Cyber Security & Cyber Resilience framework for KYC Registration Agencies mandates board approved policies, CISO, controls, VAPT and quarterly reporting. KRAs must implement a Board approved Cyber Security and Cyber Resilience policy by January 1, 2020, appoint a CISO, form a Technology Committee for quarterly reviews, and follow an identify protect detect respond recover lifecycle. Required measures include least privilege access and two factor authentication, encrypted logging and data, baseline hardening, network security devices, VAPT including annual penetration testing and pre commissioning testing, continuous monitoring and alerting, incident forensic analysis and drills, quarterly reporting of cyber incidents to SEBI, and annual independent audits with Board comments.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
Cyber Security & Cyber Resilience framework for KYC Registration Agencies mandates board approved policies, CISO, controls, VAPT and quarterly reporting.
KRAs must implement a Board approved Cyber Security and Cyber Resilience policy by January 1, 2020, appoint a CISO, form a Technology Committee for quarterly reviews, and follow an identify protect detect respond recover lifecycle. Required measures include least privilege access and two factor authentication, encrypted logging and data, baseline hardening, network security devices, VAPT including annual penetration testing and pre commissioning testing, continuous monitoring and alerting, incident forensic analysis and drills, quarterly reporting of cyber incidents to SEBI, and annual independent audits with Board comments.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.