Home India ELECTRONICS AND INFORMATION TECHNOLOGY Parliament Question: Cyber Security Audit of Digital Governm...
Date: 2026-02-04 Category: Not Applicable State: Union Government Country: India

Parliament Question: Cyber Security Audit of Digital Government Services

Issued by ELECTRONICS AND INFORMATION TECHNOLOGY · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** This document is a response to Lok Sabha Unstarred Question No. 850, concerning the cyber security audit of digital Government services, to be answered on February 4, 2026. It outlines measures taken by the Government of India to ensure a secure cyberspace and mitigate cyber risks. CERT-In and NCIIPC are key agencies involved in these efforts. The response covers cybersecurity audits, measures to strengthen security, and future protective steps. **Key Points / Main Content** * **Cyber Security Audits:** * Indian Computer Emergency Response Team (CERT-In) and National Critical Information Infrastructure Protection Centre (NCIIPC) regularly conduct cybersecurity audits. * National Informatics Centre (NIC) conducts comprehensive annual cyber security audits of critical infrastructure. * Concerned entities undertake corrective measures to address security gaps identified in audits. * **Measures to Strengthen Security:** * Comprehensive Cyber Security Audit Policy Guidelines were issued by CERT-In in July 2025, requiring annual audits. * CERT-In has empanelled 237 security auditing organizations. * National Cyber Coordination Centre (NCCC) implemented by CERT-In detects and shares cyber security threat information. * CERT-In issues ongoing alerts and advisories regarding cyber threats and vulnerabilities. * Cyber Swachhta Kendra (CSK) provides citizen-centric services, including malware detection and removal tools. * Cyber Crisis Management Plan formulated by CERT-In counters cyberattacks and cyber terrorism. * Responsible Vulnerability Disclosure and Coordination Program operationalized by CERT-In. * CERT-In has issued guidelines for Secure Application Design, Development, Implementation & Operations. * CERT-In has issued guidelines on information security practices for government entities in June 2023. * CERT-In conducts cyber security mock drills. * Cyber security training programs are conducted by CERT-In. * **National Cyber Security Awareness Activities:** * The Government organizes events and activities for citizens and the technical cyber community. * National Cyber Security Awareness Month (NCSAM) occurs in October annually. * Safer Internet Day is observed on the second Tuesday of February. * Cyber Jagrookta Diwas (CJD) is on the first Wednesday of every month. * Swachhta Pakhwada (1st -15th February). **Impact Analysis** **Stakeholders Impacted: Government Organizations** * **Impact:** Must adhere to CERT-In guidelines and policies for cybersecurity. * **Action Required:** Implement CERT-In guidelines, participate in audits, and take corrective measures. **Stakeholders Impacted: Citizens** * **Impact:** Benefit from a more secure digital environment and have access to cyber security awareness resources. * **Action Required:** Utilize available resources and tools, follow cyber security tips and best practices, and participate in awareness activities. **Stakeholders Impacted: CERT-In Empanelled Organizations** * **Impact:** Opportunity to support and audit implementation of Information Security Best Practices. * **Action Required:** Conduct periodic information security audits for the Cybersecurity measures implemented by various organizations.

Key Entities Referenced

Indian Computer Emergency Response Team (CERT-In): India's national incident response centre responsible for cybersecurity incident response, vulnerability management, and cybersecurity awareness. National Cyber Coordination Centre (NCCC): Implemented by CERT-In, it detects cyber security threats by examining the cyberspace and shares the information with concerned organizations. National Critical Information Infrastructure Protection Centre (NCIIPC): Organisation that regularly carry out cybersecurity audits to protect critical information infrastructure. Cyber Swachhta Kendra (CSK): A citizen-centric cybersecurity service provided by CERT-In for cleaning botnets and malware. Ministry of Electronics and Information Technology: Government ministry responsible for policies related to information technology and cybersecurity.
Official Source Record View Original Source →
See Full Document Text
† O.I.H. GOVERNMENT OF INDIA MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY LOK SABHA UNSTARRED QUESTION NO. 850 TO BE ANSWERED ON: 04.02.2026 CYBER SECURITY AUDIT OF DIGITAL GOVERNMENT SERVICES †850. SHRI OMPRAKASH BHUPALSINH ALIAS PAVAN RAJENIMBALKAR: SHRI SANJAY HARIBHAU JADHAV: Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state: (a) whether the Government has conducted a cyber security audit of all digital Government services; (b) if so, the details along with the findings thereof; (c) the corrective measures taken by the Government based on the above findings; (d) the measures currently being implemented to strengthen the security of digital Government platforms; and (e) the additional steps proposed to protect digital Government services from cyber threats in the future? ANSWER MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY (SHRI JITIN PRASADA) (a) to (e): The policies of the Government of India aim to ensure a secure and trustworthy cyberspace while taking active measures to mitigate risk to India’s digital infrastructure and Government services. Indian Computer Emergency Response Team (CERT-In) and National Critical Information Infrastructure Protection Centre (NCIIPC) regularly carry out cybersecurity audits. NCIIPC undertakes vulnerabilities and risk assessment of Critical Information Infrastructure/ Protected Systems periodically and gives feedback to all concerned. CERT-In has created a panel of 'Information Security Auditing Organisations' for auditing, including vulnerability assessments and penetration testing of computer systems, networks and applications of various organizations across sectors. Cyber security measures implemented by various organizations and its compliance with regulations are evaluated through periodic information security audits conducted by CERT-In empanelled organizations. National Informatics Centre (NIC) carries out comprehensive annual cyber security audit of its critical applications, databases, and Information and Communication Technology (ICT) network infrastructure across Ministries, Departments, States, Union Territories and National Data Centres. Based on the auditfindings, the concerned entities undertake corrective measures to address the security gaps identified during the audit process. The measures undertaken by government to strengthen security of digital Government platforms and services from cyber threats, inter alia, includes: 1. Comprehensive Cyber Security Audit Policy Guidelines have been issued by CERT-In in July 2025. As per these guidelines, cyber security audits are required to be conducted at least once every year in a consistent, effective, and secure manner across all sectors, including critical infrastructure. 2. Empanelled 237 security auditing organizations by CERT-In to support and audit implementation of Information Security Best Practices. 3. National Cyber Coordination Centre (NCCC) implemented by CERT-In, examines the cyberspace to detect cyber security threats. It shares the information with concerned organisations, state governments and stakeholder agencies for taking action. 4. Alerts and advisories issued by CERT-In regarding latest cyber threats/vulnerabilities and countermeasures on an ongoing basis. 5. Cyber Swachhta Kendra (CSK) • A citizen-centric service provided by CERT-In, which extends the vision of Swachh Bharat to the Cyber Space. • It is the Botnet Cleaning and Malware Analysis Centre and helps to detect malicious programs and provides free tools to remove the same. • It also provides cyber security tips and best practices for citizens and organisations. 6. Cyber Crisis Management Plan formulated by CERT-In for countering cyberattacks and cyber terrorism for implementation by all Ministries/Departments. 7. A Responsible Vulnerability Disclosure and Coordination Program has been operationalised by CERT-In for the collection, analysis, and mitigation of vulnerabilities, including coordination with researchers, finders, and vendors for fixing vulnerabilities in software and devices. 8. CERT-In has issued guidelines for Secure Application Design, Development, Implementation & Operations to promote security-by-design across the application lifecycle. 9. CERT-In has issued guidelines on information security practices for government entities in June 2023 covering domains such as data security, network security, identity and access management, application security, third-party outsourcing, hardening procedures, security monitoring, incident management and security auditing. 10. Cyber security mock drills by CERT-In for assessment of cyber security posture and preparedness of organisations in Government and critical sectors. 11. Cyber security training programs conducted by CERT-In in collaboration with Industry partners to upskill the cyber security workforce in Government, public and private organizations. 23 and 32 training programs were conducted covering 12014 and 20799 participants during 2024 and 2025 respectively. 12. National Cyber Security Awareness Activities The Government organises events and activities for citizens as well as the technical cyber community across the country. Some of these include: • National Cyber Security Awareness Month (NCSAM) in October every year • Safer Internet Day on the second Tuesday of February• Swachhta Pakhwada (1st –15th February), and • Cyber Jagrookta Diwas (CJD) on the first Wednesday of every month • Awareness resources are available on platforms like www.staysafeonline.in, www.infosecawareness.in, and www.csk.gov.in. ******

Continue your research