Framework for Adoption of Cloud Services by SEBI Regulated Entities (REs)
X X X X Extracts X X X X
X X X X Extracts X X X X
....fted to provide baseline standards of security and for the legal and regulatory compliances by the RE. The framework shall be seen as an addition to already existing SEBI circulars /guidelines /advisories. 2. Objective: The major purpose of this framework is to highlight the key risks, and mandatory control measures which REs need to put in place before adopting cloud computing. The document also sets out the regulatory and legal compliances by REs if they adopt such solutions. 3. Applicability: The framework shall be applicable to the following REs: i. Stock Exchanges ii. Clearing Corporations iii. Depositories iv. Stock Brokers through Exchanges v. Depository Participants through Depositories vi. Asset Management Companies (AMCs)/ Mutual Funds (MFs) vii. Qualified Registrars to an Issue and Share Transfer Agents viii. KYC Registration Agencies (KRAs) 4. Transition Period i. The framework shall come into force with immediate effect for all new or proposed cloud onboarding assignments/ projects of the REs. ii. REs which are currently availing cloud services (as on date of issuance ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....herein. ii. Deployment of any other cloud model is prohibited unless explicitly permitted under this framework. However, as the field of cloud computing is a dynamic and emerging area, SEBI may allow deployment of other models after due consultations. The same may be specified by SEBI from time to time. 6. Approach: The cloud framework is a principle-based framework which covers Governance, Risk and Compliance (GRC), selection of Cloud Service Providers (CSPs), data ownership and data localization, due- diligence by REs, security controls, legal and regulatory obligations, DR & BCP, and vendor lock-in risk. The principles are broadly stated guidelines to set the standards by which RE must comply with while adopting cloud services. The principles are stated below: i. Principle 1: Governance, Risk and Compliance Sub-Framework ii. Principle 2: Selection of Cloud Service Providers iii. Principle 3: Data Ownership and Data Localization iv. Principle 4: Responsibility of the Regulated Entity v. Principle 5: Due Diligence by the Regulated Entity vi. Principle 6: Security Controls vii. Principle 7: Contractual an....
X X X X Extracts X X X X
X X X X Extracts X X X X
....all aspects related to the cloud services adopted by it including but not limited to availability of cloud applications, confidentiality, integrity and security of its data and logs, and ensuring RE's compliance with the laws, rules, regulations, circulars, etc. issued by SEBI/Government of India/ respective state government. Accordingly, the RE shall be responsible and accountable for any violation of the same. iii. The cloud services shall be taken only from the Ministry of Electronics and Information Technology (MeitY) empaneled CSPs. The CSP's data center should hold a valid STQC (or any other equivalent agency appointed by Government of India) audit status. For selection of CSPs offering PaaS and SaaS services in India, RE shall choose only such CSPs which: 1. Utilize the underlying infrastructure of MeitY empaneled CSPs for providing services to the RE. 2. Host the application/ platform/ services provided to RE as well as store/ process data of the RE, only within the data centers as empaneled by MeitY and holding a valid STQC (or any other equivalent agency appointed by Government of India) audit status. iv. In a multi-tenant cloud architecture, adequ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....enial-of-Service 7 Dev Development Environment 8 DR Disaster Recovery 9 IPS Intrusion Prevention System 10 LAN Local Area Network 11 MeitY Ministry of Electronics and Information Technology 12 MII Market Infrastructure Institution 13 MPLS Multiprotocol Label Switching 14 MSP Managed Service Provider 15 NIST National Institute of Standards and Technology 16 P2P Point-to-Point connection 17 PII Personal Identifiable Information 18 RE Regulated Entity 19 SI System Integrator 20 SLA Service Level Agreement 21 SOAR Security Orchestration, Automation and Response 22 SOC Security Operations Center 23 SSL Secure Sockets Layer 24 STQC Standardization Testing and Quality Certification 25 UAT User Acceptance Testing 26 VAPT Vulnerability Assessment & Penetration Testing 27 VM Virtual Machine 28 VPN Virtual Private Network 29 WAF Web Application Firewall Definitions 1. Cloud Model Description- The description of common cloud deployment models (as per NIST) [Ref: https://nvlpubs.nis....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ramming languages, libraries, services, and tools supported by the provider. The consumer does not directly manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment. A few examples of PaaS are Google App Engine, Amazon Web Services (AWS) Elastic Beanstalk, etc. iii. Software as a Service (SaaS): The capability provided to the consumer is to use the provider's applications running on a cloud infrastructure. The applications are accessible from various client devices through either a thin client interface, such as a web browser (e.g., web-based email), or a program interface. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user specific application configuration settings. A few examples of SaaS are Gmail, Microsoft Office 365, etc. B. Other deployment models such as Application as a Service, Security as a Service, etc. may be considered ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ed by SEBI. 3. Measures to ensure the protection of stakeholder's interests 4. Measures to comply with the applicable legal and regulatory requirements. ii. Cloud Risk Management: 1. There is a paradigm shift in the manner of how cloud technology is built and managed in comparison with traditional on-premise infrastructure. Therefore, a comprehensive risk management should be undertaken by the RE to continually identify, monitor, and mitigate the risks posed by cloud computing. 2. The cloud risk management approach should be approved by the Board of the RE. The cloud risk management approach shall provide details regarding the various risks of cloud adoption such as technical, legal, business, regulatory etc., and the commensurate risk mitigation controls which should be proportionate to the criticality and sensitivity of the data/operations to be on-boarded on the cloud. 3. As part of risk management process, a thorough risk assessment shall also be done keeping in mind that the RE cannot outsource the risks and decision making associated with deployment of cloud services, to the CSP. The risk assessment shall include (but not limite....
X X X X Extracts X X X X
X X X X Extracts X X X X
....skill gaps which emerge as a result of transition to cloud computing. ii. Capacity building within organization to build adequate skillsets to manage cloud deployments effectively. 3. Role of IT team- The IT team shall be responsible for managing day to day operations and assisting senior management in achieving the objectives of cloud deployments. 4. Additional roles/ responsibilities may be added (to the Board/KMP, Senior Management, etc.) as per requirements of the RE. v. Grievance Redressal Mechanism: The RE shall have a robust grievance redressal mechanism, which in no way shall be compromised on account of cloud adoption i.e., responsibility and accountability for redressal of investors'/ members' grievances related to cloud on boarded services shall rest with the RE. Adoption of cloud services shall not affect the rights of the investor/ member against the RE, including the ability of the investor/ member to obtain redressal of grievances as applicable under relevant laws. vi. Monitoring and Control of Cloud Deployments: 1. RE shall have in place a management structure to monitor and control the activities and services deployed on cloud. This sh....
X X X X Extracts X X X X
X X X X Extracts X X X X
...., etc.) provided to the RE as well as store/ process data of the RE, only within the data centers as empaneled by MeitY and holding a valid STQC (or any other equivalent agency appointed by Government of India) audit status. 3. Have a back-to-back, clear and enforceable agreement with their partners/ vendors/ sub-contractors (including those that provide the underlying infrastructure/ platform) for ensuring their compliance with respect to the requirements provided in this framework including those in Principles 6 (Security Controls), 7 (Contractual and Regulatory Obligations) and 8 (BCP, Disaster Recovery & Cyber resilience). iii. Any other additional criteria that the RE considers appropriate/ as per RE's requirement. iv. The RE shall ensure that storage/ processing/ transfer of its data should be done according to requirements provided in this framework as well as any other regulations/ circulars/ guidelines issued by SEBI and any other Government authorities. Principle 3: Data Ownership and Data Localization 3. Data Ownership and Localization: i. Data Ownership: The RE shall retain the complete ownership of all its data and logs, encryption keys, etc....
X X X X Extracts X X X X
X X X X Extracts X X X X
....d applications, confidentiality, integrity and security of its data and logs, and ensuring RE's compliance with respect to the applicable laws, rules, regulations, circulars, etc. issued by SEBI/ Government of India/ respective state government. Accordingly, the RE shall be held accountable for any violation of the same. ii. There shall be an explicit and unambiguous delineation/ demarcation of responsibilities with respect to all activities (including but not limited to technical, managerial, governance related, etc.) of the cloud services between the RE and CSP. There shall be no "joint/ shared ownership" for any function/ task/ activity between the RE and CSP. If any function/ task/ activity has to be performed jointly by the RE and CSP, there shall be a clear delineation and fixing of responsibility for each sub-task/ line-item within the task. The aforementioned delineation of responsibilities shall be added explicitly in the agreement (as an annexure) signed between the RE and the CSP. iii. In the event of a Managed Service Provider (MSP) or System Integrator (SI) being involved in procurement of cloud services, an explicit and unambiguous delineation/ demarcation of re....
X X X X Extracts X X X X
X X X X Extracts X X X X
....y of the organization, etc. The above mentioned evaluations / analyses should be conducted keeping in mind that although the IT services/ functionality can be outsourced (to a CSP), REs are ultimately accountable for all aspects related to the cloud services adopted by it including but not limited to availability of cloud applications, confidentiality, integrity and security of RE's data and logs, and ensuring RE's compliance with respect to the applicable laws, rules, regulations, circulars, etc. issued by SEBI/ Government of India/ respective state government. Accordingly, the RE shall be held accountable for any violation of the same. iv. The criteria that an RE shall look out for are (including but not limited to): 1. Financial soundness of CSP and its ability to service commitments even under adverse conditions. 2. CSP's capability to identify and segregate RE's data, whenever required. 3. Security risk assessment of the CSP. 4. Ensuring that appropriate controls, assurance requirements and possible contractual arrangements are in place to establish data ownership. 5. CSP's ability to effectively service all the RE's customers wh....
X X X X Extracts X X X X
X X X X Extracts X X X X
....components of the services that the CSP is responsible for (i.e. managed by the CSP). The RE shall assess and ensure that the patch management of CSP adequately covers the components for which the CSP is responsible (i.e. components managed by the CSP). The patch management framework shall include the timely patching of all components coming under the purview of CSP. 2. The RE shall also ensure that CSP conducts Vulnerability Assessment and Penetration Testing (VAPT) for the components managed by the CSP and fixes the issues/ vulnerabilities within the prescribed timelines (as agreed upon by CSP and RE). 3. The RE shall also ensure that the vulnerability management, patch management and VAPT processes are conducted by CSP in-line with the requirements (for example scope, classification of vulnerabilities, duration for closure, etc.) provided in applicable circulars/ guidelines issued by SEBI. ii. Monitoring: RE shall ensure that CSP has adequate security monitoring solutions in place. The monitoring solutions of CSP shall be responsible for the following: 1. Monitoring shall cover all components of the cloud. Additionally, the CSP shall continuous....
X X X X Extracts X X X X
X X X X Extracts X X X X
....hat CSP has taken adequate controls to ensure that the RE's data (in transit, at rest and in use) shall be isolated and inaccessible to any other tenants. RE shall appropriately assess and ensure the multi tenancy segregation controls placed by CSP and place additional security controls if required. Any access by other tenants/unauthorized access by CSP's resources to RE's data shall be considered as an incident/breach and the CSP shall ensure that the incident/breach is notified to the RE (as per the norms/ guidelines/ circulars issued by SEBI/ Government of India and (wherever applicable) as per the contractual agreement signed between the CSP and RE, and adequate steps are taken to control the same. During such incident/breach, the RE shall ensure that CSP should provide all related forensic data, reports and event logs as required to the RE /SEBI /CERT-In/ any government agency for further investigation. All conditions and obligations of the RE and CSP under this framework shall also be applicable in multi-tenancy structure. vii. The RE shall ensure that the agreement with the CSP contains clause(s) for safe deletion/ erasure of RE's information. The clause should cover....
X X X X Extracts X X X X
X X X X Extracts X X X X
....e services/ application/ infrastructure deployed by RE in cloud. The continuous monitoring shall be done in an integrated manner and the services/ application/ infrastructure deployed in cloud should be treated as an extension of the RE's on premise network. The SOC shall have complete visibility of information systems of the RE deployed on cloud and should be capable to take SOAR actions across the information systems owned by the RE. Additionally, only logs, meta-data should be shipped to shared SOC. REs shall ensure that PII/sensitive data should not be shipped to the SOC. 6.2.4. Continuous Monitoring: Continuous monitoring shall be done by the RE to review the technical, legal and regulatory compliance of CSP and take corrective measures/ ensure CSP takes corrective measures wherever necessary. 6.2.5. Secure User Management: The RE shall ensure that the following Identity, Authentication and Authorization practices are followed (by CSP as well as by RE): i. Principle of least privilege shall be adopted for granting access to any resources for normal and admin/privileged accounts. ii. The identity and access management solution should give the complete vie....
X X X X Extracts X X X X
X X X X Extracts X X X X
....eb applications might not be relevant for cloud native development concepts. iii. Best practices such as zero trust principles, fine grained access control mechanism, API Gateways, etc. shall be adopted for development and usage of APIs. End to end security of the APIs shall also be taken care by the RE as per standard practices and guidelines. iv. Secure identification, authentication and authorization mechanisms shall be adopted by the RE. 6.2.8. Managed Service Provider (MSP) & System Integrator (SI): i. Wherever MSP and SI are involved in cloud services procurement, a clear demarcation of roles, and liabilities shall be clearly defined in the Agreement/Contract. ii. As there are new risks introduced in engaging MSP/SI or both, the same shall be assessed, and mitigated by the RE. 6.2.9. Encryption and Cryptographic Key Management: i. To ensure the confidentiality, privacy and integrity of the data, encryption as defined below shall be adopted by the RE: 1. Data-at-rest encryption to be done with strong encryption algorithms. Data object encryption, file level encryption or tokenization in addition to the encryption provided at the platform level sha....
X X X X Extracts X X X X
X X X X Extracts X X X X
....icy is in place to address the backup requirement of cloud deployments. The backup and recovery processes shall be checked at least twice in a year to ensure the adequacy of the backups. ii. The backup shall be logically segregated from production/dev/UAT environment to ensure that the malware infection in such systems does not percolate to backup environment. iii. Wherever CSP's backup services are utilized, adequate care should be taken with encryption solution and Key management. 6.2.13. Skillset: RE shall equip staff overseeing cloud operations with the knowledge and skills required to securely use and manage the risks associated with cloud computing. The skills should also be imparted to oversee the management interfaces, security configurations etc. of CSP infrastructure. This is a critical factor as it will reduce the misconfigurations, vulnerabilities etc. and will increase the reliability of services. 6.2.14. Breach Notification: CSP shall notify the RE of any cybersecurity incident (for example data breach, ransomware, etc.) as mandated by the RE. The reporting shall be done as per the norms/ guidelines/ circulars issued by SEBI/ Government of India and ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....nnel/ agency may access RE's IT infrastructure, applications, data, documents, and other necessary information given to, stored or processed by the CSP and/ or its sub-contractors. 3. Engage a forensic auditor to identify the root cause of any incident (cyber security or other incidents) related to RE. 4. Seek the audit reports of the audits conducted by CSP. The RE shall ensure that adequate provisions are included in the agreement/ contract with CSP to enable the above functionalities. Additionally, RE shall also include provisions (in the contract/ agreement with CSP) mandating that CSP extends full cooperation to SEBI while conducting the above-mentioned activities. v. The RE shall also ensure that adequate provisions are included in the agreement/ contract for the following audit/ VAPT functions- 1. CSP shall be responsible for conducting audit/ VAPT of the services/ components managed by the CSP. 2. The RE shall be responsible for conducting audit/ VAPT of the services/ components managed by the RE. The audit/ VAPT shall be conducted as per the requirements (including scope, duration for closure of vulnerabilities, etc.) provided in various applicable ci....
X X X X Extracts X X X X
X X X X Extracts X X X X
....sources being on boarded on cloud, including appropriate service and performance standards including for the material sub-contractors, if any. 2. Effective access to all the objects/ information relevant to the RE/ RE's operation including data, books, records, logs, alerts, and data centre. 3. Continuous monitoring and assessment of the CSP by the RE so that any necessary corrective measure can be taken immediately, including termination of contract and any minimum period required to execute such provisions, if deemed necessary. 4. Type of material adverse events (e.g., data breaches, denial of service, service unavailability etc.) and incident reporting requirements to the RE to take prompt mitigation and recovery measures and ensure compliance with statutory and regulatory guidelines. 5. Compliance with the provisions of IT Act, other applicable legal requirements and standards to protect the customer (RE) data. 6. The deliverables, including SLAs, for formalizing the performance criteria to measure the quality and quantity of service levels. 7. Storage of data (as applicable to the RE) within the legal boundaries of India as....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... ownership" for any task/ activity/ function/ component. xii. If any function/ task/ activity has to be performed jointly by the RE and CSP/MSP/SI, there shall be a clear delineation and fixing of responsibility between the RE and the CSP (and MSP/SI wherever applicable) for each sub-task/ line-item within the task. The aforementioned delineation of responsibilities shall be added explicitly in the agreement (as an annexure) signed between the RE and the CSP (and MSP/SI wherever applicable). However, any such clause in the agreement shall not absolve the RE from having the ultimate responsibility and liability for any violation of the laws, rules, regulations, circulars, etc. issued by SEBI or any other authority under any law, regardless of any delineation/ demarcation of responsibilities. xiii. Similarly, there shall be an explicit and unambiguous delineation/ demarcation of responsibilities between the RE and CSP (and MSP/SI wherever applicable) for ensuring compliance with respect to applicable circulars (for example cybersecurity and cyber resilience circular, outsourcing circular, BCP-DR etc.) issued by SEBI from time to time. There shall be no "joint/ shared owner....
X X X X Extracts X X X X
X X X X Extracts X X X X
....relevant SEBI circular/ guidelines/ regulations. The auditor shall also verify, and certify, whether the above-mentioned demarcations of roles and responsibilities have been incorporated in the agreement/ contract signed between the RE and CSP (and MSP/SI wherever applicable). xv. In the event of any CSP deployed by an RE losing its empanelment status with MeitY/ commits a passive breach of contract/ agreement in any way, the RE shall ensure that it becomes compliant with this framework within 6 (six) months of being notified of/ discovering the breach. Principle 8: BCP, Disaster Recovery & Cyber Resilience 8. Business Continuity Planning (BCP), Disaster Recovery & Cyber Resilience: i. The RE shall assess its BCP framework and ensure that it is in compliance with this cloud framework as well as other guidelines/ circulars issued by SEBI from time to time. ii. RE shall also assess the capabilities, preparedness and readiness with respect to cyber resilience of CSP. The same can be periodically assessed by conducting DR drills (in accordance with circulars/ guidelines issued by SEBI) by involving necessary stakeholders. iii. Additionally, RE shall develop a viabl....
X X X X Extracts X X X X
X X X X Extracts X X X X
....rinciple 4: Responsibility of the Regulated Entity 5. Principle 5: Due Diligence by the Regulated Entity 6. Principle 6: Security Controls 7. Principle 7: Contractual and Regulatory Obligations 8. Principle 8: BCP, Disaster Recovery & Cyber Resilience 9. Principle 9: Vendor Lock-in and Concentration Risk Management The REs shall ensure that their cloud deployments are compliant, in letter and spirit, with the above-mentioned principles. iv. The cloud services shall be taken only from the MeitY empaneled CSPs. The CSP's data center should hold a valid STQC (or any other equivalent agency appointed by Government of India) audit status. For selection of CSPs offering PaaS and SaaS services in India, RE shall choose only such CSPs which: 1. Utilize the underlying infrastructure/ platform of only MeitY empaneled CSPs for providing services to the RE. 2. Host the application/ platform/ services provided to RE, and store/ process data of the RE, only within the data centers as empaneled by MeitY and holding a valid STQC (or any other equivalent agency appointed by Government of India) audit status. 3. Have a bac....
X X X X Extracts X X X X
X X X X Extracts X X X X
....The auditor shall also verify, and certify, whether the above-mentioned demarcations of roles and responsibilities have been incorporated in the agreement/ contract signed between the RE and CSP (and MSP/SI wherever applicable. viii. The contractual/agreement terms between RE and CSP shall include the provisions for audit, and information access rights to the RE as well as SEBI, for the purpose of performing due diligence and carrying out supervisory reviews. RE shall also ensure that its ability to manage risks, provide supervision and comply with regulatory requirements is not hampered by the contractual terms and agreement with CSP. ix. SEBI/ CERT-In/ any other government agency shall at any time: 1. Conduct direct audits and inspection of resources of CSP (and its sub-contractors/ vendors) pertaining to the RE or engage third party auditor to conduct the same and check the adherence with SEBI and government guidelines/ policies/ circulars and standard industry policies. 2. Perform search and seizure of CSP's resources storing/ processing data and other relevant resources (including but not limited to logs, user details, etc.) pertaining to the RE. In thi....
X X X X Extracts X X X X
X X X X Extracts X X X X
....EBI from time to time. All other conditions for reporting (for example reporting authority, duration of reporting, etc.) shall be as per the existing mechanism of reporting for systems audit/ cybersecurity audit/VAPT. Appendix-A Format for Submission of Details of Cloud Deployments The REs shall provide details of their cloud deployment in the following format- A. Entity Name: B. Entity Type: (For example stock exchange, depository, mutual fund, etc.) C. Whether Utilizing Cloud Services? Yes/ No For Each Cloud application/ service/ system, please provide a response to the following: SN Details Required Entity Response 1 Name of the Application/ Service/ System 2 The type of deployment model utilized (public cloud, community cloud, etc.) 3 The type of service model utilized (For example IaaS, PaaS, etc.) 4 Name of the Cloud Service Provider (CSP) 5 Country of incorporation/ registration of CSP Name of the Managed Service Provider (MSP) / System Integrator (SI) [wherever applicable] 6 Country of incorporation/ registration of MSP/ SI ....
TaxTMI