India CERT-In Cyber Security Directions 2022
CERT-In Audit + Drills + Training

India CERT-In Cyber Security Directions 2022 CERTIN-Audit-Drills-Training-AwarenessProgram-CERTInExercises-CISO: CERT-In Audit + Cyber Security Drills + Training + Awareness + CERT-In Cyber Exercises + CISO + Information Security Auditor Empanelment

Audit + Drills + Training operationalise the Directions through ongoing assurance + cyber preparedness. (1) CERT-In Cyber Security Audit: organisations should undergo periodic cyber security audit by CERT-In Empanelled Information Security Auditing Organisations (currently 100+ empanelled auditors including STQC + ICERT-Cert + Deloitte + KPMG + EY + PwC + IBM Security + Wipro + TCS + Infosys + L&T Infotech and others) + initial audit + periodic recurring audit (typically annual) + post-incident audit + Vulnerability Assessment and Penetration Testing (VAPT) + Source Code Audit + Web Application Audit + Mobile App Audit + Cloud Audit + scope coverage per CERT-In Audit Guidelines + audit report submission + remediation tracking + RBI/SEBI/IRDAI sectoral audit alignment. (2) CERT-In Cyber Security Drills/Exercises: organisations participate in CERT-In coordinated national cyber exercises + sectoral drills (Power Cyber + BFSI Cyber + Healthcare Cyber + Telecom Cyber) + tabletop exercises + technical exercises + Red-Team Blue-Team + national-level coordination tests + cyber attack simulation + response time measurement + after-action review + improvement plans. (3) Cyber Security Awareness and Training: structured awareness programs for employees + cyber hygiene + phishing simulations + role-based training for IT + security + executives + Board + crisis communication + integration with CERT-In Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre) + Cyber Crisis Management Plan (CCMP) + national cyber awareness month + Awareness Campaigns. (4) CISO Role: appointed Chief Information Security Officer (CISO) + reporting to CEO or Board + accountability for CERT-In compliance + Indian Empanelled CISO Certification + ISO 27001 + CISSP/CISM + experience requirements + ongoing professional development. (5) Indian National Cybersecurity Strategy alignment + integration with broader India Cyber Resilience posture. (6) Cyber Insurance + Cyber Risk Management + Cyber Maturity Models (NCMM + NIST CSF + CIS Controls). Coordinates with CERT-In Empanelled Auditors list + CERT-In Cyber Swachhta Kendra (cyberswachhtakendra.gov.in) + Cyber Crisis Management Plan (CCMP) + National Critical Information Infrastructure Protection Centre (NCIIPC) + Indian Cyber Crime Coordination Centre (I4C) + Cyber Surakshit Bharat Initiative + DSCI Data Security Council of India + NASSCOM CoE Cybersecurity + RBI Cyber Hygiene Index + SEBI System Audit Framework + IRDAI Information and Cyber Security Guidelines. CERT-In Audit + Drills + Training applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.