VAPT Reference Guide for Indian Companies
Types of VAPT Testing
| Type | What is tested | Best for |
|---|---|---|
| Web Application VAPT | OWASP Top 10, business logic flaws, authentication, session management | SaaS platforms, e-commerce, banking portals |
| Mobile App VAPT | Android/iOS app binary, API calls, data storage, OWASP Mobile Top 10 | Fintech, health apps, consumer apps |
| API Penetration Testing | REST/GraphQL/SOAP API endpoints, authentication, rate limiting, injection | API-first products, microservices architectures |
| Network VAPT | Internal/external network, firewall config, open ports, lateral movement | Enterprises, data centres, cloud environments |
| Cloud Security Assessment | AWS/Azure/GCP misconfigurations, IAM policies, S3/Blob exposure, logging | Cloud-native companies, SaaS on cloud |
| Red Team Assessment | Full attack simulation β phishing + network + application in scope | Mature organisations, advanced threat modelling |
CVSS Severity Ratings (v3.1)
| Severity | CVSS Score | Action Required |
|---|---|---|
| Critical | 9.0β10.0 | Remediate within 24β72 hours |
| High | 7.0β8.9 | Remediate within 7β14 days |
| Medium | 4.0β6.9 | Remediate within 30 days |
| Low | 0.1β3.9 | Remediate in next sprint cycle |
| Informational | 0.0 | Best practice improvement |
VAPT Compliance Requirements in India
| Regulator/Standard | VAPT Frequency Required |
|---|---|
| RBI (Banks & NBFCs) | Annual + after major changes |
| SEBI (Brokers, Depositories) | Annual VAPT by CERT-In empanelled firm |
| IRDAI (Insurers) | Annual |
| ISO 27001:2022 | Regular (typically annual + quarterly scans) |
| PCI DSS v4.0 | Annual penetration test + quarterly scans |
| SOC 2 | Annual |
| DPDP Act (Section 8) | As part of security safeguards (best practice: annual) |