CERT-In - Guidelines for Secure Application Design, Development, Implementation & Operations - Version 1.1
AI / PRIVACY / CYBER RELEVANCE
Highly relevant to secure-by-design AI applications, APIs, source code, PII, access controls and testing.
AI: HighPrivacy: HighCybersecurity: Very High
READ FIRST
- Threat modelling
- PII protection
- API security
- SAST/DAST
- secure deployment
- monitoring
PURVIEW
Provides lifecycle-oriented secure-application practices covering design, development, implementation and operations. For AI applications, these controls are relevant not only to the surrounding software but also to APIs, model-serving layers, data pipelines, plugins and integrations through which an AI system can be attacked or can expose data. The guideline therefore provides an engineering bridge between general cybersecurity obligations and the secure-by-design development of AI-enabled products and services.
Classification and legal status. Technical guideline; not per se a universal statutory obligation.