Indian Computer Emergency Response Team
Definition
CERT-In is India’s national agency for cybersecurity incident response and guidelines. It issues directions on logging, reporting, and data-handling practices for organisations operating in India.
CERT-In-aligned practices and India-hosted data give fleets assurance that their operational data is handled to national security standards.
CERT-In is India’s national nodal agency for computer security incident response, operating under the Ministry of Electronics and Information Technology. It coordinates response to cybersecurity incidents, issues advisories and vulnerability notes, and in April 2022 issued directions that created concrete operational obligations for organisations operating in India.
Those directions are what make CERT-In relevant to a fleet platform rather than a purely governmental concern. They are binding on service providers, intermediaries, data centres and body corporates, which includes telematics providers and, in relevant respects, the fleets using them.
A fleet platform holds continuous location history, driver identity, and in many deployments cab-facing video. That is an attractive target and a serious breach if it is exposed, so the security posture of the vendor is part of the fleet’s own risk rather than a detail of procurement.
The questions worth asking are concrete. Where are logs stored, and for how long. What is the incident notification path to the customer, and how fast. Who is the designated contact. How is access to location history and cab video scoped and audited internally.
These sit alongside DPDP Act obligations rather than replacing them: CERT-In is largely about incident response and evidence, DPDP is about lawful collection and the rights of the people the data describes. A fleet needs both answered, and they are usually answered by different documents.
CERT-In is India’s national agency for cybersecurity incident response, operating under MeitY. It coordinates incident response, issues advisories and vulnerability notes, and has issued binding directions covering incident reporting, log retention and related obligations for organisations operating in India.
Under the April 2022 directions, reportable cybersecurity incidents must be reported to CERT-In within six hours of being noticed or brought to notice. In practice this requires an out-of-hours detection and escalation path and a named responsible person, not a next-working-day process.
ICT system logs must be maintained securely for a rolling period of 180 days and stored within India, and made available to CERT-In when required in connection with an incident.
CERT-In directions are about cybersecurity incident response, logging and evidence. The DPDP Act is about lawful processing of personal data and the rights of the individuals it describes. A fleet platform needs to satisfy both, and they are usually addressed by different controls and documents.
Related terms
Begin
Join thousands of vehicle owners and businesses across every Indian state and union territory that trust MoboSafe for real-time tracking, safety, and peace of mind.