SEBI framework requires REs to use MeitY empaneled CSPs, retain data ownership and ensure explicit contractual controls. SEBI's cloud framework requires REs to adopt Board approved GRC, remain fully accountable for cloud hosted data and services, use MeitY empaneled CSPs with STQC (or equivalent) audited data centres, and ensure explicit, enforceable contracts that delineate responsibilities, provide SEBI/RE audit and access rights, mandate encryption and key management (preferably BYOK/BYOE and HSM), continuous monitoring, incident notification and forensic support, and integrated reporting of compliance in systems audit, cybersecurity audit and VAPT reports within prescribed transition timelines.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
SEBI framework requires REs to use MeitY empaneled CSPs, retain data ownership and ensure explicit contractual controls.
SEBI's cloud framework requires REs to adopt Board approved GRC, remain fully accountable for cloud hosted data and services, use MeitY empaneled CSPs with STQC (or equivalent) audited data centres, and ensure explicit, enforceable contracts that delineate responsibilities, provide SEBI/RE audit and access rights, mandate encryption and key management (preferably BYOK/BYOE and HSM), continuous monitoring, incident notification and forensic support, and integrated reporting of compliance in systems audit, cybersecurity audit and VAPT reports within prescribed transition timelines.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.