Adaptive
CERT-In Compliance Checklist for Indian Businesses
Pages
2
Time to read
4 mins
Publication
Language
English
Pages
2
Time to read
4 mins
Publication
Language
English
This document is a checklist designed for Indian businesses to ensure compliance with CERT-In Cyber Security Directions and Comprehensive Cyber Security Audit Policy Guidelines. It outlines mandatory requirements such as reporting cyber incidents to CERT-In within six hours, retaining ICT system logs for 180 days, and designating a point of contact for CERT-In. The checklist includes various items categorized as mandatory or recommended, detailing the responsibilities of different roles within an organization, such as the Chief Information Security Officer (CISO) and IT departments. Each item specifies the evidence required to demonstrate compliance, such as policy documents, risk assessments, and security testing reports. The document also emphasizes the importance of maintaining proper documentation and preparedness for audits, including having an evidence repository and conducting regular training and simulations. The guidelines are based on the latest regulations and standards applicable to organizations in India.