What CERT-In Actually Mandates on Logging
CERT-In Directions 2022 (Direction 6) explicitly states that all service providers, intermediaries, data centres, and government organisations must maintain "logs of all their ICT systems for a rolling period of 180 days" and that these logs must be maintained "within the Indian jurisdiction." Critically, NTP synchronisation is also mandated — all system clocks must be set to the Indian Standard Time (IST) zone, synchronised with the National Physical Laboratory (NPL) time server or a replica, ensuring accurate timestamps across all log sources. ISO/IEC 27001:2022 Annex A.8.15 requires logging of activities, exceptions, and events that can assist in future investigations. The RBI Cybersecurity Framework requires real-time log monitoring for BFSI organisations.
What Must Be Logged — CERT-In Mandatory Sources
| Log Source | What to Log | Minimum Retention |
|---|---|---|
| Firewalls / NGFWs | All allowed + denied connections, IPS alerts | 180 days |
| Active Directory / IAM | Logon/logoff, failed auth, privilege changes, account creation/deletion | 180 days |
| Servers (OS) | System events, service starts/stops, privilege use, file access (critical paths) | 180 days |
| DNS Servers | All query logs (source IP, queried domain, response) | 180 days |
| Web / Email Gateways | URL access logs, email routing, malware detections, DLP events | 180 days |
| Applications (critical) | User activity, transactions, API calls, errors | 180 days |
SIEM Architecture for Indian Enterprises
A Security Information and Event Management (SIEM) platform collects logs from all sources, normalises them into a common format, correlates events across sources to detect multi-stage attacks, and provides alerting, dashboards, and reporting for both operational and compliance use. For Indian mid-market enterprises, the practical SIEM options include: Elastic SIEM (open source, powerful, requires expertise), Wazuh (open source, CERT-In use-case community), Microsoft Sentinel (cloud-native, strong AD integration, data residency options), and commercial options like IBM QRadar or Splunk. For CERT-In data residency compliance, choose a SIEM that stores log data within Indian data centre regions.
NTP Synchronisation — The Overlooked CERT-In Requirement
CERT-In mandates that all ICT systems synchronise their clocks with the NPL Stratum-1 NTP server at time.nplindia.org or equivalent stratum-2 servers. Misconfigured system clocks make log correlation forensically useless — events appear out of sequence or with wrong timestamps. Configure all servers, network devices, and endpoints to synchronise NTP via a hierarchy that traces back to the NPL source. Verify NTP configuration as part of every server hardening check.
Log Management Assessed On-Site by InfraVeritas 360
Every IGaaS engagement assesses log coverage, SIEM architecture, retention configuration, and NTP synchronisation — producing a CERT-In compliance gap report with specific remediation actions.
Assess Your Log Management →