Advisory for SEBI Regulated Entities (REs) regarding Cybersecurity best practices
Show AI Summary
Cybersecurity best practices advisory requires regulated entities to strengthen incident response, patching, MFA and third party risk controls.
Advisory requires SEBI regulated entities to adopt comprehensive cybersecurity measures, define senior information-security roles, maintain incident response plans, integrate compliance reporting with SEBI audit mechanisms, and implement operational controls including phishing detection and takedown, routine patch management and VAPT with timely remediation, robust log retention, encryption of sensitive and PII data, data leakage prevention, strong authentication with multi-factor authentication, least-privilege/zero-trust privilege management, network and endpoint protections, cloud security safeguards, prompt implementation of CERT-In/CSIRT-Fin advisories, mitigation of third-party concentration risk, and consideration of external audits and ISO certification.