The Pension Fund Regulatory and Development Authority (PFRDA) on June 15, 2022 has issued Cyber Security Directions issued by CERT-In. This has come into effect from June 27, 2022
The Directions cover aspects related to synchronisation of Information and Communication Technology (ICT) system clocks, reporting of the cyber incidents to CERT-In types of cyber incident to reported maintaining logs of ICT system among others.
The following directions has been stated namely: -
• All service providers, intermediaries, data centres, body corporate and Government organisations shall connect to the Network Time Protocol (NTP) Server of National Informatics Centre (NIC) or National Physical Laboratory (NPL) or with NTP servers traceable to these NTP servers, for synchronisation of all their ICT systems clocks.
• Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents.
• The service provider/intermediary/data centre/body corporate is mandated to take action or provide information or any such assistance to CERT-In, which may contribute towards cyber security mitigation actions and enhanced cyber security situational awareness.
[Notification No. PFRDA/2022/14/I&CS/02]