Cyber Security and Cyber Resilience framework for Registrars to an Issue / Share Transfer Agents (hereinafter referred to as RTAs)
Show AI Summary
Cyber security framework for large registrars mandates board-approved policies, CISO, testing, monitoring, and incident reporting.
A mandatory cyber security and cyber resilience framework for Qualified RTAs requires board-approved policies, appointment of a CISO, a Technology Committee, and adoption of a risk lifecycle approach-identify, protect, detect, respond and recover-aligned with national critical infrastructure principles and standards such as ISO 27001/27002. Controls include strict access management, two-factor authentication, encryption of data in transit and at rest, network hardening, regular vulnerability assessment and penetration testing, monitoring and logging, incident response and recovery plans with drills, quarterly anonymised incident reporting to the regulator, staff training, and annual independent audits.