CERT-In Issues New Cybersecurity Audit Guidelines

  • 29 Jul 2025

In July 2025, the Indian Computer Emergency Response Team (CERT-In) released its Comprehensive Cyber Security Audit Policy Guidelines, aiming to revolutionize the way cybersecurity audits are conducted across India’s public and private sectors.

  • The guidelines provide a complete audit lifecycle framework—from planning and execution to reporting and post-audit follow-up—enhancing the consistency and depth of cybersecurity evaluations across organizations.
  • The policy stresses risk-based audits, continuous monitoring, and alignment with global standards such as ISO/IEC 27001.
  • It emphasizes that audits should be strategic tools for identifying vulnerabilities and governance failures, rather than mere compliance exercises or checkbox formalities.
  • The guidelines push empanelled auditors and internal audit teams to upgrade their skills and address both technical flaws and governance oversights during assessments.
  • It encourages collaboration between Chief Information Security Officers (CISOs), IT teams, auditors, and regulators, mandating remediation planning and data-driven reporting as essential components.