Control Library

Controls

CEA control library, test evidence, formally logged exceptions and compensating controls (Module 8 control operations).

43 of 43
IDClauseControl StatementNext DueState
CTL-0015(1)-(3)CISO and Alternate CISO designated with senior-management standing and documented reporting line to Head of Entity.09 Jan 2027Evidence Valid
CTL-0025(9)24x7 India-based Information Security Division maintained with qualified, trained staff.28 Aug 2026Evidence Valid
CTL-0035(12)-(15)CII/critical systems separated with perimeter and web/application security devices; audit clearance on record.18 Sept 2026Pending Government Order
CTL-0045(16)-(17)Critical systems classified and remote access to them individually approved.28 Aug 2026Implemented
CTL-0055(19)Sensitive data stored, processed and backed up within India with encryption at rest and in transit.06 Sept 2026Implemented
CTL-0065(21)Online and offline backups of critical systems maintained, no older than one month, in a separate safe environment.14 Sept 2026Implemented
CTL-0075(25)-(26)Cyber asset register maintained and cyber risk assessment/mitigation plan kept current.06 Sept 2026Pending Government Order
CTL-0085(32)All critical systems synchronized to an approved reference time source.10 Dec 2026Pending Government Order
CTL-0095(35)Incident Response and Recovery Plan maintained and reviewed at least every six months.28 Aug 2026External Dependency
CTL-0105(36)-(38)Continuous security monitoring active on IT/OT with logs retained for the prescribed minimum period.09 Jan 2027Implemented
CTL-0115(40)-(42)IT Act obligations met; vulnerability disclosure process and incident register maintained.06 Sept 2026Evidence Valid
CTL-0126(1)OT network logically and physically isolated from corporate IT and the internet, with documented exceptions.28 Aug 2026External Dependency
CTL-0136(2)Electronic Security Perimeter devices deployed at every OT boundary with an annual rule review.06 Sept 2026Evidence Valid
CTL-0146(3)Dedicated, encrypted communication channels used for inter-entity and remote OT connectivity.25 Sept 2026Implemented
CTL-0156(4)-(5)Remote OT operation limited to approved, India-only, isolated channels with prior risk assessment.10 Nov 2026Implemented
CTL-0166(6)OT trust-level segmentation applied based on asset criticality, security posture and risk.10 Dec 2026Implemented
CTL-0176(7)Inter-entity OT communication paths registered with owner and cyber protection evidence.11 Oct 2026Implemented
CTL-0186(8)-(9)Only compliant, trusted-source OT equipment procured and commissioned.18 Sept 2026Pending Government Order
CTL-0197(1)CISO meets qualification criteria: 15+ years relevant experience, degree/equivalent, tenure ≥ 3 years.18 Sept 2026Evidence Valid
CTL-0207(2)CISO reviews policies, registers and reference time source configuration on a defined cadence.18 Sept 2026Pending Government Order
CTL-0217(3)CISO conducts or commissions random tests of controls and retains patch/IP inventory oversight.10 Nov 2026Evidence Valid
CTL-0227(4)CISO office maintains threat-intelligence review and retention-policy compliance oversight.14 Sept 2026Overdue
CTL-0238(1)-(10)Cyber Security Policy covers governance, roles, asset management and access control topics.06 Sept 2026External Dependency
CTL-0248(11)-(20)Cyber Security Policy covers network security, monitoring, incident management and vendor topics.09 Jan 2027Pending Government Order
CTL-0258(21)-(33)Cyber Security Policy covers training, physical security, retention, BCP alignment and remaining Regulation 8 topics.09 Jan 2027Implemented
CTL-0268 (review)Cyber Security Policy reviewed and re-approved by Head/Board at least annually.10 Dec 2026Evidence Valid
CTL-0279Cyber Crisis Management Plan (CCMP) authored with detection SOP, crisis criteria and scenario library.09 Jan 2027Evidence Valid
CTL-0289 (exercise)Annual crisis exercise conducted covering a scenario not repeated until the full library is tested.28 Aug 2026Implemented
CTL-02910Crisis communications directory maintained and essential-communications readiness verified.10 Dec 2026Evidence Valid
CTL-03010 (after-action)After-action report produced post-exercise/incident and CCMP updated with lessons learned.09 Jan 2027Evidence Valid
CTL-03111(1)-(3)Vendor Cyber SLA/NDA executed with confidentiality obligations surviving contract completion.14 Sept 2026Overdue
CTL-03211(4)-(5)Vendor patch/update commitments digitally signed or validated, available for contract or useful life.28 Aug 2026Evidence Valid
CTL-03311(6)-(7)Vendor BOM/SBOM submitted and vulnerability disclosure process in place with CSIRT-Power forwarding.14 Sept 2026Implemented
CTL-03412(1)-(2)DGR/prosumer vendors host data in India with encrypted, mutually authenticated remote access.28 Aug 2026Implemented
CTL-03512(3)Trusted-source information verified for all vendor-supplied OT equipment.10 Dec 2026Implemented
CTL-03613(1)Annual cyber audit commissioned with independent auditor and defined scope.14 Sept 2026Pending Government Order
CTL-03713(2)Previous audit findings closed and verified before the next audit cycle begins.18 Sept 2026Evidence Valid
CTL-03813(3)Audit report submitted within six weeks of commencement with remediation deadlines tracked.10 Nov 2026Implemented
CTL-03914(1)CISO reviews audit findings and reports major/critical/high items to Head/Board.28 Aug 2026Implemented
CTL-04014(2)Entity maintains readiness for third-party verification on Ministry of Power / CISO request.18 Sept 2026Overdue
CTL-04115(a)Annual self-audit performed covering every applicable regulation.25 Sept 2026Pending Government Order
CTL-04215(b)Non-compliances identified in self-audit closed before the next annual self-audit.28 Aug 2026Implemented
CTL-04315(c)Self-audit records retained for the prescribed minimum period and available for inspection.11 Oct 2026Pending Government Order