Concept Page
Computer Emergency Response Team (CERT)
A Computer Emergency Response Team is a group that responds to computer security incidents. It plays a crucial role in mitigating cyber threats. India has a CERT, known as CERT-In.
Computer Emergency Response Teams (CERTs) are dedicated units that coordinate the detection, analysis, and mitigation of computer security incidents across networks, organizations, and nations. Originating as a rapid‑response hub after the 1988 Morris worm, the CERT model has become the backbone of global cyber‑defence, providing real‑time alerts, vulnerability advisories, and a trusted liaison between technical experts, law‑enforcement agencies, and policy makers.
Origins and Global Evolution
The first CERT, the Computer Emergency Response Team Coordination Center (CERT/CC), was founded in November 1988 at Carnegie Mellon University under a U.S. Department of Defense contract. Its success prompted the creation of national and sectoral teams worldwide, and by 2023 the Forum of Incident Response and Security Teams (FIRST) listed more than 150 active CERTs. Early adopters such as the United Kingdom’s CERT‑UK (1999) and Japan’s JPCERT/CC (1996) expanded the model to include public‑private partnerships and mandatory incident‑reporting frameworks.
Legal Foundations and Mandate in India
India’s statutory basis for a national CERT is Section 70B of the Information Technology Act, 2000, which authorises the Ministry of Electronics and Information Technology (MeitY) to “establish a Computer Emergency Response Team.” The team, known as CERT‑In, was formally constituted in 2004 and became operational in early 2005. Subsequent amendments—most notably the CERT‑In (Amendment) Rules 2021—require owners of Critical Information Infrastructure (CII) to report cyber incidents to CERT‑In within 72 hours, thereby granting the agency statutory powers to issue advisories, coordinate takedowns, and impose penalties for non‑compliance.
Operational Mechanism
CERT‑In runs a 24 × 7 Security Operations Centre that ingests alerts from ISPs, government agencies, and private sector partners through a dedicated portal (https://www.cert‑in.org.in). Each alert is triaged by a team of analysts who classify the threat, assess impact, and disseminate a technical advisory—often within hours of detection. The team also publishes a monthly “Threat Landscape Report,” which in 2022 documented 2,13,000 reported incidents and 1,587 vulnerability advisories, helping organisations prioritise patches and harden defenses.
India’s CERT‑In: Evolution and Current Role
Since its inception, CERT‑In has broadened its remit from reactive incident handling to proactive threat intelligence. In 2020 it launched the Cyber Incident Reporting Portal, enabling automated submission of logs and forensic artefacts. By 2023, under the leadership of Director Dr. S. S. R., the agency introduced an AI‑driven analytics engine that correlates global malware signatures with domestic attack vectors, reducing average response time by 30 percent. The same year it issued the first national ransomware response guideline, outlining containment steps, ransom‑payment policies, and post‑incident forensic standards for both public and private entities.
International Collaboration and Comparison
CERT‑In is a founding member of FIRST and maintains formal liaison agreements with the U.S. CERT‑CC, the European Union Agency for Cybersecurity (ENISA), and Australia’s Cyber Security Centre (ACSC). While the U.S. CERT‑CC operates primarily as a research hub, India’s CERT‑In combines research with regulatory enforcement, a hybrid model mirrored only by a few nations such as Singapore’s Cyber Security Agency. In 2024, the Andhra Pradesh Police Department partnered with CERT‑In to establish an AI‑powered cyber war room, illustrating how the Indian model integrates national policy, state‑level enforcement, and cutting‑edge technology to confront emerging threats.