Skip to content

CERT-In Issues Comprehensive Cyber Security Audit Guidelines

28 July 20251 min read
SCIENCE & TECHNOLOGYCERT-In IssuesComprehensiveCyber SecurityAudit Guidelines28 July 2025safalsetu.com

Why in the news

The Indian Computer Emergency Response Team (CERT-In) has issued comprehensive cyber security audit policy guidelines, described as a landmark directive for organisations that run digital systems.

Key facts

  • Issuer: CERT-In.
  • Coverage: public and private organisations managing digital systems.
  • Requirement: comprehensive third-party cyber security audits every year.
  • The audit cycle covers planning, scoping, execution, reporting and follow-up.
  • Approach is risk-based and domain-specific, aligned with ISO/IEC 27001 standards.
AspectDetail
FrequencyAt least once a year
Stricter schedulesMay be set by sectoral regulators
AuditorsEmpanelled auditors and internal teams
After the auditRemediation is mandatory

About the push

The guidelines call on empanelled auditors and in-house teams to sharpen skills for spotting technical flaws and governance gaps. The aim is to move organisations from reactive compliance towards proactive resilience, in line with wider digital public infrastructure and cyber security goals.

Exam angle

  • Remember the issuer, CERT-In, and the key rule: annual third-party audits.
  • ISO/IEC 27001 is the standard the approach is aligned with.
  • Useful for cyber security and IT governance questions in banking exams.

Test yourself

1. Which body issued the comprehensive cyber security audit policy guidelines?

The guidelines were introduced by CERT-In.

2. How often must organisations undergo third-party cyber security audits under the guidelines?

Comprehensive third-party audits are required every year, at minimum.

3. The audit approach is aligned with which international standard?

The notes say it follows ISO/IEC 27001 aligned practices.

Sources: GKToday: Cyber security audit policy guidelines, GKToday daily archive 28 Jul 2025