Legal, Regulatory & Governance Framework
Every technical finding you write later needs a peg to hang on — a law, rule, or standard that says what "good" looks like. This module gives you that vocabulary in plain language first, then the citation you'd actually put in a report.
applicable Legal Framework: applicable cyber law
The Information Technology Act, 2000 (amended 2008) is applicable primary cyber law. Think of it as the law that first said "things you do with computers and data are legally real" — electronic records and digital signatures are legally valid, hacking and data theft are crimes, and the organisation has named bodies (official incident-response service, critical-infrastructure coordination body) to defend the country's critical digital systems. Everything else in this module either comes from this Act or sits alongside it.
As an auditor, you don't need to memorise the whole Act. You need the handful of sections that explain why certain things you'll examine exist at all:
| Section | What it plainly says | Why you care as an auditor |
|---|---|---|
| 43A | A company handling sensitive personal data must use "reasonable security practices" — if it doesn't, and someone is harmed, it can be made to pay damages. | This is the legal root of "reasonable security practices" — your audit is one way of testing whether that standard is actually met. |
| 66 / 66B–66F | Defines computer-related offences: hacking, identity theft, cyberterrorism, etc. | Explains why incidents you find may need to be reported to police/official incident-response service, not just fixed quietly. |
| 69 / 69A | Organisation can order interception of communications or blocking of content/access, under defined procedures. | Relevant context if an entity references "lawful intercept" capability in telecom/ISP-adjacent systems. |
| 70 | Organisation can declare any computer resource a "protected system" — unauthorised access becomes a serious offence. | Some of the systems you audit (e.g. core banking, power grid SCADA) may be formally notified as protected systems — ask. |
| 70A | Creates the legal basis for the National Critical Information Infrastructure Protection Centre (critical-infrastructure coordination body). | critical-infrastructure coordination body, a unit of NTRO created by gazette notification in January 2014, identifies and protects "Critical Information Infrastructure" (CII) — see Part 5.9 for what that means for OT audits. |
| 70B | Creates official incident-response service (applicable Computer Emergency Response Team) and gives it power to issue binding directions on cybersecurity practice, incident reporting, and response. | This is the section behind the 6-hour incident reporting rule below — one of the most operationally important rules you'll check compliance against. |
official incident-response service Directions & Incident Reporting
official incident-response service is applicable national "first responder" agency for cyber incidents — like a fire brigade for cyberattacks, except its main tool is information: collecting incident reports, issuing alerts, and telling organisations what they must do to be prepared. In April 2022, it issued binding "Directions" that significantly raised the bar on what every organisation operating in the applicable jurisdiction — including organisations — must do.
The official incident-response service Directions (dated 28 April 2022, issued under Section 70B(6), effective from 27 June 2022) are the single most-cited compliance instrument you will check during an audit. Five things to verify:
1. Six-hour incident reporting
Any of 20 specified categories of cyber incident (data breach, ransomware, defacement, unauthorised access, DDoS, and others) must be reported to official incident-response service within 6 hours of the entity noticing it or being notified of it. Audit test: ask for the last 3 reportable incidents and check the timestamp gap between detection and the official incident-response service report.
2. 180-day log retention
ICT system logs must be retained for at least 180 days, stored within the applicable jurisdiction. Audit test: check the log retention policy/configuration on the SIEM or log server and confirm actual retained history, not just the policy document.
3. Time synchronisation
Systems must sync clocks to the official Network Time Protocol (NTP) servers of relevant service provider or the National Physical Laboratory (NPL), or to NTP servers traceable to these sources. Audit test: check NTP configuration on a sample of servers — mismatched clocks make incident timelines unreliable evidence.
4. Designated point of contact
Entities must designate a point of contact to interface with official incident-response service. Audit test: ask who this person is — if no one can answer immediately, that's itself a finding.
5. Cooperation & data provision
Entities must provide requested information to official incident-response service within stipulated timeframes when asked. Audit test: review any recent official incident-response service information requests and how quickly they were answered.
Non-compliance with a official incident-response service direction currently carries a fine of up to ₹1 lakh and imprisonment of up to 1 year under Section 70B(7). The Jan Vishwas (Amendment of Provisions) Bill, 2023 proposes raising this fine to up to ₹1 crore — check the current status when you audit, as this is a moving target.
official incident-response service maintains a public list of "empanelled" organisations approved to conduct information security audits, including Vulnerability Assessment and Penetration Testing (VAPT). Many organisation procurement rules require VAPT to be performed by an empanelled auditor. Ask the entity: "Who performed your last VAPT, and were they official incident-response service empanelled at the time?" — and cross-check the name against the current list on incident-service.org.in.
Digital Personal Data Protection Act, 2023
The data-protection guidance is applicable first comprehensive personal data protection law — it says that anyone (the "Data Fiduciary") who collects or processes a person's personal data (the "Data Principal") must have their consent or a lawful reason, must keep that data reasonably secure, and must tell people — and the organisation — if it's breached. Organisation departments handling citizen data (which is nearly all of them) are squarely covered.
The Act was notified along with the Digital Personal Data Protection Rules, 2025 on 13 November 2025, and rolls out in three stages:
| Stage | Date | What kicks in |
|---|---|---|
| Stage 1 | From notification (late 2025 / early 2026) | The Data Protection Board of the applicable jurisdiction is established and begins operating. |
| Stage 2 | 13 November 2026 | Registration process for "Consent Managers" — intermediaries through whom individuals manage consent — comes into force. |
| Stage 3 | 13 May 2027 | Full compliance duties apply: notice requirements, security safeguards, breach notification, and the heavier obligations on "Significant Data Fiduciaries." |
Section 8(5) of the Act requires "reasonable security safeguards" to prevent personal data breaches — failure can draw a penalty of up to ₹250 crore per breach. Failing to notify the Data Protection Board and affected individuals of a breach can draw a separate penalty of up to ₹200 crore. As an auditor, build data protection readiness checks into Part 4.8 (Data Security & Privacy Audit) now — entities that wait until 2027 to start will fail.
applicable authority / relevant service provider / web safety guidance Policies
Beyond hard law, several policy instruments set the baseline you should expect organisation IT to meet:
Mandatory standards for organisation websites covering accessibility, content, security, and quality. In plain terms: it's the rulebook that says a organisation website has to actually work for everyone (including people using screen readers) and be built and hosted safely. Audit check: is the website web safety guidance-compliant and certified by STQC (Standardisation Testing and Quality Certification)?
relevant service provider's standardised platform for building organisation websites with security and accessibility baked in by default. In plain terms: rather than every department building its own website from scratch (and making its own security mistakes), this gives them a pre-secured template. Audit check: if a department built its own site instead of using S3WaaS, ask why, and apply extra scrutiny.
The Organisation of applicable cloud computing initiative. Cloud service providers must be empanelled by applicable authority to host organisation workloads. In plain terms: it's the organisation's approved list of "safe" cloud vendors. Audit check: is the cloud provider hosting this entity's systems on the current applicable authority empanelment list? See Part 4.7 for the full cloud audit walkthrough.
National Cyber Security Strategy
This is the organisation's big-picture plan for cybersecurity as a country — not a checklist you audit line by line, but context that explains why certain priorities (critical infrastructure protection, faster incident reporting, a bigger cybersecurity workforce) keep showing up in the rules you do audit against.
applicable first National Cyber Security Policy was issued in 2013; successive strategy efforts have built on it. Public reporting describes a National Cybersecurity Strategy with 2026 initiatives that emphasise tighter coordination between official incident-response service, state police cyber units, and sector regulators across banking, power, telecom, healthcare, and organisation services, alongside a target to build a cybersecurity workforce of 500,000+ professionals over five years. Treat the specific document as a fast-moving target — verify the current official text on incident-service.org.in or meity.gov.in before citing it in a formal report.
International Standards Crosswalk
applicable law tells you what is required. International standards tell you how to structure the controls that satisfy that requirement — and most organisations' own policies already reference one or more of these.
| Standard | In plain terms | Where you'll use it in this manual |
|---|---|---|
| ISO/IEC 27001:2022 | The internationally recognised checklist (technically a "management system standard") for running an information security programme — policies, risk assessment, controls, continual improvement. | Governance audit (Part 4.1); many organisations hold or are pursuing 27001 certification. |
| NIST Cybersecurity Framework (CSF) 2.0 | A US framework, widely used globally, organising everything an organisation does into six functions: Govern, Identify, Protect, Detect, Respond, Recover. Released February 2024; the "Govern" function was new, putting leadership accountability front and centre. | Useful structure for organising your overall audit programme (Part 3.7). |
| IEC 62443 | The standard family specifically for securing industrial automation and control systems (OT/ICS) — covers everything from organisational policy to specific technical requirements for control system components. | The backbone of Part 5 (OT/ICS/SCADA Audit). |
| COBIT 2019 | A framework for IT governance — how IT decisions get made, who's accountable, and how IT investment ties back to organisational goals. | Useful when assessing IT governance maturity (Part 4.1). |
| CIS Controls v8 | A prioritised, very practical list of defensive actions (e.g. "maintain an inventory of assets," "enforce MFA") ranked by impact — less theoretical than ISO 27001, good for quick benchmarking. | Used for configuration benchmarking in Part 6. |
Standards Mapping Tool
Pick a control area below to see how applicable legal requirements and international standards both address it — useful when you need to justify a finding from multiple angles.
cyber-safety law s.70B + official incident-response service Directions 2022: report within 6 hours, retain logs 180 days.
NIST CSF 2.0 "Respond" & "Recover" functions; ISO 27001 Annex A.5.24–5.28 (incident management).
cyber-safety law s.43A "reasonable security practices"; sector-specific rules often mandate MFA for privileged/financial access.
ISO 27001 Annex A.5.15–5.18 (access control); CIS Control 5 & 6 (account & access management).
data-protection guidance s.8(5) reasonable security safeguards; breach notification duties.
ISO 27701 (privacy extension to 27001); NIST CSF 2.0 "Protect" function, data security category.
cyber-safety law s.70 (protected systems); critical-infrastructure coordination body guidelines for notified Critical Information Infrastructure.
IEC 62443 series; NIST SP 800-82 Rev. 3 (Guide to OT Security).
Now that you know what "good" looks like on paper, Part 3 walks through how to actually plan and run an audit against it, step by step.