Cybersecurity reporting for QRTAs now requires six-hour incident notifications and quarterly reports to SEBI via the dedicated email. SEBI requires QRTAs to report all cyber-attacks, threats, incidents and breaches to SEBI within six hours of detection and to the national computer emergency response authority; systems designated as protected must also notify the critical infrastructure protection centre. Quarterly reports detailing incidents and mitigation measures must be submitted within 15 days after each quarter via the dedicated e-mail, using the existing reporting format, and QRTAs must implement systems to ensure immediate compliance.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
Cybersecurity reporting for QRTAs now requires six-hour incident notifications and quarterly reports to SEBI via the dedicated email.
SEBI requires QRTAs to report all cyber-attacks, threats, incidents and breaches to SEBI within six hours of detection and to the national computer emergency response authority; systems designated as protected must also notify the critical infrastructure protection centre. Quarterly reports detailing incidents and mitigation measures must be submitted within 15 days after each quarter via the dedicated e-mail, using the existing reporting format, and QRTAs must implement systems to ensure immediate compliance.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.