Regulatory Intelligence

Cybersecurity
Compliance Hub.

A comprehensive reference for India's IT Act, DPDP Bill, ISO 27001, PCI-DSS, CERT-In mandates, and global data protection frameworks — curated by CFSS compliance experts.

Indian Legal Framework
IT Act 2000 (Amended 2008)
Information Technology Act — Primary Cyber Law of India
IT Act

The IT Act 2000 (amended 2008) is India's primary legislation governing electronic commerce, digital signatures, cybercrime, and data protection. Key provisions:

Section 43: Penalty for unauthorized access, damage to computer systems (up to ₹1 Crore compensation)
Section 66: Computer-related offences — hacking, data theft (imprisonment up to 3 years and/or fine up to ₹5 Lakhs)
Section 66A: Offensive online communication (struck down by Supreme Court, but Section 66 applies)
Section 66C: Identity theft — punishment up to 3 years imprisonment and fine
Section 66D: Cheating by personation using computer resources
Section 67B: Punishment for child pornography — up to 7 years + fine
Section 69: Government power to intercept, monitor, or decrypt information
Section 72A: Punishment for disclosure of information in breach of lawful contract
Digital Personal Data Protection Act (DPDP) 2023
India's First Comprehensive Data Privacy Law
DPDP

Signed into law in August 2023, the DPDP Act governs the processing of digital personal data in India. It introduces significant obligations for data fiduciaries (organizations) and rights for data principals (individuals):

Consent: Organizations must obtain free, specific, informed, and unambiguous consent before processing personal data
Data Minimization: Collect only data necessary for the stated purpose
Purpose Limitation: Data must be used only for the purpose for which it was collected
Data Principal Rights: Right to access, correct, erase, and nominate regarding personal data
Data Fiduciary Obligations: Maintain data accuracy, implement security safeguards, notify breaches to DPBI
Breach Notification: Mandatory breach reporting to the Data Protection Board of India (DPBI)
Penalties: Up to ₹250 Crore for significant violations; up to ₹10,000 for individual minor breaches
Children's Data: Parental consent mandatory for processing data of children under 18
CERT-In Mandatory Cybersecurity Directions 2022
Ministry of Electronics and Information Technology
CERT-In

The Indian Computer Emergency Response Team (CERT-In) issued mandatory Cybersecurity Directions in April 2022, effective from June 2022, creating binding obligations for all organizations operating in India:

Mandatory 6-Hour Reporting: All cybersecurity incidents must be reported to CERT-In within 6 hours of detection
60+ Incident Types: Covers data breaches, ransomware, malware, phishing, unauthorized access, and DDoS attacks
Log Retention: 180 days of ICT system logs must be maintained within Indian jurisdiction
Synchronized Clocks: All ICT infrastructure must use NTP with traceable time sources (Indian standard)
VPN/VPS Providers: Must register subscriber information and retain for 5 years
Data Centers: Must maintain details of subscribers for 5 years
International Standards
ISO/IEC 27001:2022
International Information Security Management Standard
ISO 27001

ISO/IEC 27001 is the internationally recognized standard for Information Security Management Systems (ISMS). It provides a systematic framework for managing sensitive company information:

Context of Organization: Understanding internal/external issues, stakeholder needs, ISMS scope
Risk Assessment: Systematic identification, analysis, and evaluation of information security risks
Annex A Controls: 93 security controls across 4 themes — Organizational, People, Physical, Technological
Statement of Applicability: Document which controls apply and reasons for inclusion/exclusion
ISMS Policy: Top management must establish and endorse the information security policy
Continual Improvement: Regular internal audits, management reviews, and nonconformity correction
Incident Management: Documented incident response procedures covering detection, response, and post-incident review
PCI DSS v4.0
Payment Card Industry Data Security Standard
PCI DSS

PCI DSS v4.0 (effective March 2024) is the payment card security standard mandatory for all entities storing, processing, or transmitting cardholder data. 12 core requirements:

Req 1-2: Install and maintain network security controls; apply secure configurations
Req 3-4: Protect stored cardholder data; protect cardholder data in transit (TLS 1.2+)
Req 5-6: Protect against malicious software; develop and maintain secure systems
Req 7-9: Restrict access; identify users; restrict physical access
Req 10-11: Log and monitor all access; test security systems and networks regularly
Req 12: Support information security with organizational policies and programs
SEBI Cybersecurity & Cyber Resilience Framework (CSCRF)
Securities & Exchange Board of India — Financial Market Regulation
SEBI

SEBI's Cybersecurity and Cyber Resilience Framework is mandatory for all SEBI-regulated entities including stock brokers, depositories, mutual funds, and market infrastructure institutions:

Governance: Board-level cybersecurity oversight; appointment of CISO with direct reporting
SOC Requirement: Mandatory Security Operations Center for Critical Market Infrastructure entities
VAPT Mandated: Annual comprehensive vulnerability assessment and penetration testing
Cyber Drill: Mandatory participation in biannual SEBI/CERT-In cyber drills
Recovery Objectives: RTO ≤ 4 hours, RPO ≤ 2 hours for critical systems
Incident Reporting: Report incidents to SEBI within 6 hours; forensic analysis within 21 days
Compliance Assessment

Need a Compliance Audit?

CFSS provides comprehensive compliance audits, gap assessments, and remediation roadmaps for Indian and international cybersecurity frameworks.

Request Compliance Audit Our Services