India Unveils Comprehensive Cyber Security Audit Policy Guidelines

In a decisive move to strengthen India's digital security framework, the Indian Computer Emergency Response Team (CERT-In) has released the Comprehensive Cyber Security Audit Policy Guidelines (Version 1.0, July 2025). This policy aims to introduce uniformity, clarity, and accountability in audits across government, critical infrastructure, and private enterprises, transforming them from routine exercises to reliable benchmarks for risk reduction.

Key Takeaways:

  • The guidelines define a structured audit process that spans planning, scope definition, technical assessments, asset discovery, vulnerability scanning, and evidence gathering, ensuring that audits move beyond a box-ticking approach.
  • The framework applies to a broad spectrum of entities, including operators of critical infrastructure such as power grids, transport, and healthcare systems, along with financial institutions, IT service providers, data centres, cloud platforms, and government departments.
  • Audits must be conducted by CERT-In empanelled professionals, ensuring quality and consistency in assessments, and vulnerabilities or control gaps must be ranked as critical, high, medium, or low, with corresponding timelines for mitigation.
  • The guidelines introduce a scoring model such as CVSS combined with EPSS to enable accurate prioritisation of vulnerabilities most likely to be exploited.
  • The policy suggests using CERT-In-approved templates for planning, documentation, and evidence submission, emphasizing traceability and accountability in audits.
  • Independence of auditors is a key feature, aimed at removing conflicts of interest and ensuring transparent, trustworthy findings.
  • The guidelines demand immediate alignment of internal programmes with the new audit model, with organisations required to map existing procedures against the CERT-In structure, train audit teams and vendors on updated requirements, and identify gaps in documentation and evidence readiness.

Statistics:

  • The guidelines apply to a broad spectrum of entities, including operators of critical infrastructure, financial institutions, IT service providers, data centres, cloud platforms, and government departments.
  • Auditors must conduct vulnerability or control gap rankings as critical, high, medium, or low, with corresponding timelines for mitigation.
  • The guidelines introduce a scoring model such as CVSS combined with EPSS to enable accurate prioritisation of vulnerabilities most likely to be exploited.

Sources:

  • "Comprehensive Cyber Security Audit Policy Guidelines (Version 1.0, July 2025)" by Indian Computer Emergency Response Team (CERT-In)
  • Published by HT Digital Content Services with permission from Voice & Data.