Modification in Cyber Security and Cyber resilience framework of KYC Registration Agencies (KRAs)
X X X X Extracts X X X X
X X X X Extracts X X X X
....ework of KYC Registration Agencies (KRAs) 1. SEBI vide circular SEBI/HO/MIRSD/DOP/CIR/P/2019/111 dated October 15, 2019 prescribed framework for Cyber Security and Cyber Resilience for KYC Registration Agencies. 2. In partial modification to Annexure A of SEBI circular dated October 15, 2019, the paragraph-11, 40, 41 and 42 shall be read as under: 11. KRAs shall identify and classif....
X X X X Extracts X X X X
X X X X Extracts X X X X
....data flows. 40. KRAs shall carry out periodic vulnerability assessment and penetration tests (VAPT) which inter-alia include critical assets and infrastructure components like Servers, Networking systems, Security devices, load balancers, other IT systems pertaining to the activities done as KRAs etc., in order to detect security vulnerabilities in the IT environment and in-depth evaluati....
X X X X Extracts X X X X
X X X X Extracts X X X X
....tted to SEBI within 3 months post the submission of final VAPT report. 42. In addition, KRAs shall perform vulnerability scanning and conduct penetration testing prior to the commissioning of a new system which is a critical system or part of an existing critical system. 3. Further, the KRAs are mandated to conduct comprehensive cyber audit at least twice a financial year. All KRAs sha....
TaxTMI