(1) During the course of interaction with user community and discharging its functions CERT-In may collect and analyse information relating to cyber security incidents from individuals, organisations and computer resource. CERT- In shall follow applicable legal restrictions, orders of competent Indian courts and ethical practices with regard to disclosure of information and shall maintain reasonable controls and internal checks to maintain confidentiality of such information.
(2) CERT-In shall not disclose any information which may lead to identification of individual, group of individuals or organizations affected by cyber security incidents without their explicit written consent or orders of Indian competent courts.' CERT-In shall take appropriate measures to protect such information and shall also not disclose the identity of individuals, group of individuals and organisations sharing the information and reporting cyber security incidents to it, without their explicit written consent or orders of Indian competent courts.
(3) CERT-In may share or disclose the general trends of cyber security incidents, cyber security breaches freely to assist general public for the purpose of resolving and preventing cyber security incidents and promoting awareness.
(4) Save as provided in sub-rules (1), (2) and (3) of Rule 13, it may be necessary or expedient so to do, for CERT-In to disclose all relevant information to the stakeholders, in the interest of sovereignty or integrity of India, defence of India, security of the State, friendly relations with foreign States or public order or for preventing incitement to the commission of an offence relating to cognizable offences or enhancing cyber security in the country.