Which CERT-In direction mandates VPN service providers to maintain user logs for 180 days?
- Direction 12
- Direction 20
- Direction 44
- Direction 66
Answer: Direction 20
CERT-In Direction 20 (April 2022) requires service providers including VPNs to maintain logs of customer registration and usage for 180 days, report cyber incidents within 6 hours, and synchronize with NTP. Aimed at enhancing incident response and law enforcement capabilities. Important for cybersecurity compliance questions.