Compliance Checklist
A readiness checklist spanning CERT-In, RBI, and the IT Act / DPDP requirements.
Incident handling
- Documented incident-response plan with named owners.
- CERT-In six-hour incident-reporting workflow in place and rehearsed.
- Log retention configured to the mandated period and tamper-evident.
Data protection & residency
- Data classification mapping personal and sensitive data.
- Data-residency controls aligned to RBI / IRDAI / DPDP obligations.
- Breach-notification process consistent with the DPDP Act.
Resilience
- Tested DR plan with documented RPO/RTO per workload.
- Immutable / air-gapped backup copy maintained.
- Annual (or better) recovery test with a signed-off report.
Mapping this to your own estate?