IT Infrastructure Foundation Audit Checklist: 50 Controls Before Any Compliance Review

By Arjun Mehta · 12 May 2026

How to Use This Checklist

This checklist covers the 50 foundation-layer controls that every CERT-In, ISO/IEC 27001:2022, or RBI audit will assess. For each control, mark your status: ✅ Implemented and documented, ⚠️ Partially implemented, ❌ Not implemented. Any ❌ or ⚠️ is a finding. Prioritise ❌ items in Critical and Access Control categories first — these are the highest-risk gaps and the ones most likely to trigger regulatory action. Use the results to build a remediation roadmap before your formal audit begins.

Section 1: Asset Management (Controls 1–8)

#ControlFramework
1Complete hardware asset inventory maintained and currentCIS C1, ISO A.5.9
2Software inventory with licence and EOL status trackedCIS C2, ISO A.5.9
3All assets classified by criticality and data sensitivityISO A.5.12, DPDP
4Named owner assigned to every critical assetISO A.5.10
5Network discovery scan performed in last 30 daysCIS C1, CERT-In
6Unauthorised device detection alerts are activeCIS C1
7Decommissioned assets removed from inventory and securely disposedISO A.7.14, DPDP
8Storage media disposal certificates on file for last 12 monthsISO A.7.14

Section 2: Access Control (Controls 9–18)

#ControlFramework
9Formal access provisioning process with manager approvalISO A.5.18, CERT-In
10Quarterly access review completed with documented evidenceISO A.5.18, RBI
11MFA enforced on all privileged accountsCERT-In, RBI
12MFA enforced on all remote access (VPN, RDP, SSH)CERT-In mandatory
13No shared service accounts — all have unique identities and ownersISO A.5.16
14Formal offboarding disables accounts within 1 business dayISO A.5.18
15Privileged Access Management (PAM) tool deployedISO A.8.2, RBI
16Admin accounts separate from standard user accountsCIS C5, CERT-In
17Password policy: complexity, minimum length, history enforced via GPO/LDAPCIS L1
18Account lockout policy configured (max 5 failed attempts)CIS L1, CERT-In

Sections 3–6: Patch, Network, Backup, Documentation (Controls 19–50)

#ControlCategory
19Documented patch management policy with SLA timelinesPatch Mgmt
20Vulnerability scan completed in last 30 days (all critical assets)Patch Mgmt
21Zero critical/high CVEs older than 15 days on internet-facing systemsPatch Mgmt
22Patch exception register with risk acceptance and owner sign-offPatch Mgmt
23No flat network — minimum VLAN segmentation in placeNetwork
24Dedicated management VLAN for network device accessNetwork
25All network device default credentials changed and documentedNetwork
26Firewall rules reviewed in last 90 days with documented sign-offNetwork
27All denied firewall traffic logged (180-day retention)Network
28Legacy protocols disabled: SMBv1, TLS 1.0/1.1, TelnetNetwork
29DNS logging enabled and forwarded to SIEMNetwork
30DHCP snooping enabled on all managed switchesNetwork
31RTO and RPO defined and board-approved for all critical systemsBackup/DR
323-2-1 backup architecture implemented for all critical dataBackup/DR
33Restore test completed in last 90 days with documented resultsBackup/DR
34Offsite/immutable backup copy exists and testedBackup/DR
35Annual DR failover test completed with RTO evidenceBackup/DR
36Full-disk encryption enabled on all laptops and mobile devicesEndpoint
37EDR deployed on 100% of managed endpointsEndpoint
38USB storage blocked or controlled via policyEndpoint
39Mobile devices enrolled in MDM with remote-wipe enabledEndpoint
40Server CIS Benchmark score ≥70% on critical serversHardening
41Server room access log maintained (minimum 12-month retention)Physical
42CCTV covers all server room entry points (90-day retention)Physical
43Information Security Policy — current version, board-approvedDocumentation
44Incident Response Procedure documented and testedDocumentation
45Change Management Procedure with CAB records last 6 monthsDocumentation
46Risk Assessment completed in last 12 months with treatment planDocumentation
47Third-party vendor security assessment completed for critical vendorsVendor
48Security awareness training completed by all staff — evidence on fileTraining
49SIEM deployed with 180-day log retention across all critical systemsMonitoring
50CERT-In incident reporting procedure ready — contacts registeredIncident Response

Let InfraVeritas 360 Run This Checklist For You — On-Site

Our IGaaS engine assesses all 50 of these foundation controls on-site, with evidence collection, gap analysis, and a board-ready report in 48 hours — mapped to CERT-In, ISO 27001, DPDP, and RBI.

Start the Foundation Assessment →