CERT-In Issues New Cybersecurity Directions for VPN Providers and Cloud Service Providers
April 2022
This development highlighted CERT-In's enhanced regulatory powers under the IT Act amendments. The directions mandated VPN providers and cloud service providers to maintain logs of user activities and report cybersecurity incidents within six hours. This demonstrated the evolution of India's cybersecurity institutional framework from reactive incident response to proactive threat prevention through regulatory oversight. The controversy surrounding these directions also illustrated the ongoing tension between cybersecurity enforcement and privacy concerns, connecting to broader debates about institutional powers and their limits.
UPSC Angle: UPSC likely to test understanding of CERT-In's regulatory evolution, the balance between cybersecurity and privacy, and the institutional mechanisms for implementing cybersecurity policies.