System and Network Audit requirements mandate independent audits, board review and regulator submission to assure IT security and compliance. SEBI mandates a revised System and Network Audit regime for Market Infrastructure Institutions requiring independent auditors selected under specified norms to assess governance, IT and network architecture, security, change control, business continuity, vendor management and related areas. Audit reports must include issue logs, risk rated non compliances, remediation plans, evidence and management responses, be placed before the Governing Board and submitted to SEBI with a joint MD/CEO and CTO declaration. Follow on audits or verified Action Taken Reports must close findings within prescribed timelines; special audit frequency applies for systems designated as protected.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
System and Network Audit requirements mandate independent audits, board review and regulator submission to assure IT security and compliance.
SEBI mandates a revised System and Network Audit regime for Market Infrastructure Institutions requiring independent auditors selected under specified norms to assess governance, IT and network architecture, security, change control, business continuity, vendor management and related areas. Audit reports must include issue logs, risk rated non compliances, remediation plans, evidence and management responses, be placed before the Governing Board and submitted to SEBI with a joint MD/CEO and CTO declaration. Follow on audits or verified Action Taken Reports must close findings within prescribed timelines; special audit frequency applies for systems designated as protected.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.