CERT-In Issues Comprehensive Cyber Security Audit Guidelines
Why in the news
The Indian Computer Emergency Response Team (CERT-In) has issued comprehensive cyber security audit policy guidelines, described as a landmark directive for organisations that run digital systems.
Key facts
- Issuer: CERT-In.
- Coverage: public and private organisations managing digital systems.
- Requirement: comprehensive third-party cyber security audits every year.
- The audit cycle covers planning, scoping, execution, reporting and follow-up.
- Approach is risk-based and domain-specific, aligned with ISO/IEC 27001 standards.
| Aspect | Detail |
|---|---|
| Frequency | At least once a year |
| Stricter schedules | May be set by sectoral regulators |
| Auditors | Empanelled auditors and internal teams |
| After the audit | Remediation is mandatory |
About the push
The guidelines call on empanelled auditors and in-house teams to sharpen skills for spotting technical flaws and governance gaps. The aim is to move organisations from reactive compliance towards proactive resilience, in line with wider digital public infrastructure and cyber security goals.
Exam angle
- Remember the issuer, CERT-In, and the key rule: annual third-party audits.
- ISO/IEC 27001 is the standard the approach is aligned with.
- Useful for cyber security and IT governance questions in banking exams.