Industries
Data centres and cloud providers
Physical and logical controls, uptime and Tier commitments, multi-tenant isolation and customer audit support across colocation and cloud services.
Applicable regulations
- ISO 27001 ISMS and ISO 22301 business continuity
- SOC 2 for service assurance
- DPDP Act 2023 and data-localisation for hosted data
- Customer audit and security-questionnaire requirements
Common cybersecurity risks
- Multi-tenant isolation and shared-infrastructure risk
- Physical-access and environmental control failures
- Availability and uptime commitments under threat from DDoS and power loss
- Customer data-localisation and audit-support gaps
Audit findings we typically see
- Isolation controls not independently evidenced
- BCP and DR not tested to RPO and RTO commitments
- Incomplete physical-access logs
- No reusable customer-audit evidence pack
Services required
Our engagement approach
- Scope. Map physical, logical and multi-tenant boundaries, and the customer commitments behind them.
- Assess. ISO and SOC 2 gap testing, BCP and DR review, and isolation testing.
- Remediate. Control design and evidence for uptime, isolation and audit support.
- Assure. Certification and attestation, plus a reusable customer-audit pack.
Expected evidence
- Physical and logical control evidence
- BCP and DR test results against RPO and RTO
- Isolation-testing results
- Customer-audit evidence pack
Indicative timeline
A certification programme usually runs 3 to 6 months.
Deliverables
- ISO 27001 and ISO 22301 evidence
- SOC 2 readiness
- Isolation and DR test reports
- Customer-audit support pack
Related case study
Free tool
Try it free →Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
