Cybersecurity Risk Compliance in India
Keywords:
Cybersecurity risk management, The Companies Act 2013, Auditing Standards, Compliance, Auditor’s reports, Vulnerability Assessment and Penetration Testing (VAPT), Cyber Hygiene, Incident Management, Awareness.Abstract
The Cyber risk to all Companies is real and present. It impacts not only financially but also adversely to the company’s reputation and its brand. The Companies Act 2013 has made the Board of Directors responsible for appropriately manage risk to the company (S. 134), while auditors are accountable for reporting any risk to the company (S. 177). The Auditing standard AAS 29 (SA 401) requires computer security auditing. Therefore annual auditor’s report will be incomplete without assessing Cybersecurity risk management policy and its implementation. The Auditors may seek experts help to complete the effective audit. Therefore Cybersecurity risk management is a statutory 4compliance requirement.
References
1. https://www.kroll.com/en-us/global-fraud- and-risk-report-2018
2. https://www.pwc.com/gx/en/ceo- agenda/ceosurvey/2018/gx.html
3. https://www.accenture.com/t20170926T07 2837Z__w__/us-en/_acnmedia/PDF- 61/Accenture-2017- CostCyberCrimeStudy.pdf
4. https://www.google.com/url?sa=t&rct=j& q=&esrc=s&source=web&cd=1&cad=rja &uact=8&ved=0ahUKEwifqamqrMnbAh WDV30KHbURCuYQFggoMAA&url=htt ps%3A%2F%2Fwww.kroll.com%2Fen- us%2Fglobal-fraud-and-risk-report- 2018&usg=AOvVaw3AomBK7jSWO0lw WrwlsEFB Cite this Article Mukesh Saini . Cybersecurity Risk Compliance in India . National Journal of Cyber Security Law. 2018; 1(1): 65-68p
