Section 3(3)(h) in The Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018
(h)ensure conduct of internal and external Information Security audits periodically according to Information Security Management System(ISMS) as suggested in clause (b). The Standard Operating Procedure (SOP) released by National Critical Information Infrastructure Protection Centre (NCIIPC) for "Auditing of CIIs/Protected Systems by Private/Government Organisation" shall be strictly followed;