Just a moment...
Press 'Enter' to add multiple search terms. Rules for Better Search
No Folders have been created
Are you sure you want to delete "My most important" ?
NOTE:
Don't have an account? Register Here
<h1>Regulator issues immediate technical clarifications to Cybersecurity and Cyber Resilience Framework, adding Exclusivity and Equivalence principles and operational changes</h1> Regulator issued technical clarifications to the Cybersecurity and Cyber Resilience Framework for regulated entities, introducing Principles of Exclusivity and Equivalence for overlapping regulator oversight, and detailed technical changes to critical-systems definitions, zero-trust implementation, incident response (aligned to entity-approved crisis plans), VAPT/cyber audit submission formats (no explicit vulnerabilities unless requested), log/retention, supply-chain assessment, Market-SOC onboarding, RTO/RPO expectations, and encouragement (not mandate) of ISO 27001 for qualified entities. Portfolio managers and merchant banker thresholds were re-categorised, CERT-level audit guidance adopted, and exchanges/depositories instructed to amend bylaws and notify members. Provisions take immediate effect.