Cybersecurity obligations for KYC Registration Agencies updated; enhanced VAPT and biannual cyber audit requirements imposed. KRAs must identify, classify and board approve critical assets, maintain inventories of hardware, software and network resources, and subject new or critical systems to vulnerability scanning and penetration testing prior to commissioning. Periodic VAPT covering critical infrastructure must be conducted at least annually, by CERT In empaneled organisations, with final reports approved by the Technology Committee and submitted to the regulator. Vulnerabilities must be remediated immediately and closure certified within three months. KRAs must undertake comprehensive cyber audits twice per financial year and submit an MD/CEO compliance declaration with audit reports.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
Cybersecurity obligations for KYC Registration Agencies updated; enhanced VAPT and biannual cyber audit requirements imposed.
KRAs must identify, classify and board approve critical assets, maintain inventories of hardware, software and network resources, and subject new or critical systems to vulnerability scanning and penetration testing prior to commissioning. Periodic VAPT covering critical infrastructure must be conducted at least annually, by CERT In empaneled organisations, with final reports approved by the Technology Committee and submitted to the regulator. Vulnerabilities must be remediated immediately and closure certified within three months. KRAs must undertake comprehensive cyber audits twice per financial year and submit an MD/CEO compliance declaration with audit reports.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.