<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://www.taxtmi.com/rss_sitemap/rss_feed_blog.xsl?v=1750492856"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyber Security and Cyber Resilience framework for Mutual Funds / Asset Management Companies (AMCs)</title>
    <link>https://www.taxtmi.com/circulars?id=59087</link>
    <description>SEBI mandates all mutual funds and AMCs to adopt a board approved Cyber Security and Cyber Resilience framework requiring designation of a CISO, Technology Committee oversight, and implementation of the identify protect detect respond recover lifecycle. Operational controls include least privilege access, two factor authentication, encryption of data in motion and data at rest, hardened systems, patch management, VAPT and annual penetration testing, continuous monitoring and logging, incident response and recovery planning, quarterly reporting of cyber incidents to SEBI, anonymised threat sharing, periodic training, annual independent audits, and vendor compliance obligations.</description>
    <language>en-us</language>
    <pubDate>Thu, 10 Jan 2019 00:00:00 +0530</pubDate>
    <lastBuildDate>Fri, 11 Jan 2019 18:11:00 +0530</lastBuildDate>
    <generator>TaxTMI RSS Generator</generator>
    <atom:link href="https://www.taxtmi.com/rss_feed_blog?id=552598" rel="self" type="application/rss+xml"/>
    <item>
      <title>Cyber Security and Cyber Resilience framework for Mutual Funds / Asset Management Companies (AMCs)</title>
      <link>https://www.taxtmi.com/circulars?id=59087</link>
      <description>SEBI mandates all mutual funds and AMCs to adopt a board approved Cyber Security and Cyber Resilience framework requiring designation of a CISO, Technology Committee oversight, and implementation of the identify protect detect respond recover lifecycle. Operational controls include least privilege access, two factor authentication, encryption of data in motion and data at rest, hardened systems, patch management, VAPT and annual penetration testing, continuous monitoring and logging, incident response and recovery planning, quarterly reporting of cyber incidents to SEBI, anonymised threat sharing, periodic training, annual independent audits, and vendor compliance obligations.</description>
      <category>Circulars</category>
      <law>SEBI</law>
      <pubDate>Thu, 10 Jan 2019 00:00:00 +0530</pubDate>
      <guid isPermaLink="true">https://www.taxtmi.com/circulars?id=59087</guid>
    </item>
  </channel>
</rss>