Just a moment...
Press 'Enter' to add multiple search terms. Rules for Better Search
Press 'Enter' after typing page number.
Press 'Enter' after typing page number.
No Folders have been created
Are you sure you want to delete "My most important" ?
NOTE:
Press 'Enter' after typing page number.
Press 'Enter' after typing page number.
Don't have an account? Register Here
Reserve Bank of India (RBI) has informed that an incident of data breach with respect to cards was reported and the matter is under investigation. Independent investigation by a forensic auditor approved under Payment Card Industry Data Security Standard (PCI-DSS) framework is under process.
RBI has set up a Cyber Security and IT Examination (CSITE) Cell within its Department of Banking Supervision in 2015. The Bank issued a comprehensive circular on Cyber Security Framework in Banks on June 2, 2016 covering best practices pertaining to various aspects of cyber security. The circular requires banks to have among other things, a cyber-security policy, cyber crisis management plan, a gap assessment vis-a-vis the baseline requirements indicated in the circular, monitoring certain risk indicators in this area, report unusual cyber security incidents within 2 to 6 hours.
RBI has been carrying out IT Examination of banks from last year. RBI has also set up a Cyber Crisis Management Group to address any major incidents reported including suggesting ways to respond and recover to/from the incidents. Department of Banking Supervision also conducts cyber security preparedness testing among banks on the basis of hypothetical scenarios with the help of CERT-In. RBI has also set up an IT Subsidiary, which would focus, among other things, on cyber security within RBI as well as in regulated entities.
This was stated by Shri Santosh Kumar Gangwar, Minister of State in the Ministry of Finance in written reply to a question in Rajya Sabha today.
Cyber security reporting: banks required to report unusual incidents promptly and maintain crisis management and preparedness. Guidance requiring banks to adopt a comprehensive cyber-security framework including a cyber-security policy, a cyber crisis management plan, gap assessments against baseline requirements, monitoring of risk indicators, and mandatory reporting of unusual cyber security incidents within 2 to 6 hours; supported by RBI's CSITE Cell, Cyber Crisis Management Group, IT examinations, CERT-In preparedness testing, PCI DSS forensic audits for card breaches, and an IT Subsidiary to focus on cyber security across RBI and regulated entities.Press 'Enter' after typing page number.