What are the CERT-In log retention requirements and where must logs live?
CERT-In mandates that all service providers, intermediaries, data centres, body corporates, and Government organisations must enable and securely maintain logs of all their Information and Communication Technology (ICT) systems for a rolling period of 180 days. These logs must be provided to CERT-In upon request or when reporting a cyber incident. The directive emphasises secure maintenance but does not explicitly specify a geographic location for log storage, leaving the responsibility for secure and accessible storage with the organisation.
Practitioners must understand that "all ICT systems" encompasses a broad range of assets, including network devices, servers, applications, and security tools. Implementing comprehensive logging across such diverse environments requires robust log management solutions capable of collecting, normalising, and storing vast quantities of data. The "rolling period of 180 days" means organisations must continuously manage log volume and archiving, ensuring older logs are retained up to the 180-day mark while new logs are ingested. Failure to maintain complete and unalterable logs can severely impede incident response capabilities, forensic investigations, and the ability to demonstrate compliance during audits or regulatory inquiries.
While the CERT-In directive specifies secure maintenance, it does not explicitly mandate that logs must reside within India's geographical borders. However, for entities operating within India, storing logs locally or in a cloud region within India is often a practical and prudent measure to address data sovereignty concerns, reduce latency for access during incidents, and simplify legal or regulatory access requests. Organisations must ensure the integrity and availability of these logs, protecting them from unauthorised modification or deletion, which typically involves implementing strong access controls, encryption, and regular backups. Non-compliance with these logging requirements can lead to significant regulatory scrutiny and potential penalties.
Sources
- Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for a class of subscribers, service providers, body corporate and Government organisations, CERT-In, 28 April 2022, Clause (1)(c)