← CSI Knowledge

Security Assessment Report

name
Security Assessment Report
source
Notion Export
migration_status
Imported
document_id
DOC-22
document_type
Report
domain
Cyber Security
hierarchy
Template
status
Under Review
version
v1.0
owner
Cyber Space Infocom
created
July 25, 2026 12:07 AM
last_updated
July 25, 2026 12:53 AM
review_date
August 1, 2026
review_priority
P2 High
effective
next_review
languages
English, Gujarati, Hindi
source_archive
CSI DOCS.tar(1).gz
source_formats
DOCX, PDF
source_files
CSI_Security_Assessment_Report_English.docx | CSI_Security_Assessment_Report_English.pdf | CSI_Security_Assessment_Report_Gujarati.docx | CSI_Security_Assessment_Report_Gujarati.pdf | CSI_Security_Assessment_Report_Hindi.docx | CSI_Security_Assessment_Report_Hindi.pdf
source_path
/home/csi/master/inbox/imports/notion-verify/staging/notion/Export-a01daa1a-664a-4975-9744-61a6104bc176/CSI Nexus тАФ Operating System/07 тАФ Document Library/Security Assessment Report 3a74d778395381bea469e7aab84a7eb5.md
classification_reason
CSI security documentation
06-Cybersecurity/Security Assessment Report.md

Security Assessment Report

Attachments: ../../Untitled%203a74-7eb5/CSI_Security_Assessment_Report_English.docx, ../../Untitled%203a74-7eb5/CSI_Security_Assessment_Report_English.pdf, ../../Untitled%203a74-7eb5/CSI_Security_Assessment_Report_Gujarati.docx, ../../Untitled%203a74-7eb5/CSI_Security_Assessment_Report_Gujarati.pdf, ../../Untitled%203a74-7eb5/CSI_Security_Assessment_Report_Hindi.docx, ../../Untitled%203a74-7eb5/CSI_Security_Assessment_Report_Hindi.pdf Created: July 25, 2026 12:07 AM Document ID: DOC-22 Document Type: Report Domain: Cyber Security Hierarchy: Template Languages: English, Gujarati, Hindi Last Updated: July 25, 2026 12:53 AM Migration Status: Migrated Owner: Cyber Space Infocom Remarks: Reviewed and approved as the CSI controlled working master on 2026-07-26. Use a client-specific copy for each engagement and complete all variable fields before issue. Review Date: August 1, 2026 Review Priority: P2 High Source Archive: CSI DOCS.tar(1).gz Source Files: CSI_Security_Assessment_Report_English.docx | CSI_Security_Assessment_Report_English.pdf | CSI_Security_Assessment_Report_Gujarati.docx | CSI_Security_Assessment_Report_Gujarati.pdf | CSI_Security_Assessment_Report_Hindi.docx | CSI_Security_Assessment_Report_Hindi.pdf Source Formats: DOCX, PDF Status: Under Review Version: v1.0

This page contains the readable working content migrated from the CSI source archive. Review and approve it before external or contractual use.

  • English
|  | CYBER SPACE INFOCOM IT Infrastructure • AI • Cyber Security +91 90547 79647 | [info@cyberspaceinfocom.com](mailto:info@cyberspaceinfocom.com) |
| --- | --- |

SECURITY ASSESSMENT REPORT

Govern • Identify • Protect • Detect • Respond • Recover

Assessment template • Complete written authorisation and exact scope before technical testing. Passive review does not authorise exploitation, password attacks, denial-of-service, phishing simulation or disruptive scanning.

1. Client and Assessment Details

| Assessment Detail | Client Entry | Assessment Detail | Client Entry |
| --- | --- | --- | --- |
| Client / Company |  | Site / Location |  |
| Report No. |  | Assessment Dates |  |
| Assessment Lead |  | Client Contact |  |
| Assessment Type |  | Authorisation Ref. |  |
| Systems / IP Ranges |  | Next Review Due |  |
1. Scope, Authorization and Limitations

| Scope / Authority | Approved Detail |
| --- | --- |
| Included methods | ☐ Interview ☐ Document review ☐ Configuration review ☐ Passive discovery ☐ Authenticated scan ☐ External scan ☐ Other:  |
| Explicitly excluded | ☐ Exploitation ☐ Password attack ☐ Phishing ☐ DoS/load test ☐ Social engineering ☐ Data extraction ☐ Production change |
| Approved IPs / domains | __ |
| Approved accounts / credentials | __ |
| Maintenance window | __ |
| Emergency stop contact | __ |
| Data handling / retention | __ |
| Known limitations | __ |
1. Executive Risk Summary

| Risk Summary | Assessment Result |
| --- | --- |
| Overall risk | ☐ Critical ☐ High ☐ Moderate ☐ Low ☐ Not fully assessed |
| Critical findings |  |
| High findings |  |
| Medium findings |  |
| Low findings |  |
| Good practices observed | __ |
| Immediate action (0–7 days) | __ |
| Priority action (30 days) | __ |
| Strategic action (90+ days) | __ |
| Residual-risk owner | __ |
1. Risk Rating Method

| Method Item | Definition |
| --- | --- |
| Likelihood | 1 Rare; 2 Unlikely; 3 Possible; 4 Likely; 5 Almost certain |
| Impact | 1 Minor; 2 Limited; 3 Moderate; 4 Major; 5 Severe |
| Score | Likelihood × Impact |
| Critical | 20–25 — urgent containment and executive ownership |
| High | 15–19 — priority remediation and tracked exception |
| Medium | 8–14 — planned remediation based on exposure |
| Low | 1–7 — improve through normal maintenance |
| Evidence status | Verified / Observed / Client-stated / Not tested |
1. Asset and Exposure Overview

| Category | Count / Scope | Internet Exposed | Unsupported / EOL | Security Tool Coverage | Owner / Notes |
| --- | --- | --- | --- | --- | --- |
| Users / identities |  |  |  |  /  |  |
| Desktops / laptops |  |  |  |  /  |  |
| Servers / RDP / VMs |  |  |  |  /  |  |
| Firewalls / routers |  |  |  |  /  |  |
| Switches / Wi‑Fi |  |  |  |  /  |  |
| NAS / backup |  |  |  |  /  |  |
| Cloud / SaaS |  |  |  |  /  |  |
| Business applications |  |  |  |  /  |  |
1. Governance and Risk Management

| Status | Assessment Control | Evidence / Finding Ref. | Owner / Action |
| --- | --- | --- | --- |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Security policy, accountable owner, risk appetite and exception approval are documented. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Critical services, data owners, legal/contractual obligations and third-party dependencies are identified. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Joiner/mover/leaver, acceptable use, remote work and supplier access procedures exist. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Asset ownership, classification, retention and secure disposal requirements are defined. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Management receives tracked security metrics, incidents, overdue risk and remediation status. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Security awareness, phishing reporting and role-specific administrator training are performed. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | CERT-In directions and applicable audit/reporting requirements are reviewed with evidence. |  |  |
1. Identity and Access Management

| Status | Assessment Control | Evidence / Finding Ref. | Owner / Action |
| --- | --- | --- | --- |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Named user/admin accounts are used; shared/default/dormant accounts are removed or justified. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | MFA protects email, cloud, VPN, remote access and privileged administration where supported. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Password policy, lockout, reset, vaulting and emergency account controls are appropriate. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Local/domain/cloud administrator membership follows least privilege and is reviewed. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Vendor and remote support access is time-bound, approved, logged and revoked after use. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Departed users are disabled promptly and sessions/tokens/keys are revoked. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Service accounts have owners, restricted logon, rotated secrets and documented dependencies. |  |  |
1. Endpoint and Server Security

| Status | Assessment Control | Evidence / Finding Ref. | Owner / Action |
| --- | --- | --- | --- |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Supported OS and applications receive timely security updates. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Antivirus/EDR is licensed, active, centrally visible and tamper protected. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Disk encryption, screen lock, firewall and secure baseline are enabled where required. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Unapproved software, macros/scripts, removable media and local admin rights are controlled. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Servers expose only required services; RDP/SSH is restricted, logged and protected by MFA/VPN. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Application allowlisting or equivalent control is considered for high-risk systems. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Device inventory links owner, location, OS, security status and last check-in. |  |  |
1. Network, Firewall and Wi‑Fi Security

| Status | Assessment Control | Evidence / Finding Ref. | Owner / Action |
| --- | --- | --- | --- |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Firewall firmware/support and threat signatures are current. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Internet-facing rules, port forwards, VPNs and management interfaces have a documented business need. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Inbound/outbound rules follow least privilege and unused rules are removed after review. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Network is segmented for servers, users, guests, management, CCTV/IoT and backups as appropriate. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Switch/AP/router management uses secure protocols, named admins and restricted source networks. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Wi‑Fi uses strong encryption; guest access is isolated; obsolete protocols and default keys are removed. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Configuration backups, diagrams, device ownership and change logs are current. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Unapproved scanning is not performed; approved discovery results are reconciled with inventory. |  |  |
1. Email, Cloud and Application Security

| Status | Assessment Control | Evidence / Finding Ref. | Owner / Action |
| --- | --- | --- | --- |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Email anti-phishing/spam/malware protections and external-sender indicators are configured. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | DMARC, DKIM and SPF posture is reviewed for approved mail domains. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Cloud tenant administrators, OAuth applications, forwarding rules and risky sign-ins are reviewed. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Business applications use supported versions, secure authentication and protected administrative interfaces. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Public links, shared drives, guest users and excessive permissions are reviewed. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Sensitive data transfer, encryption, retention and deletion requirements are documented. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Critical SaaS/application logs and backup/export capability are understood. |  |  |
1. Vulnerability and Patch Management

| Status | Assessment Control | Evidence / Finding Ref. | Owner / Action |
| --- | --- | --- | --- |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Asset inventory identifies supported versions and patch responsibility. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Critical/high vulnerabilities and known exploited vulnerabilities are prioritised by exposure and impact. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Operating system, application, firmware and network-device patches have defined timelines. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Authenticated scanning is preferred where approved; false positives are validated. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Internet-facing systems receive more frequent review and rapid emergency patching. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Exceptions record owner, reason, compensating control, expiry and acceptance. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Rescan or configuration evidence confirms remediation; ticket closure alone is not evidence. |  |  |
1. Logging, Monitoring and Detection

| Status | Assessment Control | Evidence / Finding Ref. | Owner / Action |
| --- | --- | --- | --- |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Security-relevant logs have correct time, sufficient retention and protected access. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Authentication, privileged changes, endpoint alerts, firewall/VPN and backup failures are monitored. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Alert owners, escalation paths and response times are documented and tested. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | EDR/antivirus alerts are investigated; exclusions and suppressed detections are reviewed. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Critical devices do not rely only on local logs that an attacker can erase. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Baseline/threshold anomalies and repeated failed logins are reviewed. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Monitoring coverage gaps and unavailable evidence are recorded as findings. |  |  |
1. Backup, Ransomware and Recovery

| Status | Assessment Control | Evidence / Finding Ref. | Owner / Action |
| --- | --- | --- | --- |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Critical data and systems have defined owner, backup scope, RPO and RTO. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Backup jobs, off-site/isolated copies, retention, encryption and failure alerts are verified. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | A controlled restore test—not job status alone—demonstrates recoverability. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Backup administration and deletion rights are separated where practical. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Ransomware cannot use normal endpoint credentials to delete every backup copy. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Recovery runbook, dependencies, contacts and alternate communication are documented. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Post-incident password/key rotation and clean rebuild procedures are prepared. |  |  |
1. Incident Response and CERT-In Readiness

| Status | Assessment Control | Evidence / Finding Ref. | Owner / Action |
| --- | --- | --- | --- |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Incident response roles, severity, communication and decision authority are defined. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Users know how to report phishing, malware, lost devices and suspicious access. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Evidence preservation, containment, legal/management escalation and vendor coordination are documented. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | CERT-In applicability, reportable incident categories, time requirements and contact process are reviewed with qualified legal/compliance owners. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | A current incident contact list and offline copy of the response plan are available. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Tabletop exercises test ransomware, email compromise, data loss and service outage scenarios. |  |  |
| ☐ Pass ☐ Gap ☐ N/A ☐ NT | Lessons learned produce owned corrective actions and updates to controls. |  |  |
1. Detailed Findings Register

| ID | Risk | Asset / Control | Finding and Evidence | Business Impact | Recommendation | Owner / Due | Status |
| --- | --- | --- | --- | --- | --- | --- | --- |
| SEC-01 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-02 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-03 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-04 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-05 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-06 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-07 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-08 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-09 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-10 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-11 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
| SEC-12 | ☐ C ☐ H ☐ M ☐ L |  |  |  |  | __ / **/**/__ | ☐ Open ☐ Closed |
1. Remediation Roadmap

| Priority / Window | Remediation Workstream | Finding IDs | Responsible Owner | Budget / QTN Ref. | Success Evidence | Residual Risk |
| --- | --- | --- | --- | --- | --- | --- |
| Immediate / 0–7 days |  | __ |  |  |  |  |
| Priority / 8–30 days |  | __ |  |  |  |  |
| Near term / 31–90 days |  | __ |  |  |  |  |
| Strategic / 90+ days |  | __ |  |  |  |  |
1. Evidence Register

| Ref. | Evidence Type | System / Control | Source / Date | Location / Attachment | Evidence Status | Verified By |
| --- | --- | --- | --- | --- | --- | --- |
| 1 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
| 2 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
| 3 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
| 4 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
| 5 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
| 6 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
| 7 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
| 8 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
| 9 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
| 10 | ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan |  |  |  | ☐ V ☐ O ☐ C ☐ NT |  |
1. Final Assessment and Sign-off

| Final Item | Assessment Result |
| --- | --- |
| Overall risk | ☐ Critical ☐ High ☐ Moderate ☐ Low ☐ Not fully assessed |
| Assessment coverage | ☐ Complete to scope ☐ Partial ☐ Significant limitations |
| Intrusive testing performed | ☐ No ☐ Yes — separate authorisation:  |
| Immediate containment completed | __ |
| Open critical/high risk owner | __ |
| Retest / next assessment | ***_ /*** _ /  |
| Quotation / ticket references | __ |

This report is a point-in-time, scope-limited assessment based on available evidence. It does not certify that the environment is secure or free from vulnerabilities. Unauthorised or intrusive testing was not performed. The Client owns remediation decisions and residual risk unless separately contracted.

| Sign-off Item | Name / Signature / Date |
| --- | --- |
| CSI Assessor | __ |
| CSI Signature | __ |
| Client Representative | __ |
| Designation | __ |
| Client Comments | __ |
| Client Signature & Stamp | __ |
| Date / Time | __ |

Appendix A — Assessment Checklist

| Status | Assessment Checklist | Owner / Evidence |
| --- | --- | --- |
| ☐ | Written authorisation and exact scope recorded |  |
| ☐ | Emergency stop contact verified |  |
| ☐ | Asset inventory/sample reconciled |  |
| ☐ | Internet exposure reviewed |  |
| ☐ | Privileged and dormant accounts reviewed |  |
| ☐ | MFA coverage reviewed |  |
| ☐ | Endpoint/EDR coverage reviewed |  |
| ☐ | Patch/vulnerability process reviewed |  |
| ☐ | Firewall/rule exposure reviewed |  |
| ☐ | Wi‑Fi and segmentation reviewed |  |
| ☐ | Email/cloud controls reviewed |  |
| ☐ | Logging/detection reviewed |  |
| ☐ | Backup and restore evidence reviewed |  |
| ☐ | Incident/CERT-In readiness reviewed |  |
| ☐ | Findings evidence and owner assigned |  |
| ☐ | Client briefing and sign-off completed |  |

Appendix B — Official References

| Official Reference | URL |
| --- | --- |
| NIST Cybersecurity Framework 2.0 | [https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20](https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20) |
| NIST CSF 2.0 PDF | [https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf](https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf) |
| CISA Cybersecurity Performance Goals 2.0 | [https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0](https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0) |
| CERT-In directions / audit evidence notice | [https://www.cert-in.org.in/s2cMainServlet?CACODE=CICA-2024-3329&pageid=PUBADV01](https://www.cert-in.org.in/s2cMainServlet?CACODE=CICA-2024-3329&pageid=PUBADV01) |
| CERT-In official site | [https://www.cert-in.org.in/](https://www.cert-in.org.in/) |
  • ગુજરાતી

    | | CYBER SPACE INFOCOM IT Infrastructure • AI • Cyber Security +91 90547 79647 | info@cyberspaceinfocom.com | | --- | --- |

    સિક્યુરિટી એસેસમેન્ટ રિપોર્ટ

    Govern • Identify • Protect • Detect • Respond • Recover

    Assessment template • Technical testing પહેલાં written authorisation અને exact scope પૂર્ણ કરો. Passive review exploitation, password attack, DoS, phishing simulation અથવા disruptive scanની મંજૂરી આપતું નથી.

    1. Client અને Assessment Details
    Assessment Detail Client Entry Assessment Detail Client Entry
    Client / Company Site / Location
    Report No. Assessment Dates
    Assessment Lead Client Contact
    Assessment Type Authorisation Ref.
    Systems / IP Ranges Next Review Due
    1. Scope, Authorization અને Limitations
    Scope / Authority Approved Detail
    Included methods ☐ Interview ☐ Document review ☐ Configuration review ☐ Passive discovery ☐ Authenticated scan ☐ External scan ☐ Other:
    Explicitly excluded ☐ Exploitation ☐ Password attack ☐ Phishing ☐ DoS/load test ☐ Social engineering ☐ Data extraction ☐ Production change
    Approved IPs / domains __
    Approved accounts / credentials __
    Maintenance window __
    Emergency stop contact __
    Data handling / retention __
    Known limitations __
    1. Executive Risk Summary
    Risk Summary Assessment Result
    Overall risk ☐ Critical ☐ High ☐ Moderate ☐ Low ☐ Not fully assessed
    Critical findings
    High findings
    Medium findings
    Low findings
    Good practices observed __
    Immediate action (0–7 days) __
    Priority action (30 days) __
    Strategic action (90+ days) __
    Residual-risk owner __
    1. Risk Rating Method
    Method Item Definition
    Likelihood 1 Rare; 2 Unlikely; 3 Possible; 4 Likely; 5 Almost certain
    Impact 1 Minor; 2 Limited; 3 Moderate; 4 Major; 5 Severe
    Score Likelihood × Impact
    Critical 20–25 — urgent containment and executive ownership
    High 15–19 — priority remediation and tracked exception
    Medium 8–14 — planned remediation based on exposure
    Low 1–7 — improve through normal maintenance
    Evidence status Verified / Observed / Client-stated / Not tested
    1. Asset અને Exposure Overview
    Category Count / Scope Internet Exposed Unsupported / EOL Security Tool Coverage Owner / Notes
    Users / identities /
    Desktops / laptops /
    Servers / RDP / VMs /
    Firewalls / routers /
    Switches / Wi‑Fi /
    NAS / backup /
    Cloud / SaaS /
    Business applications /
    1. Governance અને Risk Management
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Security policy, accountable owner, risk appetite અને exception approval documented હોવા જોઈએ.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical services, data owners, obligations અને third-party dependencies identified હોવા જોઈએ.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Joiner/mover/leaver, acceptable use, remote work અને supplier access procedures હોવા જોઈએ.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Asset ownership, classification, retention અને secure disposal defined હોવા જોઈએ.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Managementને security metrics, incidents, overdue risks અને remediation status મળવું જોઈએ.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Security awareness, phishing reporting અને administrator training થવી જોઈએ.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT CERT-In directions અને applicable reporting/audit requirements evidence સાથે review કરવા.
    1. Identity અને Access Management
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Named user/admin accounts વાપરો; shared/default/dormant accounts remove અથવા justify કરો.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Email, cloud, VPN, remote access અને privileged admin પર MFA રાખો.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Password, lockout, reset, vault અને emergency account controls appropriate રાખો.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Administrator membership least privilege પ્રમાણે અને regularly review કરો.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Vendor/remote access time-bound, approved, logged અને use પછી revoke કરો.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Departed users promptly disable અને sessions/tokens/keys revoke કરો.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Service accountsના owner, restricted logon અને rotated secrets રાખો.
    1. Endpoint અને Server Security
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Supported OS and applications receive timely security updates.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Antivirus/EDR is licensed, active, centrally visible and tamper protected.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Disk encryption, screen lock, firewall and secure baseline are enabled where required.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Unapproved software, macros/scripts, removable media and local admin rights are controlled.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Servers expose only required services; RDP/SSH is restricted, logged and protected by MFA/VPN.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Application allowlisting or equivalent control is considered for high-risk systems.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Device inventory links owner, location, OS, security status and last check-in.
    1. Network, Firewall અને Wi‑Fi Security
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Firewall firmware/support and threat signatures are current.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Internet-facing rules, port forwards, VPNs and management interfaces have a documented business need.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Inbound/outbound rules follow least privilege and unused rules are removed after review.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Network is segmented for servers, users, guests, management, CCTV/IoT and backups as appropriate.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Switch/AP/router management uses secure protocols, named admins and restricted source networks.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Wi‑Fi uses strong encryption; guest access is isolated; obsolete protocols and default keys are removed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Configuration backups, diagrams, device ownership and change logs are current.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Unapproved scanning is not performed; approved discovery results are reconciled with inventory.
    1. Email, Cloud અને Application Security
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Email anti-phishing/spam/malware protections and external-sender indicators are configured.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT DMARC, DKIM and SPF posture is reviewed for approved mail domains.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Cloud tenant administrators, OAuth applications, forwarding rules and risky sign-ins are reviewed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Business applications use supported versions, secure authentication and protected administrative interfaces.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Public links, shared drives, guest users and excessive permissions are reviewed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Sensitive data transfer, encryption, retention and deletion requirements are documented.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical SaaS/application logs and backup/export capability are understood.
    1. Vulnerability અને Patch Management
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Asset inventory identifies supported versions and patch responsibility.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical/high vulnerabilities and known exploited vulnerabilities are prioritised by exposure and impact.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Operating system, application, firmware and network-device patches have defined timelines.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Authenticated scanning is preferred where approved; false positives are validated.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Internet-facing systems receive more frequent review and rapid emergency patching.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Exceptions record owner, reason, compensating control, expiry and acceptance.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Rescan or configuration evidence confirms remediation; ticket closure alone is not evidence.
    1. Logging, Monitoring અને Detection
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Security-relevant logs have correct time, sufficient retention and protected access.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Authentication, privileged changes, endpoint alerts, firewall/VPN and backup failures are monitored.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Alert owners, escalation paths and response times are documented and tested.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT EDR/antivirus alerts are investigated; exclusions and suppressed detections are reviewed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical devices do not rely only on local logs that an attacker can erase.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Baseline/threshold anomalies and repeated failed logins are reviewed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Monitoring coverage gaps and unavailable evidence are recorded as findings.
    1. Backup, Ransomware અને Recovery
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical systems/dataના owner, backup scope, RPO અને RTO defined હોવા જોઈએ.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Backup jobs, off-site copies, retention, encryption અને alerts verify કરો.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Controlled restore test—ફક્ત job status નહીં—recoverability prove કરે.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Backup admin અને deletion rights અલગ રાખો જ્યાં practical હોય.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Normal endpoint credentialsથી બધી backup copies delete ન થઈ શકે.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Recovery runbook, dependencies, contacts અને alternate communication documented રાખો.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Post-incident password/key rotation અને clean rebuild procedure તૈયાર રાખો.
    1. Incident Response અને CERT-In Readiness
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Incident response roles, severity, communication and decision authority are defined.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Users know how to report phishing, malware, lost devices and suspicious access.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Evidence preservation, containment, legal/management escalation and vendor coordination are documented.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT CERT-In applicability, reportable incident categories, time requirements and contact process are reviewed with qualified legal/compliance owners.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT A current incident contact list and offline copy of the response plan are available.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Tabletop exercises test ransomware, email compromise, data loss and service outage scenarios.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Lessons learned produce owned corrective actions and updates to controls.
    1. Detailed Findings Register
    ID Risk Asset / Control Finding and Evidence Business Impact Recommendation Owner / Due Status
    SEC-01 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-02 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-03 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-04 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-05 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-06 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-07 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-08 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-09 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-10 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-11 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-12 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    1. Remediation Roadmap
    Priority / Window Remediation Workstream Finding IDs Responsible Owner Budget / QTN Ref. Success Evidence Residual Risk
    Immediate / 0–7 days __
    Priority / 8–30 days __
    Near term / 31–90 days __
    Strategic / 90+ days __
    1. Evidence Register
    Ref. Evidence Type System / Control Source / Date Location / Attachment Evidence Status Verified By
    1 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    2 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    3 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    4 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    5 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    6 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    7 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    8 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    9 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    10 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    1. Final Assessment અને Sign-off
    Final Item Assessment Result
    Overall risk ☐ Critical ☐ High ☐ Moderate ☐ Low ☐ Not fully assessed
    Assessment coverage ☐ Complete to scope ☐ Partial ☐ Significant limitations
    Intrusive testing performed ☐ No ☐ Yes — separate authorisation:
    Immediate containment completed __
    Open critical/high risk owner __
    Retest / next assessment _ / _ /
    Quotation / ticket references __

    આ report ઉપલબ્ધ evidence આધારિત point-in-time અને scope-limited assessment છે. તે environment secure અથવા vulnerability-free હોવાની certification નથી. Unauthorised/intrusive testing કરેલ નથી. અલગ contract ન હોય ત્યાં remediation અને residual risk Clientની જવાબદારી છે.

    Sign-off Item Name / Signature / Date
    CSI Assessor __
    CSI Signature __
    Client Representative __
    Designation __
    Client Comments __
    Client Signature & Stamp __
    Date / Time __

    Appendix A — Assessment Checklist

    Status Assessment Checklist Owner / Evidence
    Written authorisation and exact scope recorded
    Emergency stop contact verified
    Asset inventory/sample reconciled
    Internet exposure reviewed
    Privileged and dormant accounts reviewed
    MFA coverage reviewed
    Endpoint/EDR coverage reviewed
    Patch/vulnerability process reviewed
    Firewall/rule exposure reviewed
    Wi‑Fi and segmentation reviewed
    Email/cloud controls reviewed
    Logging/detection reviewed
    Backup and restore evidence reviewed
    Incident/CERT-In readiness reviewed
    Findings evidence and owner assigned
    Client briefing and sign-off completed

    Appendix B — Official References

    Official Reference URL
    NIST Cybersecurity Framework 2.0 https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
    NIST CSF 2.0 PDF https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
    CISA Cybersecurity Performance Goals 2.0 https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0
    CERT-In directions / audit evidence notice https://www.cert-in.org.in/s2cMainServlet?CACODE=CICA-2024-3329&pageid=PUBADV01
    CERT-In official site https://www.cert-in.org.in/
    - हिन्दी

    | | CYBER SPACE INFOCOM IT Infrastructure • AI • Cyber Security +91 90547 79647 | info@cyberspaceinfocom.com | | --- | --- |

    सुरक्षा मूल्यांकन रिपोर्ट

    Govern • Identify • Protect • Detect • Respond • Recover

    Assessment template • Technical testing से पहले written authorisation और exact scope पूरा करें। Passive review exploitation, password attack, DoS, phishing simulation या disruptive scan की अनुमति नहीं देता।

    1. Client और Assessment Details
    Assessment Detail Client Entry Assessment Detail Client Entry
    Client / Company Site / Location
    Report No. Assessment Dates
    Assessment Lead Client Contact
    Assessment Type Authorisation Ref.
    Systems / IP Ranges Next Review Due
    1. Scope, Authorization और Limitations
    Scope / Authority Approved Detail
    Included methods ☐ Interview ☐ Document review ☐ Configuration review ☐ Passive discovery ☐ Authenticated scan ☐ External scan ☐ Other:
    Explicitly excluded ☐ Exploitation ☐ Password attack ☐ Phishing ☐ DoS/load test ☐ Social engineering ☐ Data extraction ☐ Production change
    Approved IPs / domains __
    Approved accounts / credentials __
    Maintenance window __
    Emergency stop contact __
    Data handling / retention __
    Known limitations __
    1. Executive Risk Summary
    Risk Summary Assessment Result
    Overall risk ☐ Critical ☐ High ☐ Moderate ☐ Low ☐ Not fully assessed
    Critical findings
    High findings
    Medium findings
    Low findings
    Good practices observed __
    Immediate action (0–7 days) __
    Priority action (30 days) __
    Strategic action (90+ days) __
    Residual-risk owner __
    1. Risk Rating Method
    Method Item Definition
    Likelihood 1 Rare; 2 Unlikely; 3 Possible; 4 Likely; 5 Almost certain
    Impact 1 Minor; 2 Limited; 3 Moderate; 4 Major; 5 Severe
    Score Likelihood × Impact
    Critical 20–25 — urgent containment and executive ownership
    High 15–19 — priority remediation and tracked exception
    Medium 8–14 — planned remediation based on exposure
    Low 1–7 — improve through normal maintenance
    Evidence status Verified / Observed / Client-stated / Not tested
    1. Asset और Exposure Overview
    Category Count / Scope Internet Exposed Unsupported / EOL Security Tool Coverage Owner / Notes
    Users / identities /
    Desktops / laptops /
    Servers / RDP / VMs /
    Firewalls / routers /
    Switches / Wi‑Fi /
    NAS / backup /
    Cloud / SaaS /
    Business applications /
    1. Governance और Risk Management
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Security policy, accountable owner, risk appetite और exception approval documented हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical services, data owners, obligations और third-party dependencies identified हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Joiner/mover/leaver, acceptable use, remote work और supplier access procedures हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Asset ownership, classification, retention और secure disposal defined हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Management को security metrics, incidents, overdue risks और remediation status मिले।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Security awareness, phishing reporting और administrator training हो।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT CERT-In directions और applicable reporting/audit requirements evidence सहित review हों।
    1. Identity और Access Management
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Named user/admin accounts उपयोग हों; shared/default/dormant accounts remove या justify हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Email, cloud, VPN, remote access और privileged admin पर MFA हो।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Password, lockout, reset, vault और emergency account controls appropriate हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Administrator membership least privilege पर और regularly reviewed हो।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Vendor/remote access time-bound, approved, logged और use के बाद revoked हो।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Departed users promptly disable हों और sessions/tokens/keys revoke हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Service accounts के owner, restricted logon और rotated secrets हों।
    1. Endpoint और Server Security
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Supported OS and applications receive timely security updates.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Antivirus/EDR is licensed, active, centrally visible and tamper protected.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Disk encryption, screen lock, firewall and secure baseline are enabled where required.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Unapproved software, macros/scripts, removable media and local admin rights are controlled.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Servers expose only required services; RDP/SSH is restricted, logged and protected by MFA/VPN.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Application allowlisting or equivalent control is considered for high-risk systems.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Device inventory links owner, location, OS, security status and last check-in.
    1. Network, Firewall और Wi‑Fi Security
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Firewall firmware/support and threat signatures are current.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Internet-facing rules, port forwards, VPNs and management interfaces have a documented business need.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Inbound/outbound rules follow least privilege and unused rules are removed after review.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Network is segmented for servers, users, guests, management, CCTV/IoT and backups as appropriate.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Switch/AP/router management uses secure protocols, named admins and restricted source networks.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Wi‑Fi uses strong encryption; guest access is isolated; obsolete protocols and default keys are removed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Configuration backups, diagrams, device ownership and change logs are current.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Unapproved scanning is not performed; approved discovery results are reconciled with inventory.
    1. Email, Cloud और Application Security
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Email anti-phishing/spam/malware protections and external-sender indicators are configured.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT DMARC, DKIM and SPF posture is reviewed for approved mail domains.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Cloud tenant administrators, OAuth applications, forwarding rules and risky sign-ins are reviewed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Business applications use supported versions, secure authentication and protected administrative interfaces.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Public links, shared drives, guest users and excessive permissions are reviewed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Sensitive data transfer, encryption, retention and deletion requirements are documented.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical SaaS/application logs and backup/export capability are understood.
    1. Vulnerability और Patch Management
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Asset inventory identifies supported versions and patch responsibility.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical/high vulnerabilities and known exploited vulnerabilities are prioritised by exposure and impact.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Operating system, application, firmware and network-device patches have defined timelines.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Authenticated scanning is preferred where approved; false positives are validated.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Internet-facing systems receive more frequent review and rapid emergency patching.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Exceptions record owner, reason, compensating control, expiry and acceptance.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Rescan or configuration evidence confirms remediation; ticket closure alone is not evidence.
    1. Logging, Monitoring और Detection
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Security-relevant logs have correct time, sufficient retention and protected access.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Authentication, privileged changes, endpoint alerts, firewall/VPN and backup failures are monitored.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Alert owners, escalation paths and response times are documented and tested.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT EDR/antivirus alerts are investigated; exclusions and suppressed detections are reviewed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical devices do not rely only on local logs that an attacker can erase.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Baseline/threshold anomalies and repeated failed logins are reviewed.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Monitoring coverage gaps and unavailable evidence are recorded as findings.
    1. Backup, Ransomware और Recovery
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Critical systems/data के owner, backup scope, RPO और RTO defined हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Backup jobs, off-site copies, retention, encryption और alerts verified हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Controlled restore test—सिर्फ job status नहीं—recoverability prove करे।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Backup admin और deletion rights अलग हों जहाँ practical हो।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Normal endpoint credentials से सभी backup copies delete न हो सकें।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Recovery runbook, dependencies, contacts और alternate communication documented हों।
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Post-incident password/key rotation और clean rebuild procedure तैयार हो।
    1. Incident Response और CERT-In Readiness
    Status Assessment Control Evidence / Finding Ref. Owner / Action
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Incident response roles, severity, communication and decision authority are defined.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Users know how to report phishing, malware, lost devices and suspicious access.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Evidence preservation, containment, legal/management escalation and vendor coordination are documented.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT CERT-In applicability, reportable incident categories, time requirements and contact process are reviewed with qualified legal/compliance owners.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT A current incident contact list and offline copy of the response plan are available.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Tabletop exercises test ransomware, email compromise, data loss and service outage scenarios.
    ☐ Pass ☐ Gap ☐ N/A ☐ NT Lessons learned produce owned corrective actions and updates to controls.
    1. Detailed Findings Register
    ID Risk Asset / Control Finding and Evidence Business Impact Recommendation Owner / Due Status
    SEC-01 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-02 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-03 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-04 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-05 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-06 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-07 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-08 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-09 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-10 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-11 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    SEC-12 ☐ C ☐ H ☐ M ☐ L __ / //__ ☐ Open ☐ Closed
    1. Remediation Roadmap
    Priority / Window Remediation Workstream Finding IDs Responsible Owner Budget / QTN Ref. Success Evidence Residual Risk
    Immediate / 0–7 days __
    Priority / 8–30 days __
    Near term / 31–90 days __
    Strategic / 90+ days __
    1. Evidence Register
    Ref. Evidence Type System / Control Source / Date Location / Attachment Evidence Status Verified By
    1 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    2 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    3 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    4 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    5 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    6 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    7 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    8 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    9 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    10 ☐ Config ☐ Screenshot ☐ Log ☐ Interview ☐ Scan ☐ V ☐ O ☐ C ☐ NT
    1. Final Assessment और Sign-off
    Final Item Assessment Result
    Overall risk ☐ Critical ☐ High ☐ Moderate ☐ Low ☐ Not fully assessed
    Assessment coverage ☐ Complete to scope ☐ Partial ☐ Significant limitations
    Intrusive testing performed ☐ No ☐ Yes — separate authorisation:
    Immediate containment completed __
    Open critical/high risk owner __
    Retest / next assessment _ / _ /
    Quotation / ticket references __

    यह report उपलब्ध evidence पर आधारित point-in-time और scope-limited assessment है। यह environment को secure या vulnerability-free certify नहीं करती। Unauthorised/intrusive testing नहीं किया गया। Remediation और residual risk Client की जिम्मेदारी है, जब तक अलग contract न हो।

    Sign-off Item Name / Signature / Date
    CSI Assessor __
    CSI Signature __
    Client Representative __
    Designation __
    Client Comments __
    Client Signature & Stamp __
    Date / Time __

    Appendix A — Assessment Checklist

    Status Assessment Checklist Owner / Evidence
    Written authorisation and exact scope recorded
    Emergency stop contact verified
    Asset inventory/sample reconciled
    Internet exposure reviewed
    Privileged and dormant accounts reviewed
    MFA coverage reviewed
    Endpoint/EDR coverage reviewed
    Patch/vulnerability process reviewed
    Firewall/rule exposure reviewed
    Wi‑Fi and segmentation reviewed
    Email/cloud controls reviewed
    Logging/detection reviewed
    Backup and restore evidence reviewed
    Incident/CERT-In readiness reviewed
    Findings evidence and owner assigned
    Client briefing and sign-off completed

    Appendix B — Official References

    Official Reference URL
    NIST Cybersecurity Framework 2.0 https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
    NIST CSF 2.0 PDF https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
    CISA Cybersecurity Performance Goals 2.0 https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0
    CERT-In directions / audit evidence notice https://www.cert-in.org.in/s2cMainServlet?CACODE=CICA-2024-3329&pageid=PUBADV01
    CERT-In official site https://www.cert-in.org.in/