Cert-in, which is under the electronics and IT ministry, is the national nodal agency to secure Indian cyber space. It alerts about cyber security incidents and threats, provides emergency measures to handle cyber threats and issues guidelines and advisories relating to security practices and reporting of cyber incidents.
The agency has empanelled around 90 organisations, including foreign companies like KPMG, PricewaterhouseCoopers and Indian companies with foreign partnerships, for the audit of IT systems.
"Since engaging non-Indian firms for auditing requirements by the government organisations and critical sections may involve exposing sensitive information to non-Indian persons/entities or having foreign links, the concerned government ministries/organisations should obtain NOC from MHA before engaging any non-Indian firm," the advisory note said.
CERT-in has asked organisations to ensure that every audit firm and its auditors engaged should sign non-disclosure agreements before being allowed to commence the cyber security audit work.
"To the extent feasible, it may be ensured that any data collected during the auditing work and report prepared thereof is not allowed to be taken out of the government premises by such auditors or firms," the note said.
The cyber security watchdog has asked organisations to exercise caution even while engaging audit firms empanelled by it.
Business Standard has always strived hard to provide up-to-date information and commentary on developments that are of interest to you and have wider political and economic implications for the country and the world. Your encouragement and constant feedback on how to improve our offering have only made our resolve and commitment to these ideals stronger. Even during these difficult times arising out of Covid-19, we continue to remain committed to keeping you informed and updated with credible news, authoritative views and incisive commentary on topical issues of relevance.
We, however, have a request.
As we battle the economic impact of the pandemic, we need your support even more, so that we can continue to offer you more quality content. Our subscription model has seen an encouraging response from many of you, who have subscribed to our online content. More subscription to our online content can only help us achieve the goals of offering you even better and more relevant content. We believe in free, fair and credible journalism. Your support through more subscriptions can help us practise the journalism to which we are committed.
Support quality journalism and subscribe to Business Standard.