<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://www.taxtmi.com/rss_sitemap/rss_feed_blog.xsl?v=1750492856"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Modification in Cyber Security and Cyber Resilience Framework of Mutual Funds/ Asset Management Companies (AMCs)</title>
    <link>https://www.taxtmi.com/circulars?id=65650</link>
    <description>Mutual Funds and AMCs must identify and classify critical assets and maintain an up-to-date inventory approved by Boards/Trustees. They are required to conduct periodic VAPT using CERT-In empanelled organisations, submit final VAPT reports to SEBI after Technology Committee approval within one month, remediate vulnerabilities immediately and file closure compliance within three months. VAPT or scanning is required before commissioning new critical systems. All cyber incidents must be reported to SEBI within six hours and quarterly reports submitted within fifteen days of quarter-end; entities must perform two cyber audits per year and provide an MD/CEO compliance declaration.</description>
    <language>en-us</language>
    <pubDate>Thu, 09 Jun 2022 00:00:00 +0530</pubDate>
    <lastBuildDate>Thu, 09 Jun 2022 17:03:00 +0530</lastBuildDate>
    <generator>TaxTMI RSS Generator</generator>
    <atom:link href="https://www.taxtmi.com/rss_feed_blog?id=681589" rel="self" type="application/rss+xml"/>
    <item>
      <title>Modification in Cyber Security and Cyber Resilience Framework of Mutual Funds/ Asset Management Companies (AMCs)</title>
      <link>https://www.taxtmi.com/circulars?id=65650</link>
      <description>Mutual Funds and AMCs must identify and classify critical assets and maintain an up-to-date inventory approved by Boards/Trustees. They are required to conduct periodic VAPT using CERT-In empanelled organisations, submit final VAPT reports to SEBI after Technology Committee approval within one month, remediate vulnerabilities immediately and file closure compliance within three months. VAPT or scanning is required before commissioning new critical systems. All cyber incidents must be reported to SEBI within six hours and quarterly reports submitted within fifteen days of quarter-end; entities must perform two cyber audits per year and provide an MD/CEO compliance declaration.</description>
      <category>Circulars</category>
      <law>SEBI</law>
      <pubDate>Thu, 09 Jun 2022 00:00:00 +0530</pubDate>
      <guid isPermaLink="true">https://www.taxtmi.com/circulars?id=65650</guid>
    </item>
  </channel>
</rss>