India]] initiative under [[MeitY]].&lt;ref&gt;{{cite news |title=Ministry of Electronics and Information Technology (MeitY) launches Cyber Swachhta Kendra - Botnet Cleaning and Malware Analysis Centre |url=https://pib.gov.in/newsite/printrelease.aspx?relid=158620 |publisher=[[Press Information Bureau]] |date=22 February 2017}}&lt;/ref&gt; Cyber Swachhta Kendra] (CSK) is a citizen centric service provided by CERT-In, which extends the vision of Swachh Bharat to the Cyber Space. CSK aims to secure India's digital IT Infrastructure by creating a dedicated mechanism for providing timely information about Botnet/Malware threats to the victim organisation/user and suggesting remedial actions to be taken by the concerned entity. The centre has been established for detection of compromised systems in India and to notify, enable cleaning and securing systems of end users to prevent further malware infections. The centre is working in close coordination and collaboration with Internet Service Providers, Academia and Industry. The centre is providing detection of malicious programs and free tools to remove the same for common users.
 
In September-2022, CERT-In hosted exercise 'Synergy'  in collaboration with Cyber Security Agency, Singapore. It had a participation of 13 countries and was conducted as a part of the International Counter Ransomware Initiative-Resilience Working Group.&lt;ref&gt;{{Cite web |title=CERT-In hosts Cyber Security Exercise "Synergy" for 13 countries as part of International Counter Ransomware Initiative- Resilience Working Group |url=https://pib.gov.in/pib.gov.in/Pressreleaseshare.aspx?PRID=1855771 |access-date=2023-01-23 |website=pib.gov.in}}&lt;/ref&gt;


== Agreements ==
== Agreements ==
A memorandum of understanding (MoU) was signed in May 2016 between the Indian Computer Emergency Response Team (CERT-In) and the Ministry of Cabinet Office, UK.  
A memorandum of understanding (MoU) was signed in May-2016 between the Indian Computer Emergency Response Team (CERT-In) and the Ministry of Cabinet Office, UK.
 
Earlier CERT-In signed MoUs with similar organisations in about seven countries – Korea, Canada, Australia, Malaysia, Singapore, Japan and Uzbekistan.
 
The Ministry of External Affairs has also signed MoU with Cyber Security as one of the areas of cooperation with [[Shanghai Cooperation Organisation]]. With the MoUs, participating countries can exchange technical information on Cyber attacks, respond to cybersecurity incidents and find solutions to counter the cyber attacks. They can also exchange information on prevalent cyber security policies and best practices. The MoUs helps to strengthen the cyber space of signing countries, capacity building and improving the relationship between them.&lt;ref&gt;{{Cite news |date=13 October 2016 |title=Cabinet apprised of MoU between CERT-In India and CERT-UK |url=https://www.business-standard.com/article/government-press-release/cabinet-apprised-of-mou-between-cert-in-india-and-cert-uk-116083100561_1.html |access-date=20 June 2024 |work=Business Standard}}&lt;/ref&gt;
 
A memorandum of understanding was signed by CERT-In and [[Mastercard]] to foster collaboration and information exchange in the field of financial sector cyber security. Both parties will take advantage of their combined knowledge in the areas of advanced malware analysis, cybersecurity incident response, capacity building, and exchanging cyber threat intelligence relevant to the banking sector.&lt;ref&gt;{{Cite news |date=2024-06-20 |title=Mastercard and CERT-In join hands to strengthen cybersecurity for financial sector |url=https://timesofindia.indiatimes.com/technology/tech-news/mastercard-and-cert-in-join-hands-to-strengthen-cybersecurity-for-financial-sector/articleshow/111121150.cms |access-date=2024-06-20 |work=The Times of India |issn=0971-8257}}&lt;/ref&gt;


Earlier CERT-In signed MoUs with similar organisations in about seven countries - Korea, Canada, Australia, Malaysia, Singapore, Japan and Uzbekistan.  
In March-2014, CERT-In reported a critical flaw in [[Android Jelly Bean]]'s [[VPN]] implementation.&lt;ref&gt;{{cite news|date=2 March 2014|title=Android's Jelly Bean, Kit Kat under cyber threat in India: CERT-In|newspaper=NDTV|location=New Delhi, India|url=http://www.ndtv.com/article/india/android-s-jelly-bean-kit-kat-under-cyber-threat-in-india-cert-in-490293}}&lt;/ref&gt;


The Ministry of External Affairs has also signed MoU with Cyber Security as one of the areas of cooperation with [[Shanghai Cooperation Organisation]]. With the MoUs, participating countries can exchange technical information on Cyber attacks, respond to cybersecurity incidents and find solutions to counter the cyber attacks. They can also exchange information on prevalent cyber security policies and best practices. The MoUs helps to strengthen the cyber space of signing countries, capacity building and improving the relationship between them.<ref>{{Cite web|url=http://pib.nic.in/newsite/PrintRelease.aspx?relid=149372|title = Cabinet apprised of MoU between CERT-In India and CERT-UK}}</ref>
In July-2020, CERT-In warned Google Chrome users to immediately upgrade to the new Chrome browser version 84.0.4147.89. Multiple vulnerabilities that could allow access to hackers were reported.&lt;ref&gt;{{Cite news|last=IANS|date=2020-07-21|title=Update your Google Chrome browser now to avoid hackers, says CERT-In|work=Business Standard India|url=https://www.business-standard.com/article/technology/update-your-google-chrome-browser-now-to-avoid-hackers-says-cert-in-120072100333_1.html|access-date=2021-06-16}}&lt;/ref&gt;


== Incidents and reports ==
In April-2021, issued a "high severity" rating advisory on the vulnerability detected on WhatsApp and WhatsApp Business for Android prior to v2.21.4.18 and WhatsApp and WhatsApp Business for iOS prior to v2.21.32.&lt;ref&gt;{{Cite web|title=WhatsApp Users Warned of Flaw That Could Leak Their Personal Data|url=https://gadgets.ndtv.com/apps/news/whatsapp-user-data-breach-leak-security-flaw-vulnerability-cert-in-advisory-2416759|access-date=2021-06-16|website=NDTV Gadgets 360|date=19 April 2021}}&lt;/ref&gt;
In March 2014, CERT-In reported a critical flaw in [[Android Jelly Bean]]'s [[VPN]] implementation.<ref>{{cite news|date=2 March 2014|title=Android's Jelly Bean, Kit Kat under cyber threat in India: CERT-In|newspaper=NDTV|location=New Delhi, India|url=http://www.ndtv.com/article/india/android-s-jelly-bean-kit-kat-under-cyber-threat-in-india-cert-in-490293}}</ref>


In July 2020, CERT-In warned Google Chrome users to immediately upgrade to the new Chrome browser version 84.0.4147.89. Multiple vulnerabilities that could allow access to hackers were reported.<ref>{{Cite news|last=IANS|date=2020-07-21|title=Update your Google Chrome browser now to avoid hackers, says CERT-In|work=Business Standard India|url=https://www.business-standard.com/article/technology/update-your-google-chrome-browser-now-to-avoid-hackers-says-cert-in-120072100333_1.html|access-date=2021-06-16}}</ref>
According to the agency, India faced 11.5 million cyberattack incidents in 2021 including corporate attacks, and attacks on critical infrastructure and government agencies.&lt;ref&gt;{{cite news |url=https://www.thehindu.com/business/Industry/us-cybersecurity-provider-sentinelone-opens-india-office-in-bengaluru/article65529464.ece |title=US cybersecurity provider SentinelOne opens India office in Bengaluru |date=2022-06-15 |work=[[The Hindu]]}}&lt;/ref&gt;


In April 2021, issued a "high severity" rating advisory on the vulnerability detected on WhatsApp and WhatsApp Business for Android prior to v2.21.4.18 and WhatsApp and WhatsApp Business for iOS prior to v2.21.32.<ref>{{Cite web|title=WhatsApp Users Warned of Flaw That Could Leak Their Personal Data|url=https://gadgets.ndtv.com/apps/news/whatsapp-user-data-breach-leak-security-flaw-vulnerability-cert-in-advisory-2416759|access-date=2021-06-16|website=NDTV Gadgets 360|language=en}}</ref>
On 04-December-2022, CERT-In was called in to investigate the cyber attack on [[All India Institute of Medical Sciences, New Delhi|All India Institute of Medical Sciences (AIIMS), Delhi.]]


According to the agency, India faced 11.5 million cyberattack incidents in 2021 including corporate attacks, and attacks on critical infrastructure and government agencies.<ref>{{cite news |url=https://www.thehindu.com/business/Industry/us-cybersecurity-provider-sentinelone-opens-india-office-in-bengaluru/article65529464.ece |title=US cybersecurity provider SentinelOne opens India office in Bengaluru |date=2022-06-15 |work=[[The Hindu]]}}</ref>
On 19-July-2024, a [[2024 CrowdStrike incident|computer outage]] relating to [[CrowdStrike|CrowdStrike tools]] in [[Microsoft|Microsoft systems]] was reported. CERT-In categorised the incident as "critical" and the IT minister, [[Ashwini Vaishnaw|Ashwini Vaishnav]] said that the government is in touch with Microsoft and the issue will be resolved.&lt;ref&gt;{{Cite web |title=Massive Worldwide Microsoft Outage: Flights, Markets, Stock Exchange Down |url=https://www.ndtv.com/world-news/microsoft-blue-screen-of-death-flights-markets-banks-stock-exchange-microsoft-outage-crippling-sectors-6139053 |access-date=2024-07-19 |website=NDTV.com}}&lt;/ref&gt;&lt;ref&gt;{{Cite news |last=Bureau |date=2024-07-19 |title=Microsoft Global Outage LIVE: Microsoft's Windows outage impacts airlines, financial institutions and broadcasters on a global scale |url=https://www.thehindu.com/sci-tech/technology/microsoft-outage-live-updates-mumbai-delhi-flight-operations-affected/article68421219.ece |access-date=2024-07-19 |work=The Hindu|issn=0971-751X}}&lt;/ref&gt;


December 4 2022, CERT-In was called in to investigate the cyber attack on [[All India Institute of Medical Sciences, New Delhi|All India Institute of Medical Sciences (AIIMS), Delhi.]]
== Guidelines ==
The IN-CERT issues guidelines on cybersecurity and critical vulnerabilities, from time to time. In April-2022, the IN-CERT issued a set of directions requiring certain cyber security measures to be undertaken by companies,&lt;ref&gt;{{Cite web |title=CERT-In issues directions relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe &amp; Trusted Internet |url=https://www.pib.gov.in/www.pib.gov.in/Pressreleaseshare.aspx?PRID=1820904 |access-date=2024-06-07 |website=pib.gov.in}}&lt;/ref&gt; including the following:
 
* Reporting of cyber incidents within six hours&lt;ref&gt;{{Cite web |last=Sameer Avasarala |first=Prashant Phillips |title=Analyzing the new CERT-IN Directions: Wider gamut than breach reporting |url=https://lakshmisri.com/insights/articles/analyzing-the-new-cert-in-directions-wider-gamut-than-breach-reporting/ |access-date=2024-06-07 |website=lakshmisri.com}}&lt;/ref&gt; to IN-CERT (which was limited to high-severity incidents through the FAQs)
* Maintenance of ICT logs within the territory of India.&lt;ref&gt;{{Cite web |last=Sengupta |first=Arun Prabhu, Arpita |date=2022-05-24 |title=The Cert-In Cyber Security Directions: More Questions Than Answers? |url=https://corporate.cyrilamarchandblogs.com/2022/05/the-cert-in-cyber-security-directions-more-questions-than-answers/ |access-date=2024-06-07 |website=India Corporate Law}}&lt;/ref&gt; Pursuant to the FAQs, they may be stored outside India, provided the requirement to store such logs outside India is met if logs can be produced as and when solicited by IN-CERT;
* Synchronisation of system time clocks with [[Network Time Protocol]] servers of [[National Physical Laboratory of India|National Physical Laboratory]] or [[National Informatics Centre]]; and
* Additional obligations for [[Virtual private network|VPN]] and [[Virtual private server|VPS]] service providers.
 
Subsequently, the IN-CERT issued certain FAQs&lt;ref&gt;{{Cite web |title=Indian Computer Emergency Response Team (CERT-In) releases FAQs to address queries on Cyber Security Directions of 28.04.2022 |url=https://www.pib.gov.in/www.pib.gov.in/Pressreleaseshare.aspx?PRID=1826388 |access-date=2024-06-07 |website=pib.gov.in}}&lt;/ref&gt; which clarified and relaxed some of the aforesaid requirements.


==References==
==References==
Line 94: Line 109:
[[Category:Government agencies established in 2004]]
[[Category:Government agencies established in 2004]]
[[Category:2004 establishments in India]]
[[Category:2004 establishments in India]]
 
[[Category:Computer security in India]]
 
{{India-gov-stub}}
[[Category:Cyber Security in India]]

Revision as of 21:38, 25 August 2025


Indian Computer Emergency Response Team (CERT-In)
भारतीय कंप्यूटर आपातकालीन प्रतिक्रिया टीम
Agency overview
Formed19 January 2004; 22 years ago (2004-01-19)<ref name="tt.in">"techtarget.in". Archived from the original on 21 October 2013. Retrieved 21 October 2013.</ref><ref name="fir">"first.org- About CERT-In". Retrieved 23 October 2013.</ref>
Preceding agencies
JurisdictionGovernment of India
HeadquartersNew Delhi, India<ref name="meity -- icert">"meity.gov.in -- CERT-In". Retrieved 21 October 2013.</ref>
28°35′11″N 77°14′22″E / 28.58639°N 77.23944°E / 28.58639; 77.23944
MottoHandling Cyber Security Incidents
Minister responsible
  • <!-- (etc.) -->
Deputy Minister responsible
  • <!-- (etc.) -->
Agency executive
Parent departmentMinistry of Electronics and Information Technology
Child agencies
  • <!-- (etc.) -->
Key document
  • <!-- (etc.) -->
Websiteसर्ट-इन.भारत , www.cert-in.org.in, www.सीएसके.सरकार.भारत , www.csk.gov.in

The Indian Computer Emergency Response Team (CERT-In or IN-CERT) is an office within the Ministry of Electronics and Information Technology of the Government of India.<ref name="meity -- icert"/> It is the nodal agency to deal with cyber security incidents. It strengthens security-related defence of the Indian Internet domain.<ref>"During Operation Sindoor, let's not forget about digital warfare". The Indian Express. 10 May 2025. Retrieved 13 May 2025.</ref>

Background

CERT-In, an acronym for 'Indian Computer Emergency Response Team', is the National Incident Response Centre for major computer security incidents in its constituency i.e. Indian cyber community. It was formed in 2004 by the Government of India under Information Technology Act, 2000 Section (70B) under the Ministry of Communications and Information Technology. CERT-In is a functional organisation of Ministry of Electronics and Information, Govt. of India, with an objective of securing Indian cyber space.<ref name=":0">"Explained | What is CERT-In?". Onmanorama. Retrieved 20 June 2024.</ref>

CERT-In's primary role is to raise security awareness among Indian cyber community and to provide technical assistance and advise them to help them recover from computer security incidents.<ref name=":0" /> It provides technical advice to System Administrators and users to respond to computer security incidents. It also identifies trends in intruder activity, works with other similar institutions & organisations to resolve major security issues, and disseminates information to the Indian cyber community. It also enlightens its constituents about the security awareness and best practices for various systems; networks by publishing advisories, guidelines and other technical document.<ref>www.ETCISO.in. "Cyber security handbook released to empower women - ET CISO". ETCISO.in. Retrieved 13 May 2025.</ref>

CERT-In's vision is to proactively contribution in securing India's cyber space and building safe and trusted cyber ecosystem for the citizen. Its mission is to enhance the security of India's Communications and Information Infrastructure through proactive action and effective collaboration.<ref>"The Indian Computer Emergency Response Team (CERT-In) releases "Cyber Security Handbook for Mahila Suraksha" Booklet on International Women's Day". www.pib.gov.in. Archived from the original on 12 March 2025. Retrieved 13 May 2025.</ref>

Functions

In December-2013, CERT-In reported there was a rise in cyber attacks on Government organisations like banking and finance, oil and gas and emergency services. It issued a list of security guidelines to all critical departments.<ref>"As cyber attacks rise, government sounds alert". The Hindu. New Delhi, India. 26 December 2013.</ref> It liaisons with the Office of National Cyber Security Coordinator, National Security Council and National Information Board in terms of the nation's cyber security and threats. As a nodal entity, India's Computer Emergency Response Team (CERT-In) plays a crucial role under the Ministry of Electronics and Information Technology(MeitY).

Indian Computer Emergency Response Team (CERT-In) launched Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre) on 21-February-2017 as part of the Government of India's Digital India initiative under MeitY.<ref>"Ministry of Electronics and Information Technology (MeitY) launches Cyber Swachhta Kendra - Botnet Cleaning and Malware Analysis Centre". Press Information Bureau. 22 February 2017.</ref> Cyber Swachhta Kendra] (CSK) is a citizen centric service provided by CERT-In, which extends the vision of Swachh Bharat to the Cyber Space. CSK aims to secure India's digital IT Infrastructure by creating a dedicated mechanism for providing timely information about Botnet/Malware threats to the victim organisation/user and suggesting remedial actions to be taken by the concerned entity. The centre has been established for detection of compromised systems in India and to notify, enable cleaning and securing systems of end users to prevent further malware infections. The centre is working in close coordination and collaboration with Internet Service Providers, Academia and Industry. The centre is providing detection of malicious programs and free tools to remove the same for common users.

In September-2022, CERT-In hosted exercise 'Synergy' in collaboration with Cyber Security Agency, Singapore. It had a participation of 13 countries and was conducted as a part of the International Counter Ransomware Initiative-Resilience Working Group.<ref>"CERT-In hosts Cyber Security Exercise "Synergy" for 13 countries as part of International Counter Ransomware Initiative- Resilience Working Group". pib.gov.in. Retrieved 23 January 2023.</ref>

Agreements

A memorandum of understanding (MoU) was signed in May-2016 between the Indian Computer Emergency Response Team (CERT-In) and the Ministry of Cabinet Office, UK.

Earlier CERT-In signed MoUs with similar organisations in about seven countries – Korea, Canada, Australia, Malaysia, Singapore, Japan and Uzbekistan.

The Ministry of External Affairs has also signed MoU with Cyber Security as one of the areas of cooperation with Shanghai Cooperation Organisation. With the MoUs, participating countries can exchange technical information on Cyber attacks, respond to cybersecurity incidents and find solutions to counter the cyber attacks. They can also exchange information on prevalent cyber security policies and best practices. The MoUs helps to strengthen the cyber space of signing countries, capacity building and improving the relationship between them.<ref>"Cabinet apprised of MoU between CERT-In India and CERT-UK". Business Standard. 13 October 2016. Retrieved 20 June 2024.</ref>

A memorandum of understanding was signed by CERT-In and Mastercard to foster collaboration and information exchange in the field of financial sector cyber security. Both parties will take advantage of their combined knowledge in the areas of advanced malware analysis, cybersecurity incident response, capacity building, and exchanging cyber threat intelligence relevant to the banking sector.<ref>"Mastercard and CERT-In join hands to strengthen cybersecurity for financial sector". The Times of India. 20 June 2024. ISSN 0971-8257. Retrieved 20 June 2024.</ref>

In March-2014, CERT-In reported a critical flaw in Android Jelly Bean's VPN implementation.<ref>"Android's Jelly Bean, Kit Kat under cyber threat in India: CERT-In". NDTV. New Delhi, India. 2 March 2014.</ref>

In July-2020, CERT-In warned Google Chrome users to immediately upgrade to the new Chrome browser version 84.0.4147.89. Multiple vulnerabilities that could allow access to hackers were reported.<ref>IANS (21 July 2020). "Update your Google Chrome browser now to avoid hackers, says CERT-In". Business Standard India. Retrieved 16 June 2021.</ref>

In April-2021, issued a "high severity" rating advisory on the vulnerability detected on WhatsApp and WhatsApp Business for Android prior to v2.21.4.18 and WhatsApp and WhatsApp Business for iOS prior to v2.21.32.<ref>"WhatsApp Users Warned of Flaw That Could Leak Their Personal Data". NDTV Gadgets 360. 19 April 2021. Retrieved 16 June 2021.</ref>

According to the agency, India faced 11.5 million cyberattack incidents in 2021 including corporate attacks, and attacks on critical infrastructure and government agencies.<ref>"US cybersecurity provider SentinelOne opens India office in Bengaluru". The Hindu. 15 June 2022.</ref>

On 04-December-2022, CERT-In was called in to investigate the cyber attack on All India Institute of Medical Sciences (AIIMS), Delhi.

On 19-July-2024, a computer outage relating to CrowdStrike tools in Microsoft systems was reported. CERT-In categorised the incident as "critical" and the IT minister, Ashwini Vaishnav said that the government is in touch with Microsoft and the issue will be resolved.<ref>"Massive Worldwide Microsoft Outage: Flights, Markets, Stock Exchange Down". NDTV.com. Retrieved 19 July 2024.</ref><ref>Bureau (19 July 2024). "Microsoft Global Outage LIVE: Microsoft's Windows outage impacts airlines, financial institutions and broadcasters on a global scale". The Hindu. ISSN 0971-751X. Retrieved 19 July 2024. {{cite news}}: |last= has generic name (help)</ref>

Guidelines

The IN-CERT issues guidelines on cybersecurity and critical vulnerabilities, from time to time. In April-2022, the IN-CERT issued a set of directions requiring certain cyber security measures to be undertaken by companies,<ref>"CERT-In issues directions relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet". pib.gov.in. Retrieved 7 June 2024.</ref> including the following:

Subsequently, the IN-CERT issued certain FAQs<ref>"Indian Computer Emergency Response Team (CERT-In) releases FAQs to address queries on Cyber Security Directions of 28.04.2022". pib.gov.in. Retrieved 7 June 2024.</ref> which clarified and relaxed some of the aforesaid requirements.

References