Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

CERT-In readiness gaps: what audit evidence do teams still miss?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: The main gap in CERT-In readiness is proof, not control existence, according to AccuKnox: teams often have the underlying security measures but lack dated records, consolidated evidence, and an audit-ready package for six compliance pillars. That shifts the problem from implementation to governance, where identity, access, runtime, and incident evidence must be demonstrable, not assumed.

NHIMG editorial — based on content published by AccuKnox: The CERT-In Readiness Checklist

Questions worth separating out

Q: What breaks when security controls cannot be evidenced during an audit?

A: When controls cannot be evidenced, the organisation loses the ability to prove continuity, ownership, and closure.

Q: Why do identity and privileged access controls fail compliance checks so often?

A: They often fail because lifecycle evidence is split across systems.

Q: How do security teams know if their readiness programme is actually working?

A: Look for alignment across the SSP, POA&M, evidence library, and live configurations.

Practitioner guidance

  • Consolidate audit evidence by control pillar Build a single evidence package for each pillar that includes timestamps, approvals, logs, and remediation closure records so a reviewer can trace control operation without manual reconstruction.
  • Link identity records to privileged-session proof Attach access reviews, credential rotation events, and privileged-session logs to the specific systems and accounts they cover, then retain them in a retrievable format.
  • Map AI-enabled services to documented risk factors For each AI-enabled service, record data sensitivity, autonomy, connectivity, and blast radius so the inventory supports both assurance and governance review.

What's in the full article

AccuKnox's full checklist covers the operational detail this post intentionally leaves for the source:

  • The full six-pillar self-assessment structure with checkboxes for continuous assessment, release validation, and incident assurance
  • The specific evidence artefacts expected under each pillar, including dated reports, closure records, and management commitments
  • The six-hour reporting workflow and the five Section 7 deliverables that the checklist maps to CERT-In expectations
  • The exact guidance on where to start when most of the checklist remains unchecked

👉 Read AccuKnox's CERT-In readiness checklist for SaaS and technology providers →

CERT-In readiness gaps: what audit evidence do teams still miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Evidence readiness is becoming the real control plane. The checklist reflects a broader shift in security governance: compliance teams no longer just ask whether a control exists, they ask whether it can be demonstrated cleanly under pressure. That puts access reviews, session records, and closure timestamps on the same footing as technical control design. For identity programmes, the practitioner conclusion is simple: if it cannot be evidenced, it will not count.

A question worth separating out:

Q: Who is accountable when evidence is missing even though controls were implemented?

A: Accountability usually sits with the control owner and the programme that defines evidence retention, review cadence, and escalation paths. Regulators rarely accept the argument that a control existed but the proof was lost. Governance teams should assign ownership for evidence as explicitly as they assign ownership for the control itself.

👉 Read our full editorial: CERT-In readiness is mostly an evidence problem, not a control problem



   
ReplyQuote
Share: