Questionnaire for Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated
Entities (REs)
To be filled by Client
Please give the answers based on your best effort. You may attach any other document you need to
confirm your data.
If the answer is not currently available – please put “Unknown”
If it is not applicable, please put “Not Applicable”. If the answer is None – please put “None”.
Sr. no. Questions Answers
Size of firm as per SEBI direction
1
Do you have any ISMS policy, including
2 cyber incident and resilience etc. (If
not then please give your comment)
SIEM and SOC details, which is
3
currently installed
Do you have Organisation Chart? If yes
4
then please share the screenshot.
Do you have the DR drill calendar and
5
reports?
Have you performed such Audit &
6 YES
VAPT previously?
No. of locations to be covered in
7
this Audit HO
8 Employees Locations and their count
9 No. of IT Team Members
Network Diagrams High level and low
10
level view
Is there a Windows Active Directory
11 domain server client architecture or
NO
Workgroup or any other Identity
management System?
Are any servers hosted on Cloud
12 services? NO
If yes which Cloud Services is used?
13 How many servers hosted on cloud NO
Sr. no. Questions Answers
services?
14 What services do these Cloud hosted N.A.
servers offer?
How many end point devices do you – Desktops – Desktops.
15
have?
Please share infrastructure details like Firewall, Switches- FW, Switches.
16
Firewalls, Routers, and Switches etc...
Please provide details on your backup.
17
What do you backup up and where?
18 Do you have VLAN infrastructure?
EDR (Endpoint Detection and
19
Response) Tool
20 Applications Details
21 Email Solution details
22 Antivirus Solution Details
23 RMM/SOC Tool details
24 Websites Details
25 How many Static IP's do you have?
Other Details: (If you want to mention anything here)