Information technology governance requires depositories to adopt board-level IT oversight, appoint a CISO and strengthen BCP. SEBI requires depositories to establish a Board-level IT Strategy Committee and an executive IT Steering Committee to align IT with business objectives and implement IT strategy. Depositories must adopt an IT strategy document and an Information Security policy approved by the Board and reviewed annually, create an Office of Information Security, appoint a Chief Information Security Officer to manage IT risk and incidents, and designate a senior official to head the Business Continuity Plan; necessary systems must be implemented and bye-laws amended where applicable.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
Information technology governance requires depositories to adopt board-level IT oversight, appoint a CISO and strengthen BCP.
SEBI requires depositories to establish a Board-level IT Strategy Committee and an executive IT Steering Committee to align IT with business objectives and implement IT strategy. Depositories must adopt an IT strategy document and an Information Security policy approved by the Board and reviewed annually, create an Office of Information Security, appoint a Chief Information Security Officer to manage IT risk and incidents, and designate a senior official to head the Business Continuity Plan; necessary systems must be implemented and bye-laws amended where applicable.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.