Cyber Security and Cyber Resilience framework for Mutual Funds / Asset Management Companies (AMCs)
Show AI Summary
Cyber security framework requirement: mutual funds and AMCs must implement governance, technical controls, testing and mandatory reporting.
SEBI mandates all mutual funds and AMCs to adopt a board approved Cyber Security and Cyber Resilience framework requiring designation of a CISO, Technology Committee oversight, and implementation of the identify protect detect respond recover lifecycle. Operational controls include least privilege access, two factor authentication, encryption of data in motion and data at rest, hardened systems, patch management, VAPT and annual penetration testing, continuous monitoring and logging, incident response and recovery planning, quarterly reporting of cyber incidents to SEBI, anonymised threat sharing, periodic training, annual independent audits, and vendor compliance obligations.