Cyber security framework for large registrars mandates board-approved policies, CISO, testing, monitoring, and incident reporting. A mandatory cyber security and cyber resilience framework for Qualified RTAs requires board-approved policies, appointment of a CISO, a Technology Committee, and adoption of a risk lifecycle approach-identify, protect, detect, respond and recover-aligned with national critical infrastructure principles and standards such as ISO 27001/27002. Controls include strict access management, two-factor authentication, encryption of data in transit and at rest, network hardening, regular vulnerability assessment and penetration testing, monitoring and logging, incident response and recovery plans with drills, quarterly anonymised incident reporting to the regulator, staff training, and annual independent audits.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
Cyber security framework for large registrars mandates board-approved policies, CISO, testing, monitoring, and incident reporting.
A mandatory cyber security and cyber resilience framework for Qualified RTAs requires board-approved policies, appointment of a CISO, a Technology Committee, and adoption of a risk lifecycle approach-identify, protect, detect, respond and recover-aligned with national critical infrastructure principles and standards such as ISO 27001/27002. Controls include strict access management, two-factor authentication, encryption of data in transit and at rest, network hardening, regular vulnerability assessment and penetration testing, monitoring and logging, incident response and recovery plans with drills, quarterly anonymised incident reporting to the regulator, staff training, and annual independent audits.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.