Network
Getting enrolled with UIDAI, allows organizations to provide E-KYC and Aadhar based authentication. Organizations that are looking to become an empaneled KYC User Agency (KUA) or looking to integrate with Aadhaar Authentication Services (AUA), are required to get a comprehensive security assessment and corresponding compliance certification from a CERT-In Empaneled Security Auditor ensuring compliance with UIDAI standards and specifications.
The latest version of UIDAI Information Security Policy for AUAs and KUAs outlines a comprehensive process of technical and operational audit. The following domains (but not limited to) falls under the focus of the audit, thereby improving your security preparedness and technology defense:
Security of the authentication devices and applications
Network
Systems
Key management
Data vault requirements
Security framework policies for requesting entity compliance requirements
These changes include obtaining consent, transparency and purpose limitation, amongst others. As per the guidelines of UIDAI, client applications of the organization using Aadhaar based authentication need to undergo periodic annual auditing or need basis, by Information Systems Auditors certified by CERT-IN. The compliance audit report is then to be submitted to UIDAI or shared upon request. The assessment is mandatory for any organization that wants to comprise Aadhar based authentication in their business process.
As a CERT-IN empanelled body, QRC will help you understand, manage and comply with UIDAI Security Audit & Compliance requirements that are released on a periodic basis.