| 1 | The cyber security audit firm must be registered with SECP or the Registrar of firms. Additionally, the company/firm should appear on the Active Taxpayer list (ATL) of income and sales tax issued by FBR. |
| 2 | Any auditee shall not engage any audit firm which has been previously involved as a subsidiary, affiliate, or associate firm of the auditee to avoid conflicts of interest. An affidavit declaring this claim must be submitted before conducting the audit. |
| 3 | The cyber security audit firm should refrain from outsourcing its cyber security audit, penetration testing, and red teaming engagements to any foreign third-party assessor, auditor, or audit firm. |
| 4 | Foreign companies with local branch offices in Pakistan are eligible to apply, provided they are registered with SECP, or the registrar of firms in Pakistan. |
| 5 | Firms must have clear understanding of National policies, procedures and standards related to IT, IT Security, Cyber Security and data protection aspects etc. that are published on Govt websites including MoITT, PTA, nCERT and NTISB. Few such documents include National Cyber Security Policy, Pakistan Cloud First Policy, Accreditation Criteria of Cloud Service Providers, Pakistan Security Standard for Evaluation of Cryptographic and IT Security Devices, Data Protection Bill (draft), Pakistan Information Security Framework (PISF) by nCERT etc. |
| 6 | Cyber security audit Firm should not be a blacklisted entity in the Public or Private sector within Pakistan or abroad, due to any factor including but not limited to unsatisfactory performance, breach of general/specific instructions or NDA, corrupt practices and/or any fraudulent activity. |
| 7 | Cyber security audit firms can perform audits within their respective categories or downward in the hierarchy as outlined in Section-D. For example, firms qualifying for CAT-I can also conduct audits of Service Providers or organizations falling under CAT-II to CAT-IV. Similarly, firms qualifying for CAT-II can audit CAT-III and CAT-IV Service Providers. However, firms qualifying for Cat-IV cannot conduct audits of Service Providers higher in the hierarchy, i.e., CAT-III to CAT-I. |
| 8 | Cyber security audit firm must perform onsite audits by ensuring a detailed review of security measures, processes, and compliance with standards, while identifying weaknesses. |
| 9 | When assessing the cyber security audit firm, nCERT may review several key areas of discipline, including but not limited to: - Assessment methodology
- Profiles of certified individuals/resources
- Data storage and retention policies
- Information sharing policy and procedure
- Tools and reporting methodology
- Experience of Conduct of similar audits
- Sample Audit reports
|
| 10 | nCERT reserves the right to conduct a full assessment at any given point in time. This assessment may require re-submission of all relevant documents submitted at the time of registration or any additional documents necessary for further scrutiny. |
| 11 | In the event of a violation of any clause of the NDA by an approved cybersecurity audit firm, and where such violation is duly proven or established, the relevant information and supporting details may be provided to nCERT. Upon such determination, nCERT reserves the right to terminate the registration of the concerned cybersecurity audit firm. In case of termination, the information shall be duly updated on the nCERT website. |
| 12 | List of approved cyber security Audit firms will be published on the website of nCERT and regularly updated. |
| 13 | nCERT reserves the right to revise cyber security Audit firm registration criteria as and when needed. Revision criteria will be communicated to registered firms as well as published on nCERT website. |
| 14 | Registration may be revoked in the event of any legal or criminal offense. |
| 15 | Organization should implement a quality management system based on ISO 9001 or relevant standard. |
| 16 | For firms currently or previously affiliated with the public sector, experience in auditing critical infrastructure (IT/OT) will be considered on a commensurate basis for firm categorization if provided with appropriate/ verifiable evidence. |
| 17 | Accreditation of audit firms will be renewed every 2x years. |
| 18 | The firm must provide project completion certificates with clearly mentioned client’s name, project scope, and completion date. |
| 19 | The firm must provide at least three client references or a list of previous clients to validate their credibility. |
| 20 | Details and requirements for firm registration are provided in the following tables. (i.e Table B,C,D,E) |
A firm can qualify in specific category for one or more than one domain: IT Security, Cloud Security and OT Security. The organizations while engaging firms will have to select appropriate firm in the relevant category and in the specific domain.