Skip to content

Cybersecurity Governance and Audit

Cybersecurity Governance and Audit: current Indian law, practical example, evidence checklist, risks and Finin2min summary.

Current-law position: As at 4 July 2026, institutional and enabling DPDP provisions are in force. Section 6(9) and section 27(1)(d) are scheduled for 13 November 2026; most substantive processing obligations are scheduled for 13 May 2027. Readiness work should distinguish current duties from future commencement.

Finin2min crux

Security needs governance, asset ownership, logging, testing, access control and incident exercises.

Legal anchors

IT Act, CERT-In and sectoral standards

The legal conclusion must be read with the current rules, notifications, portal instructions and binding judgments applicable to the event date.

How to analyse it

1. Applicability

Identify the person, activity, location, transaction date, threshold and regulator before applying the rule.

2. Statutory condition

Separate mandatory legal conditions from portal fields, industry practice and contractual preference.

3. Evidence

Link each conclusion to contemporaneous documents, approvals, filings and accounting records.

4. Action

Adopt control, evidence, exception and remediation registers.

Practical illustration

A board receives only a vulnerability count without business-risk context.

Decision point: Reperform the analysis if a material fact, date, location or legal status changes.

Evidence pack

What can go wrong?

Technical activity without accountable closure creates false assurance.

Additional risks include stale source use, incomplete authority, inconsistent portal data, weak contemporaneous evidence and failure to consider linked tax, accounting, contract or sector rules.

Finin2min action workflow

StageControlOutput
FactsFreeze transaction, party, date and locationFact sheet
LawRead Act, Rules and later instrumentsLegal map
EvidenceReconcile filings, books and documentsEvidence index
DecisionApprove, remediate, disclose or escalateSigned action note

Quick Q&A

What is the direct answer?

Security needs governance, asset ownership, logging, testing, access control and incident exercises.

Which provision should be opened first?

IT Act, CERT-In and sectoral standards

What should be preserved?

data inventory and processing register, privacy notice and consent artefacts, processor contracts and security schedules.

What is the immediate next step?

Adopt control, evidence, exception and remediation registers.

Official sources

Digital Personal Data Protection Act, 2023

MeitY

Open official source

Source reviewed 4 July 2026

Digital Personal Data Protection Rules, 2025

MeitY

Open official source

Source reviewed 4 July 2026

DPDP phased commencement notification, 13 November 2025

MeitY

Open official source

Source reviewed 4 July 2026

Data Protection Board establishment and appointment material

MeitY

Open official source

Source reviewed 4 July 2026

CERT-In directions under section 70B

CERT-In

Open official source

Source reviewed 4 July 2026

Information Technology Intermediary Guidelines and Digital Media Ethics Code Rules

MeitY

Open official source

Source reviewed 4 July 2026

Law, portal and source review: 4 July 2026. Case law and transaction-specific conditions should be checked immediately before professional reliance.