Instrument 29 | D. CERT-In / Cybersecurity / AI Security

GUIDELINETECHNICAL GUIDELINE

CERT-In - Guidelines for Secure Application Design, Development, Implementation & Operations - Version 1.1

CERT-In / MeitY2024Technical GuidelineTechnology

AI / PRIVACY / CYBER RELEVANCE

Highly relevant to secure-by-design AI applications, APIs, source code, PII, access controls and testing.

AI: HighPrivacy: HighCybersecurity: Very High

READ FIRST

  • Threat modelling
  • PII protection
  • API security
  • SAST/DAST
  • secure deployment
  • monitoring

PURVIEW

Provides lifecycle-oriented secure-application practices covering design, development, implementation and operations. For AI applications, these controls are relevant not only to the surrounding software but also to APIs, model-serving layers, data pipelines, plugins and integrations through which an AI system can be attacked or can expose data. The guideline therefore provides an engineering bridge between general cybersecurity obligations and the secure-by-design development of AI-enabled products and services.

Classification and legal status. Technical guideline; not per se a universal statutory obligation.

Open document Download PDF Copyright remains with the publishing authority. For informational purposes only.

Read the official document

This browser cannot display the PDF in the page. Open the document or download the PDF.

Keywords

secure by designAPI securitySASTDASTthreat modellingPII

Source note

CERT-In official Version 1.1, Jan 2024, reviewed.

Legal status indicates whether this resource is legislation, delegated regulation, regulatory direction, guidance, policy, research or technical material. Inclusion in this library does not by itself make a document legally binding.

This tool provides research navigation only and does not constitute legal advice or a determination of legal applicability.

Back to the framework library