The Computer Emergency Response Team (CERT) on October 01, 2024, notified the key recommendations for CERT-In empanelled auditing organisations to contribute in & enhance the cybersecurity audit ecosystem.
The following recommendations have been stated:
• Auditing organizations should include an executive summary for board members & top management in all audit reports, translating the technical findings into relevant business risks and the overall security posture of the audited application or infrastructure.
• Auditee organizations may arrange in-person sessions for their clients or targeted sector on audit awareness, covering the audit fundamentals of information security audits such as audit scope, outcomes, limitations of audits, secure development practices and CERT-In initiatives, directions & guidelines on cybersecurity.
• Organisation must include the verification of compliance to CERT-In direction "Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet" dated April 28, 2022 in every audit assignment and findings along with relevant evidences should be included in the audit report. Organisations may refer the method of verification document "Method of verifications to compliance with CERT-In Directions issued on April 28, 2022" shared over email and also available on CERT-In website at https://cert-in.org.in/PDF/Methods_of_Verification.pdf.
• During application audits, auditing organisation should check the compliance of the guidelines document "Guidelines for Secure Application Design, Development, Implementation & Operations" issued by CERT-In and available on CERT-In website and findings along with relevant evidences should be included in the audit report.
• The limited list such as top 10, top 25 should be avoided as audit criteria. Audit should include discovery of all known vulnerabilities based on the comprehensive standards/frameworks like ISO/IEC, Cyber Security Audit Baseline Requirements, Open Source Security Testing Methodology Manual (OSSTMM3), OWASP Web Security Testing Guide along with applicable regulatory framework and directions & guidelines issued by agencies such as CERT-In.
• It is recommended that audit-related artefacts, such as hash values, versions, and timestamps should be captured & included in the audit certificate and reports.
• In system or compliance audits, evidences demonstrating both compliance and non-compliance with controls should be captured and documented by the auditing organization in the audit report.
• Audit report should be of highest standard and comprehensive to include all details of audit process, detailed scope, duration of audit, methodologies/standard used, tools, manual process, findings, prioritization, sampling decisions, manpower involved, exemptions, limitations and other constraints.
• Risk treatment techniques such as retain, avoid, transfer and reduce for any reported vulnerabilities or observations in the application or infrastructure, must be authorized & accepted by the head of the auditee organizatio