Based on the non-compliance report as submitted by the concerned aforesaid officer under Rule 16 and such direction of the Review Committee under Rule 19, the Director General shall authorise an officer of CERT-In to file a complaint before the court as provided under sub-section (8) section 70B of the Act [F.No. 9(16)/2004-EC] R.K. GOYAL, Jt. Secy.
Printed by the Manager, Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054 Annexure Types of cyber security incidents need to be reported to CERT-In:
• Targeted scanning/probing of critical networks/systems • Compromise of critical systems/information • Unauthorised access of IT systems/data • Defacement of website or intrusion into a website and unauthorised changes such as inserting malicious code, links to external websites etc.
• Malicious code attacks such as spreading of virus/worm/Trojan/Botnets/Spyware • Attacks on servers such as Database. Mail and DNS and network devices such as Routers • Identity Theft, spoofing and phishing attacks • Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks • Attacks on Critical infrastructure. SCADA Systems and Wireless networks • Attacks on Applications such as E-Governance, E-Commerce etc.