Vulnerability assessment and penetration testing required by MIIs, with empaneled testers and mandatory remediation and reporting. MIIs must classify and maintain Board approved inventories of critical assets and perform periodic VAPT covering all critical systems, using CERT In empaneled firms; final VAPT reports, after standing committee approval, must be submitted to the regulator and vulnerabilities remediated promptly with closure compliance filed within three months. MIIs must conduct VAPT before commissioning new critical systems, undertake periodic cyber audits, submit MD/CEO compliance declarations with audit reports, amend governance instruments as necessary, and report implementation status to the regulator immediately.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
Vulnerability assessment and penetration testing required by MIIs, with empaneled testers and mandatory remediation and reporting.
MIIs must classify and maintain Board approved inventories of critical assets and perform periodic VAPT covering all critical systems, using CERT In empaneled firms; final VAPT reports, after standing committee approval, must be submitted to the regulator and vulnerabilities remediated promptly with closure compliance filed within three months. MIIs must conduct VAPT before commissioning new critical systems, undertake periodic cyber audits, submit MD/CEO compliance declarations with audit reports, amend governance instruments as necessary, and report implementation status to the regulator immediately.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.