Regulatory & Compliance Advisory
India Regulatory & Compliance (CERT-In, DPDP)
Advisory and implementation support for CERT-In 2022 Directions and India’s Digital Personal Data Protection Act.
- 6-hour incident reporting SOP
- 180-day log retention controls
- Consent & breach workflows
ISO/IEC 27001:2022 (ISMS)
End-to-end ISMS consulting including transition from ISO 27001:2013.
- Risk assessment & SoA
- Annex A control mapping
- Certification readiness
NIST Cybersecurity Framework (CSF 2.0)
Governance-driven cybersecurity programs aligned with NIST CSF 2.0.
- Current & target profiles
- Govern / Identify / Protect mapping
- Risk & KPI integration
GDPR (EU)
GDPR compliance for EU and non-EU organizations handling EU personal data.
- RoPA & DPIA
- Data subject rights processes
- Cross-border transfer assessments
SOX 404 – IT General Controls
ITGC design, documentation, and testing for SOX Section 404 compliance.
- Access & change management
- Backup & DR controls
- Audit-ready documentation
PCI DSS v4.0.1
Payment security advisory and readiness for PCI DSS v4.0.1.
- CDE scoping
- MFA & vulnerability management
- ROC / AOC support
Cybersecurity Engineering & Cloud Security
Secure Architecture & Zero Trust
- CIS benchmarks & hardening
- Identity & access management
- Zero Trust & PAM
DevSecOps & Secure SDLC
- Threat modeling
- SAST / DAST / SBOM
- IaC & CI/CD security
Cloud Security & AI Governance
- Single / multi / hybrid cloud
- Kubernetes & serverless security
- Secure AI & RAG implementations
