Skip to main content

Government

CM Dashboard Odisha: CERT-In cyber security audit

Full CERT-In empanelled audit of the Chief Minister's real-time governance dashboard.

Scale

State-wide executive platform

Government of Odisha

  • CERT-In Audit
  • Penetration Testing

The brief

CERT-In empanelled audit of the Chief Minister's dashboard, which aggregates departmental data for state level decision making.

What we did

  • CERT-In empanelled audit across application, API and infrastructure
  • Authorisation testing across departmental data boundaries
  • Configuration and hardening review of the hosting environment
  • Audit certificate issued after remediation and retesting

A Chief Minister's dashboard is an aggregation platform. It pulls from many departmental systems and presents the combined picture to a small number of very senior users. That shape creates a specific risk: the aggregate is more sensitive than any of its parts, and the access model has to be tighter than the systems feeding it.

Aggregation is the risk

Individually, departmental performance data is often routine. Combined, correlated and presented as a single view of the state's operations, it becomes something a state government would not want read by an outsider. The assessment treated the dashboard as a higher classification asset than its sources, which is the correct posture and not always the one the architecture reflected at the start.

Where the work concentrated

Access control across departmental boundaries, since the dashboard's value depends on cross departmental visibility and its risk comes from the same place. Session handling for a small user population with high privilege. And the ingestion path, because a platform that pulls from many systems is only as trustworthy as the least controlled of those connections.

Infrastructure and configuration

The audit covered the hosting environment as well as the application: exposed services, patch position, transport security, administrative access paths, and logging sufficient to reconstruct events under the CERT-In retention requirement.

What was handed over

A CERT-In format audit report, remediation guidance, retesting of every finding, and the audit certificate once closure was verified.

Audit type
CERT-In empanelled
Emphasis
Aggregation and access control
Outcome
Certificate issued after retest

Engagement detail is summarised. Specific findings, payloads and architecture remain confidential under our client agreements.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.