<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://www.taxtmi.com/rss_sitemap/rss_feed_blog.xsl?v=1750492856"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyber Security and Cyber Resilience framework for Registrars to an Issue / Share Transfer Agents (hereinafter referred to as RTAs)</title>
    <link>https://www.taxtmi.com/circulars?id=57851</link>
    <description>A mandatory cyber security and cyber resilience framework for Qualified RTAs requires board-approved policies, appointment of a CISO, a Technology Committee, and adoption of a risk lifecycle approach-identify, protect, detect, respond and recover-aligned with national critical infrastructure principles and standards such as ISO 27001/27002. Controls include strict access management, two-factor authentication, encryption of data in transit and at rest, network hardening, regular vulnerability assessment and penetration testing, monitoring and logging, incident response and recovery plans with drills, quarterly anonymised incident reporting to the regulator, staff training, and annual independent audits.</description>
    <language>en-us</language>
    <pubDate>Fri, 08 Sep 2017 00:00:00 +0530</pubDate>
    <lastBuildDate>Sat, 01 Dec 2018 11:17:00 +0530</lastBuildDate>
    <generator>TaxTMI RSS Generator</generator>
    <atom:link href="https://www.taxtmi.com/rss_feed_blog?id=544891" rel="self" type="application/rss+xml"/>
    <item>
      <title>Cyber Security and Cyber Resilience framework for Registrars to an Issue / Share Transfer Agents (hereinafter referred to as RTAs)</title>
      <link>https://www.taxtmi.com/circulars?id=57851</link>
      <description>A mandatory cyber security and cyber resilience framework for Qualified RTAs requires board-approved policies, appointment of a CISO, a Technology Committee, and adoption of a risk lifecycle approach-identify, protect, detect, respond and recover-aligned with national critical infrastructure principles and standards such as ISO 27001/27002. Controls include strict access management, two-factor authentication, encryption of data in transit and at rest, network hardening, regular vulnerability assessment and penetration testing, monitoring and logging, incident response and recovery plans with drills, quarterly anonymised incident reporting to the regulator, staff training, and annual independent audits.</description>
      <category>Circulars</category>
      <law>SEBI</law>
      <pubDate>Fri, 08 Sep 2017 00:00:00 +0530</pubDate>
      <guid isPermaLink="true">https://www.taxtmi.com/circulars?id=57851</guid>
    </item>
  </channel>
</rss>