Section 17 of CTDISR-2025 requires operators to maintain an internal audit function for cybersecurity, conduct continuous compliance monitoring, and report compliance status to the ISSC. This section is often the last one operators address in a preparation programme because it feels like a meta-requirement about monitoring the other requirements, rather than a substantive control in its own right. That's a mistake: Section 17 is what an auditor uses to assess whether your compliance programme is genuinely functional or whether controls exist on paper but nobody is watching whether they're working.

What an Internal Audit Function Means for an ISP

An internal audit function doesn't require a dedicated audit department. For most Pakistani ISPs, what Section 17 requires is a defined process for periodically reviewing whether your CTDISR controls are working as documented, conducted by someone with the independence and knowledge to do it meaningfully, with findings reported to the ISSC.

The independence requirement is the important constraint: the person conducting an internal audit of a specific control shouldn't be the same person responsible for operating that control. A NOC engineer auditing their own procedures isn't an independent review. The CISO reviewing controls implemented by the security team is borderline. For small teams where full independence is difficult, documenting the limitation and compensating with peer review or periodic external assessment is a defensible approach.

The internal audit scope should cover all 19 CTDISR sections over an annual cycle, not just the sections most recently audited externally. A risk-based approach to prioritisation, spending more audit time on higher-risk sections and sections with previous findings, is acceptable and sensible.

The audit methodology should be consistent: for each control reviewed, assess whether the control is implemented, whether it's working as intended, whether the supporting documentation is current, and whether the evidence would satisfy an external auditor. These are the same four questions your CTDISR Audit Readiness work should have used, which means an internal audit is essentially a periodic self-assessment using the same framework.

Continuous Compliance Monitoring

Continuous monitoring is a higher standard than periodic audit: it implies ongoing visibility into control status rather than a snapshot taken once a year. For practical implementation at an ISP, continuous monitoring means having mechanisms that would alert you when a key control fails or degrades between audit cycles, rather than discovering control failures only when the external auditor visits.

Practical continuous monitoring mechanisms for CTDISR controls include: automated checks that MFA is still enforced on privileged accounts (most identity platforms can generate reports on MFA compliance status), NMS alerts for changes to firewall policy or access control lists that should trigger a review, log monitoring for authentication failures above threshold (which can indicate a brute force attempt or a compromised credential), certificate and license expiry monitoring for security tools, and scheduled reminders for time-bound obligations like annual risk assessments, BCP testing, and access recertification.

You don't need a dedicated GRC platform to do this. A well-maintained compliance calendar, combined with monitoring alerts for the most critical controls, delivers continuous monitoring at a scale appropriate for most Pakistani ISPs. What matters is that the monitoring is documented: an auditor should be able to see what you're monitoring, how often, and who reviews the results.

Compliance Reporting to the ISSC

Section 17 requires compliance status to be reported to the ISSC. The ISSC, chaired by the CEO under Section 1's governance requirements, needs to know whether the compliance programme is working and where the gaps are. This reporting serves both governance and accountability purposes: it ensures leadership has visibility into compliance status, and it creates evidence that the organisation is taking CTDISR obligations seriously at the executive level.

Compliance reports to the ISSC should cover: overall compliance posture against all 19 sections (a traffic-light or percentage-based summary works well), any controls that have degraded since the last report, findings from the most recent internal audit cycle, the status of remediation actions from previous audit findings, and any new compliance obligations or regulatory changes to note.

The frequency and format should match the ISSC meeting cadence, which most operators set at quarterly. An annual compliance review is the minimum, but quarterly reporting allows the ISSC to course-correct during the year rather than only reviewing compliance status immediately before the external audit.

Segregation of Duties Consideration

Section 17 includes a segregation of duties requirement: the compliance monitoring function should be independent from the operational functions it's monitoring. This connects back to the independence requirement for internal audit and extends it to the ongoing monitoring function. The practical implication is that whoever owns compliance monitoring (typically the CISO) should not also be the person operating the controls they're monitoring.

For small teams where separation is difficult, documenting the limitation and its compensating controls (external review, peer oversight, clear escalation path when conflicts arise) is the realistic approach. What's not acceptable is having the same person responsible for implementing controls, operating controls, monitoring controls, and reporting on compliance to the ISSC, with no independent check at any point.

ComplianceIQ is built specifically for the continuous monitoring and ISSC reporting requirements in Section 17: the platform tracks control status across all 19 sections, generates compliance reports formatted for ISSC review, and maintains the evidence and audit trail that internal and external audits require. For operators who need the CISO function to own and operate the compliance monitoring programme, CISO-as-a-Service covers Section 17 as a core deliverable.