Government dashboards look similar from outside and differ considerably underneath, because each is shaped by the systems that feed it and the administrative structure it serves. The Jammu and Kashmir engagement followed the same CERT-In audit discipline as our other public sector work, applied to a different data model and a different set of departmental boundaries.
What an empanelled audit actually requires
CERT-In empanelment sets expectations about method and evidence, not just about outcome. The audit has to cover the application, the interfaces and the infrastructure, findings have to be reproducible, and the closure evidence has to stand up to review by someone who was not present.
That is why our audits do not conclude at the report. The certificate follows retesting, and retesting is where the difference between a fix and a partial fix becomes visible.
Where the work concentrated
Administrative hierarchy is the interesting part of a UT dashboard. Access is layered by level and by department, and the boundaries have to hold in both directions. We tested each level against the data of every other level rather than sampling, because sampling on authorisation is how gaps survive audits.
Alongside that: session management, transport configuration, exposed administrative surfaces, and whether the logging in place would actually support an incident reconstruction under the 180 day retention requirement.
What was handed over
The audit report in CERT-In format, a remediation tracker, retest evidence, and the certificate on closure.












