Security & Compliance Framework
Zero Trust, the patch and vulnerability lifecycle, SIEM, and Indian mandates: the IT Act, CERT-In, RBI, IRDAI, and data residency.
Zero Trust as the operating assumption
Zero Trust replaces the old castle-and-moat model with a simple principle: never trust, always verify. Every access request is authenticated, authorised, and continuously evaluated regardless of network location, and privileges are granted least-first.
The vulnerability lifecycle
- Discover — continuously scan the estate for known vulnerabilities and misconfigurations.
- Prioritise — rank by exploitability and business impact, not raw CVSS alone.
- Remediate — patch on a defined SLA, with tested rollback.
- Verify — re-scan to confirm closure and feed metrics back to leadership.
SIEM and detection
A Security Information and Event Management platform centralises logs and applies correlation rules and analytics to surface threats. Combined with CERT-In's log-retention and six-hour incident-reporting requirements, a well-run SIEM is both a security control and a compliance instrument.
The Indian regulatory stack
Compliance is not a single checkbox but a layered set of obligations — the IT Act and DPDP Act at the base, CERT-In directions for incident handling, and sector regulators like RBI and IRDAI imposing data-localisation and resilience duties on regulated entities. Designing for the strictest applicable mandate keeps the whole estate audit-ready.
Mapping this to your own estate?