How to Use This Checklist
This checklist covers the 50 foundation-layer controls that every CERT-In, ISO/IEC 27001:2022, or RBI audit will assess. For each control, mark your status: ✅ Implemented and documented, ⚠️ Partially implemented, ❌ Not implemented. Any ❌ or ⚠️ is a finding. Prioritise ❌ items in Critical and Access Control categories first — these are the highest-risk gaps and the ones most likely to trigger regulatory action. Use the results to build a remediation roadmap before your formal audit begins.
Section 1: Asset Management (Controls 1–8)
| # | Control | Framework |
|---|---|---|
| 1 | Complete hardware asset inventory maintained and current | CIS C1, ISO A.5.9 |
| 2 | Software inventory with licence and EOL status tracked | CIS C2, ISO A.5.9 |
| 3 | All assets classified by criticality and data sensitivity | ISO A.5.12, DPDP |
| 4 | Named owner assigned to every critical asset | ISO A.5.10 |
| 5 | Network discovery scan performed in last 30 days | CIS C1, CERT-In |
| 6 | Unauthorised device detection alerts are active | CIS C1 |
| 7 | Decommissioned assets removed from inventory and securely disposed | ISO A.7.14, DPDP |
| 8 | Storage media disposal certificates on file for last 12 months | ISO A.7.14 |
Section 2: Access Control (Controls 9–18)
| # | Control | Framework |
|---|---|---|
| 9 | Formal access provisioning process with manager approval | ISO A.5.18, CERT-In |
| 10 | Quarterly access review completed with documented evidence | ISO A.5.18, RBI |
| 11 | MFA enforced on all privileged accounts | CERT-In, RBI |
| 12 | MFA enforced on all remote access (VPN, RDP, SSH) | CERT-In mandatory |
| 13 | No shared service accounts — all have unique identities and owners | ISO A.5.16 |
| 14 | Formal offboarding disables accounts within 1 business day | ISO A.5.18 |
| 15 | Privileged Access Management (PAM) tool deployed | ISO A.8.2, RBI |
| 16 | Admin accounts separate from standard user accounts | CIS C5, CERT-In |
| 17 | Password policy: complexity, minimum length, history enforced via GPO/LDAP | CIS L1 |
| 18 | Account lockout policy configured (max 5 failed attempts) | CIS L1, CERT-In |
Sections 3–6: Patch, Network, Backup, Documentation (Controls 19–50)
| # | Control | Category |
|---|---|---|
| 19 | Documented patch management policy with SLA timelines | Patch Mgmt |
| 20 | Vulnerability scan completed in last 30 days (all critical assets) | Patch Mgmt |
| 21 | Zero critical/high CVEs older than 15 days on internet-facing systems | Patch Mgmt |
| 22 | Patch exception register with risk acceptance and owner sign-off | Patch Mgmt |
| 23 | No flat network — minimum VLAN segmentation in place | Network |
| 24 | Dedicated management VLAN for network device access | Network |
| 25 | All network device default credentials changed and documented | Network |
| 26 | Firewall rules reviewed in last 90 days with documented sign-off | Network |
| 27 | All denied firewall traffic logged (180-day retention) | Network |
| 28 | Legacy protocols disabled: SMBv1, TLS 1.0/1.1, Telnet | Network |
| 29 | DNS logging enabled and forwarded to SIEM | Network |
| 30 | DHCP snooping enabled on all managed switches | Network |
| 31 | RTO and RPO defined and board-approved for all critical systems | Backup/DR |
| 32 | 3-2-1 backup architecture implemented for all critical data | Backup/DR |
| 33 | Restore test completed in last 90 days with documented results | Backup/DR |
| 34 | Offsite/immutable backup copy exists and tested | Backup/DR |
| 35 | Annual DR failover test completed with RTO evidence | Backup/DR |
| 36 | Full-disk encryption enabled on all laptops and mobile devices | Endpoint |
| 37 | EDR deployed on 100% of managed endpoints | Endpoint |
| 38 | USB storage blocked or controlled via policy | Endpoint |
| 39 | Mobile devices enrolled in MDM with remote-wipe enabled | Endpoint |
| 40 | Server CIS Benchmark score ≥70% on critical servers | Hardening |
| 41 | Server room access log maintained (minimum 12-month retention) | Physical |
| 42 | CCTV covers all server room entry points (90-day retention) | Physical |
| 43 | Information Security Policy — current version, board-approved | Documentation |
| 44 | Incident Response Procedure documented and tested | Documentation |
| 45 | Change Management Procedure with CAB records last 6 months | Documentation |
| 46 | Risk Assessment completed in last 12 months with treatment plan | Documentation |
| 47 | Third-party vendor security assessment completed for critical vendors | Vendor |
| 48 | Security awareness training completed by all staff — evidence on file | Training |
| 49 | SIEM deployed with 180-day log retention across all critical systems | Monitoring |
| 50 | CERT-In incident reporting procedure ready — contacts registered | Incident Response |
Let InfraVeritas 360 Run This Checklist For You — On-Site
Our IGaaS engine assesses all 50 of these foundation controls on-site, with evidence collection, gap analysis, and a board-ready report in 48 hours — mapped to CERT-In, ISO 27001, DPDP, and RBI.
Start the Foundation Assessment →