Controls
CEA control library, test evidence, formally logged exceptions and compensating controls (Module 8 control operations).
43 of 43
| ID | Clause | Control Statement | Next Due | State |
|---|---|---|---|---|
| CTL-001 | 5(1)-(3) | CISO and Alternate CISO designated with senior-management standing and documented reporting line to Head of Entity. | 09 Jan 2027 | Evidence Valid |
| CTL-002 | 5(9) | 24x7 India-based Information Security Division maintained with qualified, trained staff. | 28 Aug 2026 | Evidence Valid |
| CTL-003 | 5(12)-(15) | CII/critical systems separated with perimeter and web/application security devices; audit clearance on record. | 18 Sept 2026 | Pending Government Order |
| CTL-004 | 5(16)-(17) | Critical systems classified and remote access to them individually approved. | 28 Aug 2026 | Implemented |
| CTL-005 | 5(19) | Sensitive data stored, processed and backed up within India with encryption at rest and in transit. | 06 Sept 2026 | Implemented |
| CTL-006 | 5(21) | Online and offline backups of critical systems maintained, no older than one month, in a separate safe environment. | 14 Sept 2026 | Implemented |
| CTL-007 | 5(25)-(26) | Cyber asset register maintained and cyber risk assessment/mitigation plan kept current. | 06 Sept 2026 | Pending Government Order |
| CTL-008 | 5(32) | All critical systems synchronized to an approved reference time source. | 10 Dec 2026 | Pending Government Order |
| CTL-009 | 5(35) | Incident Response and Recovery Plan maintained and reviewed at least every six months. | 28 Aug 2026 | External Dependency |
| CTL-010 | 5(36)-(38) | Continuous security monitoring active on IT/OT with logs retained for the prescribed minimum period. | 09 Jan 2027 | Implemented |
| CTL-011 | 5(40)-(42) | IT Act obligations met; vulnerability disclosure process and incident register maintained. | 06 Sept 2026 | Evidence Valid |
| CTL-012 | 6(1) | OT network logically and physically isolated from corporate IT and the internet, with documented exceptions. | 28 Aug 2026 | External Dependency |
| CTL-013 | 6(2) | Electronic Security Perimeter devices deployed at every OT boundary with an annual rule review. | 06 Sept 2026 | Evidence Valid |
| CTL-014 | 6(3) | Dedicated, encrypted communication channels used for inter-entity and remote OT connectivity. | 25 Sept 2026 | Implemented |
| CTL-015 | 6(4)-(5) | Remote OT operation limited to approved, India-only, isolated channels with prior risk assessment. | 10 Nov 2026 | Implemented |
| CTL-016 | 6(6) | OT trust-level segmentation applied based on asset criticality, security posture and risk. | 10 Dec 2026 | Implemented |
| CTL-017 | 6(7) | Inter-entity OT communication paths registered with owner and cyber protection evidence. | 11 Oct 2026 | Implemented |
| CTL-018 | 6(8)-(9) | Only compliant, trusted-source OT equipment procured and commissioned. | 18 Sept 2026 | Pending Government Order |
| CTL-019 | 7(1) | CISO meets qualification criteria: 15+ years relevant experience, degree/equivalent, tenure ≥ 3 years. | 18 Sept 2026 | Evidence Valid |
| CTL-020 | 7(2) | CISO reviews policies, registers and reference time source configuration on a defined cadence. | 18 Sept 2026 | Pending Government Order |
| CTL-021 | 7(3) | CISO conducts or commissions random tests of controls and retains patch/IP inventory oversight. | 10 Nov 2026 | Evidence Valid |
| CTL-022 | 7(4) | CISO office maintains threat-intelligence review and retention-policy compliance oversight. | 14 Sept 2026 | Overdue |
| CTL-023 | 8(1)-(10) | Cyber Security Policy covers governance, roles, asset management and access control topics. | 06 Sept 2026 | External Dependency |
| CTL-024 | 8(11)-(20) | Cyber Security Policy covers network security, monitoring, incident management and vendor topics. | 09 Jan 2027 | Pending Government Order |
| CTL-025 | 8(21)-(33) | Cyber Security Policy covers training, physical security, retention, BCP alignment and remaining Regulation 8 topics. | 09 Jan 2027 | Implemented |
| CTL-026 | 8 (review) | Cyber Security Policy reviewed and re-approved by Head/Board at least annually. | 10 Dec 2026 | Evidence Valid |
| CTL-027 | 9 | Cyber Crisis Management Plan (CCMP) authored with detection SOP, crisis criteria and scenario library. | 09 Jan 2027 | Evidence Valid |
| CTL-028 | 9 (exercise) | Annual crisis exercise conducted covering a scenario not repeated until the full library is tested. | 28 Aug 2026 | Implemented |
| CTL-029 | 10 | Crisis communications directory maintained and essential-communications readiness verified. | 10 Dec 2026 | Evidence Valid |
| CTL-030 | 10 (after-action) | After-action report produced post-exercise/incident and CCMP updated with lessons learned. | 09 Jan 2027 | Evidence Valid |
| CTL-031 | 11(1)-(3) | Vendor Cyber SLA/NDA executed with confidentiality obligations surviving contract completion. | 14 Sept 2026 | Overdue |
| CTL-032 | 11(4)-(5) | Vendor patch/update commitments digitally signed or validated, available for contract or useful life. | 28 Aug 2026 | Evidence Valid |
| CTL-033 | 11(6)-(7) | Vendor BOM/SBOM submitted and vulnerability disclosure process in place with CSIRT-Power forwarding. | 14 Sept 2026 | Implemented |
| CTL-034 | 12(1)-(2) | DGR/prosumer vendors host data in India with encrypted, mutually authenticated remote access. | 28 Aug 2026 | Implemented |
| CTL-035 | 12(3) | Trusted-source information verified for all vendor-supplied OT equipment. | 10 Dec 2026 | Implemented |
| CTL-036 | 13(1) | Annual cyber audit commissioned with independent auditor and defined scope. | 14 Sept 2026 | Pending Government Order |
| CTL-037 | 13(2) | Previous audit findings closed and verified before the next audit cycle begins. | 18 Sept 2026 | Evidence Valid |
| CTL-038 | 13(3) | Audit report submitted within six weeks of commencement with remediation deadlines tracked. | 10 Nov 2026 | Implemented |
| CTL-039 | 14(1) | CISO reviews audit findings and reports major/critical/high items to Head/Board. | 28 Aug 2026 | Implemented |
| CTL-040 | 14(2) | Entity maintains readiness for third-party verification on Ministry of Power / CISO request. | 18 Sept 2026 | Overdue |
| CTL-041 | 15(a) | Annual self-audit performed covering every applicable regulation. | 25 Sept 2026 | Pending Government Order |
| CTL-042 | 15(b) | Non-compliances identified in self-audit closed before the next annual self-audit. | 28 Aug 2026 | Implemented |
| CTL-043 | 15(c) | Self-audit records retained for the prescribed minimum period and available for inspection. | 11 Oct 2026 | Pending Government Order |