Empanelment of IT Security Auditing Organisations by CERT-In, v6, April 2019
Empanelment of IT Security Auditing Organisations by CERT-In, v6, April 2019
No. 3(15)/2004-CERT-In
Government of India
Ministry of Electronics and Information Technology
Indian Computer Emergency Response Team (CERT-In)
Electronics Niketan, CGO Complex, Lodhi Road, New Delhi- 110 003
Note:
a. Review of auditee’s existing IT Security Policy and controls for their adequacy as per
the best practices vis--à-vis established IT Security frameworks outlined in standards
such as COBIT, cyber security framework, ITIL, ISO27001 etc.
b. ‘IT Security Audit’ may involve a combination of the following:
i. Network Mapping
ii. Vulnerability assessment
iii. Exploitation of the vulnerabilities
Note 1: Process audit experience in ‘Scalable Monitoring Platform for the Internet
“Auditing Man-day” shall mean IT Security auditing effort (both on-site as well as off-
site) of minimum 8 hours, excluding breaks, by a person with suitable IT Security auditing
related qualification such as CISSP, ISMS Lead Assessor, CISM, CISA, ISA or any other
formal security auditing related qualification.
Empanelled IT Security auditing organisations may please note that their continued
empanelment status depends on the quality of IT Security auditing service rendered by
them and extent of user satisfaction as may be reflected in their feedback to CERT-In. All
the empanelled IT Security auditing organisations are required to send bi-monthly report to
CERT-In for the list of IT Security auditing work in hand / completed with duration (from
date – to date) for over all assessment and review of the status of IT Security compliance
in the country. For the purpose of monitoring the quality of service, CERT-In may choose to
-
• Carryout sample analysis of the IT Security auditing work
• Depute its expert representatives to witness an IT Security audit when the audit
process is underway.
• Seek the opinion of the user auditee organisations.
• Adopt any other means as deemed necessary.
The organisations, already providing auditing services in the area of IT Security, as well as
desirous of being empanelled by CERT-In as an IT Security auditing organisation, should submit
the requisite information in the prescribed format, as given in the document “Application Form
for empanelment of IT Security Auditing Organisations by CERT-In”. The applicant organisation
will submit its application to CERT-In in an envelope, duly superscribed “Request for
empanelment of IT Security Auditing Organisations” to the address given below:
Empanelment Group,
Indian Computer Emergency Response Team (CERT-In),
Ministry of Electronics and Information Technology,
Electronics Niketan, 6 C.G.O Complex,
Lodhi Road, New Delhi -110003
1. A duly constituted Technical Evaluation Committee (TEC) will evaluate the applicant
organisations based on the essential criteria in documentation round. If necessary,
applicants may be called for presentation to the TEC.
2. CERT-In shall test the vulnerability assessment and penetration testing capability of
organisations through the practical skills tests.
3. CERT-In will publish the panel of successfull IT Security auditing organisation on its
website.
4. The format of the IT Security audit report and the conditions of empanelment will also be
communicated to auditee organisation. An auditee organisation will be free to choose any
of the IT Security auditing organisations on the panel. CERT-In will have no role in that
context.
5. It may be noted that CERT-In will not award any IT Security auditing assignment to any of the IT
Security Auditors. An Auditee will have a direct relationship with an IT Security Auditing
organisation selected by him from the Panel of IT Security Auditing organisations. However, CERT-
In will monitor the quality of IT Security audit to ensure that it is in compliance with international
best practices. From time to time CERT-In may choose to send its expert to an Auditee site when
an IT Security audit is underway.
Step-1: Submission of Application Form (in the prescribed format) for empanelment for the
block 2016-2019 along with the following Annexures:
On assessment & verification of the documents submitted, the organization will be declared as
successful or unsuccessful in step 1. Only organizations that are successful in Step 1 will be
considered for step 2
Step-2: The organizations will be given two virtual images in DVD having some applications
installed with the known vulnerabilities and possible penetrations built for the off-line
in-house practical skills test, which they can test at their premises and should report
at least 90% of known set of vulnerabilities and successful penetrations. Organization
scoring 90% or more, on the basis of assessment of report, will be considered for
Step 3. The organization will be given maximum two attempts to appear in offline
PST.
Step 3: On being successful in Step 2, the qualified organizations will have to take an on-line
practical skills test i.e. VA/PT PST and target a test-bed of known vulnerabilities and
possible penetrations. Challenges will be declared in real time over IRC channel to the
participating organizations. Organizations will be required to submit VA & PT report to
CERT-In. Organization scoring 90% or more , on the basis of assessment of report, will
be considered for step-4 i.e. Personal Interaction Session . The organization will be
given maximum two attempts to appear in VA/PT PST.
Step-4: For the purpose of Personal Interaction Session, the TEC will meet in Delhi as well as
in Bangalore to interact with the organizations who have qualified in step 3. This may
include]
Face to face meeting / Interaction with auditor team of suitable size. The team must
have persons from the technical personnel informed to CERT-In as per the information
form submitted to CERT-In.
Interpretation of vulnerabilities and means of exploit by the auditor organization
Technical Competence verification at CERT-In or IISc Bangalore , as deemed necessary
7. The assessment of the reported vulnerabilities and successful penetrations will be done against the
8. An organization, clearing all the required steps of empanelment, will be eligible for empanelment
subject to background verification and clearance of the organization and its technical persons
(mentioned in their application form submitted to CERT-In ).
9. Special round of practical skill test is envisaged for the empanelled auditors in case some
Complaint or reverse feedback on their technical competence and audit performance has been
received from auditee organization or any other circumstances where creditability of empanelled
auditors is suspected from technical point of view.
10. The empanelment will be valid for the block 2016-2019. All the empanelments will be valid up to
the same date during this time span and shall be eligible for renewal on the same date as per the
process as prescribed at that time.
11. CERT-In reserves its right to ask the organisations for online access to test bed either through the
static public IP at their premises, as submitted by the organisation, or from some other locations
like CERT-In, IISc and few other places, as selected by CERT-In. These places will be under direct
supervision / control of either officials from CERT-In or nominated by CERT-In.
12. After 2 (two) unsuccessful attempts in either offline in-house practical test or online VA/PT PST the
organisation may apply as a fresh candidate after cooling off period of one year.
13. For all future empanelments, Rs.5000/-will be charged at the time of application and renewal
thereafter.
14. CERT-In reserves the right to relax any qualifications for empanelment under exceptional
circumstances.
15. CERT-In reserves its right to empanel the IT Security auditing organisations subject to their
compliance to empanelment qualification criteria & guidelines and acceptance of terms and
conditions of empanelment.
16. CERT-In reserves its right to accept any application in part or full or reject any or all the
applications without assigning any reason.
17. CERT-In will not be a party to any commercial contract between an auditee organisation and a IT
Security Auditing Organisation.
19. Empanelled IT Security Auditing Organisations shall undertake to keep confidential all the
information that they have access to during the course of their actions.
20. Empanelled IT Security Auditing Organisations shall ensure adherence to applicable codes of
conduct and auditing standards with due professional care.
21. If any organisation, due to NDA between the auditing & auditee organisation, feels that it will be
difficult for them to submit the copy of the two IT Security audit reports, then, if requested, CERT-
In is ready to provide an undertaking for non-disclosure of the acquired information. So, such
arguments for not submitting the IT Security audit reports will not be accepted
23. Sanitisation / Masking of financial information only from the IT Security audit reports is acceptable.