Cyber security reporting for stock brokers and depository participants: quarterly incident reports, specified auditors, and mandated audit periodicity. SEBI requires stock brokers and depository participants to submit quarterly reports on cyber-attacks, threats, vulnerabilities and mitigation measures in a prescribed format within specified timelines; specifies authorised auditor qualifications (CERT-IN empanelled, DISA (ICAI), CISA, CISM, CISSP) for cybersecurity audits; sets audit periodicity as annual for depository participants, annual for Type I and II brokers and half-yearly for Type III brokers; and directs exchanges and depositories to amend rules, notify members, and report implementation to SEBI.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
Cyber security reporting for stock brokers and depository participants: quarterly incident reports, specified auditors, and mandated audit periodicity.
SEBI requires stock brokers and depository participants to submit quarterly reports on cyber-attacks, threats, vulnerabilities and mitigation measures in a prescribed format within specified timelines; specifies authorised auditor qualifications (CERT-IN empanelled, DISA (ICAI), CISA, CISM, CISSP) for cybersecurity audits; sets audit periodicity as annual for depository participants, annual for Type I and II brokers and half-yearly for Type III brokers; and directs exchanges and depositories to amend rules, notify members, and report implementation to SEBI.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.