Cybersecurity and Cyber Resilience Framework: SEBI clarifies scope, equivalence/exclusivity principles and reporting obligations for regulated entities. SEBI clarifies CSCRF scope and compliance: REs must apply either the Principle of Exclusivity for systems used solely for SEBI activities or the Principle of Equivalence where primary regulator frameworks provide equivalent controls; REs must demonstrate which principle is relied upon and SEBI reserves the right to verify compliance submissions made to other regulators.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
Cybersecurity and Cyber Resilience Framework: SEBI clarifies scope, equivalence/exclusivity principles and reporting obligations for regulated entities.
SEBI clarifies CSCRF scope and compliance: REs must apply either the Principle of Exclusivity for systems used solely for SEBI activities or the Principle of Equivalence where primary regulator frameworks provide equivalent controls; REs must demonstrate which principle is relied upon and SEBI reserves the right to verify compliance submissions made to other regulators.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.