Cyber Security Incident Response Team (CSIRT)
The dedicated team responsible for detecting, containing, eradicating and recovering from cyber security incidents, mandated by most Indian sectoral cyber frameworks.
A Cyber Security Incident Response Team (CSIRT) is a formally constituted team within an organisation with the responsibility to detect cyber security incidents, contain their impact, eradicate the root cause, recover normal operations and coordinate with external stakeholders including CERT-In and sectoral regulators. Team composition typically spans information security, IT operations, legal, communications and business continuity.
RBI Master Direction on IT Governance 2023 requires every regulated entity to establish a CSIRT with clearly defined roles, responsibilities and escalation matrices. SEBI CSCRF imposes an equivalent requirement on regulated market intermediaries. The CERT-In Directions dated 28 April 2022 do not use the CSIRT term, but the 6-hour incident reporting SLA is impossible to meet without a functional CSIRT.
A working CSIRT is more than a policy document. It requires a rehearsed playbook, an on-call rota, pre-agreed communication channels (out-of-band from potentially compromised email or Slack), pre-drafted external notification templates, and periodic tabletop exercises. The dcomply Academy RBI Cybersecurity Practitioner and SEBI CSCRF Practitioner certifications include working CSIRT templates.