<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://www.taxtmi.com/rss_sitemap/rss_feed_blog.xsl?v=1750492856"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Modification in Cyber Security and Cyber resilience framework of KYC Registration Agencies (KRAs)</title>
    <link>https://www.taxtmi.com/circulars?id=65627</link>
    <description>KRAs must identify, classify and board approve critical assets, maintain inventories of hardware, software and network resources, and subject new or critical systems to vulnerability scanning and penetration testing prior to commissioning. Periodic VAPT covering critical infrastructure must be conducted at least annually, by CERT In empaneled organisations, with final reports approved by the Technology Committee and submitted to the regulator. Vulnerabilities must be remediated immediately and closure certified within three months. KRAs must undertake comprehensive cyber audits twice per financial year and submit an MD/CEO compliance declaration with audit reports.</description>
    <language>en-us</language>
    <pubDate>Mon, 30 May 2022 00:00:00 +0530</pubDate>
    <lastBuildDate>Mon, 30 May 2022 16:02:00 +0530</lastBuildDate>
    <generator>TaxTMI RSS Generator</generator>
    <atom:link href="https://www.taxtmi.com/rss_feed_blog?id=680597" rel="self" type="application/rss+xml"/>
    <item>
      <title>Modification in Cyber Security and Cyber resilience framework of KYC Registration Agencies (KRAs)</title>
      <link>https://www.taxtmi.com/circulars?id=65627</link>
      <description>KRAs must identify, classify and board approve critical assets, maintain inventories of hardware, software and network resources, and subject new or critical systems to vulnerability scanning and penetration testing prior to commissioning. Periodic VAPT covering critical infrastructure must be conducted at least annually, by CERT In empaneled organisations, with final reports approved by the Technology Committee and submitted to the regulator. Vulnerabilities must be remediated immediately and closure certified within three months. KRAs must undertake comprehensive cyber audits twice per financial year and submit an MD/CEO compliance declaration with audit reports.</description>
      <category>Circulars</category>
      <law>SEBI</law>
      <pubDate>Mon, 30 May 2022 00:00:00 +0530</pubDate>
      <guid isPermaLink="true">https://www.taxtmi.com/circulars?id=65627</guid>
    </item>
  </channel>
</rss>