Just a moment...

Top
Help
×

By creating an account you can:

Logo TaxTMI
>
Call Us / Help / Feedback

Contact Us At :

E-mail: [email protected]

Call / WhatsApp at: +91 99117 96707

For more information, Check Contact Us

FAQs :

To know Frequently Asked Questions, Check FAQs

Most Asked Video Tutorials :

For more tutorials, Check Video Tutorials

Submit Feedback/Suggestion :

Email :
Please provide your email address so we can follow up on your feedback.
Category :
Description :
Min 15 characters0/2000
TMI Blog
Home / RSS

Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... 1. SEBI had issued Cybersecurity and Cyber resilience framework for Market Infrastructure Institutions (MIIs) in 2015. Subsequently, SEBI had issued other Cybersecurity and Cyber resilience frameworks in line with MIIs circular of 2015 for following REs: 1.1. Stock Brokers and Depository Participants 1.2. Mutual Funds (MFs)/ Asset Management Companies (AMCs) 1.3. KYC Registration Agencies (KRAs) 1.4. Qualified Registrar to an Issue and Share Transfer Agents (QRTAs) 1.5. Portfolio Managers 2. Further, SEBI has also issued various advisories to REs, from time to time, on Cybersecurity best practices. 3. In order to strengthen the cybersecurity measures in Indian securities market, and to ensure adequate cyber resiliency against cybersecurity incidents/ attacks, Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI REs has been formulated in consultation with the stakeholders. The CSCRF aims to provide standards and guidelines for strengthening cyber resilience and maintaining robust cybersecurity of SEBI REs. This framework shall supersede existing SEBI cybersecurity circulars/ guidelines/ advisories/ letters (list of such superseded circulars/ guidelin....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....such as data classification and localization, Application Programming Interface (API) security, Security Operations Centre (SOC) and measuring its efficacy, Software Bill of Materials (SBOM), etc. 10. CSCRF aims to ensure that even smaller REs are equipped with adequate cybersecurity measures and achieve resiliency against cybersecurity incidents/ attacks. 11. Cyber Capability Index (CCI) for MIIs and Qualified REs shall help these REs to monitor and assess their progress and cyber resilience on a periodic basis. 12. CSCRF mandates that all REs are required to establish appropriate security monitoring mechanisms through Security Operation Centre (SOC). The onboarding of SOC can be done through RE's own/ group SOC or Market SOC or any other third-party managed SOC for continuous monitoring of security events and timely detection of anomalous activities. 13. As compliance with the cybersecurity guidelines may be onerous for smaller REs due to the lack of knowledge and expertise in cybersecurity and the cost factor involved in setting up own SOC. Therefore, CSCRF mandates NSE and BSE to set up Market SOC (M-SOC) with the objective of providing cybersecurity solutions to su....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....Exchange of India Act, 1992, to protect the interests of investors in securities and to promote the development of, and to regulate the securities market. 22. The circular is issued with the approval of Competent Authority. 23. This circular is available on SEBI website at www.sebi.gov.in under the category "Legal" and drop "Circulars". Yours Faithfully, Shweta Banerjee Deputy General Manager Phone: 022-26449509 Email: [email protected] ============= Document 1SZ31 Annexure-1 Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (RES) Version 1.0 Date: August 20, 2024 Securities and Exchange Board of India Plot no. C4-A, G Block, Bandra Kurla Complex, - Bandra (East), Mumbai – 400051, India Tel.: +91-22-26449000/40459000 Website: www.sebi.gov.in SZ31 CSCRF This page intentionally left blank Page 12 of 205 Version 1.0 Executive Summary The Information Technology Act, 2000 defines Cybersecurity as “Protecting information, equipment, devices, computer, computer resource, communication device and information stored therein from unauthorised access, use, disclosure, disruption, modification or destr....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....rinciples for compliance with CSCRF. ii. Part II: Guidelines: The guidelines recommend measures for complying with standards mentioned in this document. However, few of the guidelines are mandatory in nature and shall be complied by REs as applicable. iii. Part III: Structured formats for compliance iv. Part IV: Annexures and References For ease of compliance, REs are required to comply with the all applicable standards and mandatory guidelines as mentioned in CSCRF. The Structure of CSCRF The framework is broadly based on two approaches: cybersecurity and cyber resilience. Cybersecurity approach covers various aspects from governance measures to operational controls and the cyber resilience goals include Anticipate, Withstand, Contain, Recover, and Evolve. The framework also specifies guidelines to ensure standards are implemented in a uniform manner. The summary of the CSCRF is as follows: i. Cyber Resilience Goal: Anticipate | Cybersecurity function: Governance a. REs shall establish, communicate and enforce cybersecurity risk management roles, responsibilities, and authorities to foster accountability and continuous improvement. b. A comprehensive cybersecu....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ftware/ applications for critical systems and further feature enhancements. e. Periodic audits shall be conducted by a CERT-In empanelled IS auditing organization to audit the implementation and provide compliance with the applicable standards and mandatory guidelines mentioned in the CSCRF. f. Vulnerability Assessment and Penetration Testing (VAPT) shall be done to detect vulnerabilities in the IT environment for all critical systems, infrastructure components and other IT systems as defined in the framework. To undertake this activity, a comprehensive VAPT scope has also been specified. g. Application Programming Interface (API) security and Endpoint security solutions shall be implemented with rate limiting, throttling, and proper authentication and authorisation mechanisms. h. ISO 27001 certification: ISO 27001 certification shall be mandatory for MIls and Qualified REs as it provides essential security standards with respect to Information Security Management System (ISMS). 2 Quantum computing is a rapidly emerging technology that exploits quantum mechanics' laws to solve complex problems. Post-quantum cryptography solutions can avert post-quantum risks and pr....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....fied vulnerabilities and to reduce attack surfaces shall be created and incorporated into the RE's cybersecurity and cyber resilience strategy. Version 1.0 Page 16 of 205 S=31 CSCRF viii. Compliance requirements The compliance reporting for CSCRF shall be done by the REs to their respective authorities in the standardized formats mentioned in this framework as per the stated periodicity. A glide-path has been given to REs to comply with the CSCRF standards and mandatory guidelines. Since new standards and controls have been added in CSCRF, a glide-path for adoption of CSCRF provisions has been provided as under: a. For six categories of REs where cybersecurity and cyber resilience circular already exists - by January 01, 2025. b. For other REs where CSCRF is being issued for the first time - by April 01, 2025. Further, to ensure the uniformity in auditing REs w.r.t. CSCRF, an auditors' checklist and guidelines has been included in this framework. Future proofing of CSCRF It is envisaged that quantum computing may be a reality in near future and it may be able to break the encryption schemes widely used today. Thus, quantum computing may evolve into one of the....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ion... CSCRF 71 .71 72 5.3. RS.AN: Incident Analysis.. .73 5.4. RS.IM: Improvements.. 73 6. Cyber Resilience Goal: RECOVER | Cybersecurity function: RECOVER .74 6.1. RC.RP: Incident Recovery Plan Execution...... 74 6.2. RC.CO: Incident Recovery Communication... 74 6.3. RC.IM: Improvements..... 7. Cyber Resilience Goal: EVOLVE.. 7.1. EV.ST: Strategies. 8. Exemption Table…......... Part II: CSCRF Guidelines ..... .75 76 .76 77 79 Part III: Structured Formats for CSCRF Compliance...... 133 Annexure-A: VAPT Report Format. 133 Annexure-B: Cyber Audit Report Format. 142 Annexure-C: Recovery Plan Template (Reference Guide)... 150 Part IV: CSCRF Annexures and References. 152 Annexure-D: Audit Guidelines... 152 Annexure-E: Scenario-based Cyber Resilience Testing 155 Annexure-F: Guidelines on Outsourcing of Activities. 158 Annexure-G: Application Authentication Security... 159 Annexure-H: Data Security on Customer Facing Applications . 160 Annexure-I: Data Transport Security. 161 Annexure-J: Framework for Adoption of Cloud Services 162 Annexure-K: Cyber Capability Index (CCI).. 163 Annexure-L: VAPT Scope. 188 Annexure-M: Cyber-SO....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....wered Steering Committee on Cyber Security Government of India Infrastructure as a Service Internet Based Trading 54. IDS Intrusion Detection System 55. IOAS 56. IOCS 57. IOSCO 58. IP Indicators of Attack Indicators of Compromise International Organization of Securities Commissions Internet Protocol 59. IPO Initial Public Offer 60. IPS 61. IS Intrusion Prevention System Information Security 62. ISACA Information Systems Audit and Control Association 63. ISMS 64. ISO 65. IT 66. KRA 67. MASVS 68. MD 69. MeitY 70. MFA Information Security Management System International Organization for Standardization Information Technology KYC (Know Your Client) Registration Agency Mobile Application Security Verification Standard Managing Director Ministry of Electronic and Information Technology Multi-Factor Authentication 71. MII Market Infrastructure Institution 72. MTTC Mean Time to Contain 73. MTTD Mean Time to Detect Version 1.0 Page 22 of 205 5=31 CSCRF 74. MTTR Mean Time to Respond 75. NCIIPC 76. NDR 77. NEAT 78. NIST National Critical Information Infrastructure Protection Centre Near Disaster Recovery National Ex....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....rocesses or systems. b. Integrity: Property of accuracy and completeness. c. Availability: Property of being accessible and usable on demand by an authorised entity. 2. Critical Systems · - Entities shall identify and classify their critical IT systems. Following systems shall be included in critical systems (both on premise and cloud): a. Any system, if compromised, that will have an adverse impact on core and critical business operations. b. Stores/transmits data as per regulatory requirements. c. Devices/ network through which critical systems are connected (through trusted channels). d. Internet facing applications/ systems. e. Client facing application/ systems. f. All the ancillary systems used for accessing/ communicating with critical systems either for operations or for maintenance. 3. Cyber Capability Index (CCI) – CCI is an index applicable for MIls and Qualified REs which is calculated based on certain parameters as specified in this framework. The purpose of CCI is to ascertain the cyber resilience capabilities of MIls and Qualified REs and their maturity in terms of implementation of cybersecurity measures. 4. Cyber Event - Any observa....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....e functioning of the solution. 6. There shall be an explicit and unambiguous delineation/ demarcation of responsibilities with respect to all activities (including but not limited to technical, managerial, governance related, etc.) of the hosted services between the RE and Hosted service provider. The aforementioned delineation of responsibilities shall be added explicitly in the agreement (as an annexure) signed between the RE and the CSP. For details refer to "Framework for adoption of cloud services for SEBI Regulated Entities". 9 https://www.fsb.org/wp-content/uploads/P130423-3.pdf 10 Refer Q 3. In CERT-In Cybersecurity directions: https://www.cert- in.org.in/PDF/FAQs_on_CyberSecurityDirections_May2022.pdf Version 1.0 Page 27 of 205 SZ31 9. ISO 27001 certification11 CSCRF ISO 27001 certification is a globally recognized standard for Information Security Management Systems (ISMS) published by the International Organization for Standardization (ISO). It helps organizations become risk-aware, proactively identify, and address weaknesses and promote a holistic approach to information security. 10.IT and Cybersecurity Data IT and Cybersecurity Data includes th....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... missions or business processes and to provide a comprehensive assessment of the security capabilities of an organization and its systems. 15. Regulated Entity (RE)¹² - The term 'Regulated Entity' refers to SEBI registered/ recognised intermediaries (for example stock brokers, mutual funds, KYC Registration Agencies, QRTAS, etc.) and Market Infrastructure Institutions (Stock Exchanges, Depositories and Clearing Corporations) regulated by SEBI. 16. Regulatory Data – - Regulatory Data includes the following (but not limited to): a. Data related to core and critical activities of the RE, as well as any supporting/ ancillary data impacting core and critical activities. b. Data w.r.t to communication between investors and REs through applications (e.g., Chat communication, messages, emails etc.). c. Data that is required by the laws/ regulations/ circulars, etc. issued by SEBI and Govt. of India from time to time. d. Data that is deemed necessary or sensitive by the RE/ SEBI/ central or state government. e. The Regulatory Data shall be stored in an easily accessible, legible and usable form, within the legal boundaries of India. However, for the investor....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....is also called a secure channel. Page 30 of 205 Version 1.0 S=31 1. Introduction CSCRF Technology adoption by SEBI Regulated Entities (RES) has increased manifolds in the recent years. With the fast pace of technological developments in securities market, maintaining robust cybersecurity and cyber resilience to protect the operations of REs from cyber-risks and cyber incidents has become necessary. SEBI has issued cybersecurity and cyber resilience frameworks for various RES since 2015. After taking into consideration latest trends and evolving standards, Cybersecurity and Cyber Resilience Framework (CSCRF) has been formulated to consolidate and strengthen the prevention, preparedness, and response capabilities against cyber-risks and cyber incidents. 1.1. CSCRF is based on five cyber resiliency goals namely Anticipate, Withstand, Contain, Recover, and Evolve. İ. ii. iii. iv. V. ANTICIPATE - Maintain a state of informed preparedness in order to forestall compromises of mission/ business functions from adversary attacks. WITHSTAND - Continue essential mission/business functions despite successful execution of an attack by an adversary. CONTAIN - Localiz....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....RF 5=31 CSCRF The cyber resiliency goals cover different cybersecurity functions. These functions are to be implemented by RES through various cybersecurity controls. The controls are divided into the following three categories: İ. ii. iii. Objectives: The objectives highlight goals, which a security control needs to achieve. Standards: The standards represent established principles for compliance with CSCRF. Guidelines: The guidelines recommend measures for complying with standards mentioned in this document. However, few of the guidelines are mandatory in nature and shall be complied by REs as applicable. Accordingly, the CSCRF document is divided into four parts: İ. Part I: Objectives and Standards ii. Part II: Guidelines iii. Part III: Compliance Formats iv. Part IV: Annexures and References For ease of compliance, REs are required to comply with the standards and mandatory guidelines as mentioned in the CSCRF. Since new standards and controls have been added in CSCRF, a glide-path for adoption of CSCRF provisions has been provided as under: i. For six categories of REs where cybersecurity and cyber resilience circular already exists - by Janu....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....BI/HO/MIRSD/DOP/CIR/P/2019/111 October 15, 2019 June 07, 2022 June 30, 2022 January 10, 2019 June 09, 2022 October 15, 2019 Page 34 of 205 Version 1.0 531 S. No. Regulated Entity Circular Subject (Circular Number) 5. Qualified Registrars to an Issue / Share Transfer Agents (QRTAs) 6 Portfolio Managers 7 All Entities Regulated 8 Stock Exchanges, Clearing Corporations and Depositories (except Commodities Modification in Cyber Security and Cyber resilience framework of KYC Registration Agencies(KRAS) (SEBI/HO/MIRSD/DOP/P/CIR/2022/74) Modification in Cyber Security and Cyber resilience framework of KYC Registration Agencies (KRAs) (SEBI/HO/MIRSD/TPD/P/CIR/2022/95) Cyber Security and Cyber Resilience framework for Registrars to an Issue/ Share Transfer Agents (hereinafter referred to as RTAs) (SEBI/HO/MIRSD/CIR/P/2017/100) Cyber Security & Cyber Resilience framework for Qualified Registrars to an Issue/Share Transfer Agents (SEBI/HO/MIRSD/DOP/CIR/P/2019/110 Modification in Cyber Security and Cyber resilience framework of Qualified Registrars to an Issue and Share Transfer Agents("QRTAS") (SEBI/HO/MIRSD/MIRSD_RTAMB/P/CI R/2022/7....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ance 9. National Commodities Derivatives Exchange Ltd. Submission of Cyber Audit December Report 26, 2022 (SEBI/HO/ITD/ITD_INSADT_D /P/OW/2022/0000063944/1) 10. NSE Clearing Limited (Formerly known as Submission of Cyber Audit December Report 26, 2022 National Securities (SEBI/HO/ITD/ITD_INSADT_D Clearing Corporation Ltd.) 11. National Securities /P/OW/2022/0000063951/1) Submission of Cyber Audit December Depositories Ltd. Report 26, 2022 (SEBI/HO/ITD/ITD_INSADT_D /P/OW/2022/0000063954/1) 12. Mils Recommendations of High April 22, 13. Association of Mutual Funds in India (AMFI) Powered Steering Committee - 2019 Cyber Security in meeting dated February 21, 2019 (SEBI/HO/MRD/CSC/OW/P/20 19/10055/5) Review of Cyber Security and April 19, Cyber Resilience framework for 2023 Mutual Management Funds/Asset Companies (AMCs) (SEBI/HO/IMD/IMD-TPD- 1/P/OW/2023/16538) All letters with subject 'Review of Cyber Security and Cyber Resilience Mutual framework for Funds/Asset Companies 14. Association of Mutual Funds in India (AMFI) Management (AMCs)' dated April 19, 2023 issued to Mutual Funds/AMCs or Trustee Services shall be superseded w....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....red. Entity-wise categorization and corresponding thresholds shall be as follows: 1. Alternative Investment Fund (AIF) Table 3: Criteria and thresholds for AIFs categorization Sr. Criteria Self-certification Small-size REs Mid-size RES Qualified No. RES 1 AUM Less than 100 crores Rs. Rs. 100 crores and above but less than Rs. 500 crores Rs. 500 crores and above but less than Rs. 1000 crores RES Rs. 1000 crores and above 2. Banker to an Issue and Self-Certified Syndicate Banks (SCSBs) Banker to Issue and Self-Certified Syndicate Banks shall submit a certificate of compliance with CSCRF to SEBI on the cybersecurity guidelines issued by RBI. Wherever the bank is a listed entity, the above-mentioned certificate of compliance shall also be intimated to Stock Exchanges. 3. Client-based and Proprietary stock brokers Table 4: Criteria and thresholds for Client-based and proprietary stock brokers' categorization Version 1.0 Page 39 of 205 5=31 CSCRF Sr. Criteria No Self- certification Small-size RES Mid-size Qualified RES RES14 RES 1 Active Less than or More than. More Client- base as active clients 50,000 per UCC and equal to 10,000 ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... shall categorized as Small-size REs. Table 8: Criteria and thresholds for RAS categorization All RAs who are not registered in other category of RES All RAs who are not registered in other categories of REs shall be excluded from submission of compliance with CSCRF. However, SEBI SaaS circular titled "Advisory for Financial Sector Organizations regarding Software as a Service (SaaS) based solutions" dated November 03, 2020 is applicable to RAs under which a declaration shall be submitted in respect of SaaS for managing their governance, risk compliance functions, and to improve their cybersecurity posture. 13. KYC Registration Agencies (KRAS) be Institutional RAs who are registered in other category of RES Institutional RAS who are registered with SEBI in other category of REs shall be classified as Qualified RES/ Mid-size RES/ Small size REs based on their categorization in their respective other REs/ group entity category. KRAS shall be treated at par with MIls category for the applicability of the CSCRF. 14. Limited Purpose Clearing Corporation (LPCC) LPCC shall be excluded from submission of compliance with CSCRF. Page 41 of 205 Version 1.0 ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....Self- certification RES Small-size RES Mid-size RES Qualified RES 1 Sum of Less corpus of all Rs. than Rs. 100 crores schemes of crores the VCF 100 Rs. 500 Rs. and crores and crores above but above but above less than Rs. less than 1000 and 500 crores Rs. 1000 crores 23. In case an RE is registered under more than one category of REs, then the provision of highest category under which such an RE falls shall be applicable to that RE. Page 43 of 205 Version 1.0 S=31 CSCRF 3. IT Committee for RES 3.1. In order to address various technology related issues of RES, SEBI has issued circulars for composition of technical committees for MIls, and MFs/ AMCS summarized as below: Table 14: SEBI circular for REs and composition of their technical committees S. Name of the Circular subject (Circular Date number) Committees at Market January Regulated no. Entity Committee 1. Mils Standing Committee on Technology (MIls) (SCOT) 2. MFs/ AMCS Technology Committee Infrastructure Institutions 10, 2019 (SEBI/HO/MRD/DOP2DSA 2/CIR/P/2019/13) Statutory Committees at June 25, Market Infrastructure 2024 Institutions (MIls) (SEBI/HO/MRD/MRD-PO....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....mmittees. Version 1.0 Page 45 of 205 S=31 CSCRF 4. CSCRF Compliance, Audit Report Submission, and Timelines: This section provides details regarding submission of compliance with the CSCRF including ISO audit, VAPT, Cyber audit, etc. and the corresponding applicable timelines. 4.1. Compliance with the Standards/ Guidelines Unless specified otherwise, the compliance reporting for CSCRF shall be done by the REs to their respective authority(ies) as per the existing mechanism, for example, MIls shall submit the compliance with CSCRF to SEBI, stock brokers shall submit the compliance with CSCRF to stock exchanges, depository participants to shall submit the compliance with CSCRF to depositories, etc. Further, the compliance with the applicable standards and mandatory guidelines mentioned in CSCRF shall be as follows: Table 15: Applicability and periodicity of standards mentioned in CSCRF Sr. Standard/ Guidelines and Applicability No. Clause 1. Cyber resilience third-party MIls Periodicity Half-yearly assessment using CCI (GV.OV.S4) Cyber resilience self- Qualified REs Annually assessment using CCI (GV.OV.S4) 2. Submission of CCI self- MIls and Wit....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ce of certification shall be submitted along with the cyber audit report to the authority(ies) as given below: Version 1.0 Page 47 of 205 S=31 CSCRF Table 16: Reporting authority for ISO certification evidence submission Sr. Regulated Entity Reporting authority No. 1. Stock Brokers Depository Stock Exchanges Participants who are categorized Depositories as Qualified RES 2. MIls and rest of the Qualified RES SEBI 4.3. VAPT16 The VAPT scope, periodicity and compliance has been defined in standard DE.CM.S5 and the corresponding guidelines. 4.3.1. The VAPT reporting format has been attached at Annexure-A. It may be noted that along with the VAPT report, SEBI REs shall also submit the declaration from MD/ CEO (as given in Annexure-A). The reporting authority for VAPT report is as follows: Table 17: Reporting authority for VAPT report submission Sr. Regulated Entity Reporting authority No. 1. Stock Brokers Participants Depository Stock Exchanges Depositories 2. IAs 3. MIls and rest of the RES BASL SEBI 4.3.2. RES shall plan their VAPT activity in the beginning of the financial year. REs shall ensure that no audit cycle shall be left unaudited (i....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....d as per their timelines approved by the Boards/Partners/Proprietor. 1. Table 20: Indicative categories of open observations after follow-on audit S. No. Example Category Absence of security control MFA not implemented Version 1.0 Page 49 of 205 SZ31 2. 3. Security control exist but exceptions to the control Security control in place but not consistently implemented CSCRF Data-at-rest and Data-in- motion encryption is present Asset inventory is being maintained but newly onboarded assets are not inventoried due to operational issues. 4.4. Cyber Audit Cyber audit 17 here pertains to the audit conducted for verifying the compliance with CSCRF. MIls and Qualified REs shall strive for building an automated tool and suitable dashboards (preferably integrated with log aggregator) for submitting compliance with CSCRF. The dashboard, once made, shall be available at the time of cyber audit, onsite inspection/ audit by SEBI or any agency appointed by SEBI. Cyber audit shall cover 100% of the critical systems and 25% non-critical systems (chosen on a sample basis). Box Item 3: Cyber Audit and Guidelines To verify the RES' compliance with CSCRF, cyber audit ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....udit shall completed within 5 months of completion of cyber audit. be 4.4.3. Cyber audit report shall be submitted by all applicable REs. The auditor selection norms and format for CSCRF compliance submission has been attached at Annexure-B. Along with the cyber audit report, SEBI REs shall also submit the required declaration from MD/ CEO (as given in Annexure-B). Table 23: Reporting authority for cyber audit report submission Sr. No. Regulated Entity Reporting authority 1. Stock Brokers / Depository Stock Exchanges 2. Participants IAs 3. MIls and rest of the RES Depositories BASL SEBI 4.4.4. The closure of audit observations shall be regularly tracked by IT Committee for REs. Additionally, all open observation after 3 months of completion of cyber audit shall be approved by IT Committee for REs and shall be closed before start of next audit exercise. Page 51 of 205 Version 1.0 S=31 CSCRF 4.4.5. The follow-on audit report and open observations must be placed before their respective IT Committee for REs for their confirmation and appropriate directions. 4.4.6. RES categorised as self-certification shall be required to conduct only VAPT audit throug....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....and and communicate the outcomes, capabilities, and services dependency on external resources such as third-party service providers. Page 53 of 205 S=31 CSCRF 1.2. GV.RR: Roles, Responsibilities and Authorities: i. GV.RR: Objective Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated. ii. GV.RR: Standard 1. The responsibility and accountability for cybersecurity risk lies with the RES' leadership and the leadership is responsible for nurturing a culture that is risk-aware, cybersecurity conscious, and continually improving. 2. Cybersecurity risk management roles, responsibilities, and authorities shall be developed, communicated, understood, and enforced. 3. A CISO/ Designated Officer shall be appointed and report to designated authority in the organization. 4. Budgetary planning process shall be aligned with information security and privacy management objectives and processes. Adequate resources shall be allocated and aligned with cybersecurity risk strategy, roles and responsibilities, and policies. 5. Employees and third-party service providers s....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... as follows: SN. Table 24: Rating categories of REs based on CCI Rating 1 Exceptional Cybersecurity Maturity Index Score Rating 100-91 2 Optimal Cybersecurity Maturity 90-81 3 Manageable Cybersecurity Maturity 80-71 4 Developing Cybersecurity Maturity 70-61 5 Bare Minimum Cybersecurity Maturity 60-51 6 Fail ENTITY TYPE: ENTITY CATEGORY: RATIONALE FOR THE CATEGORY: <> PERIOD OF AUDIT: <> NAME OF THE AUDITING ORGANISATION: Date on which VAPT Report presented to ‘IT Committee for REs': RE's Authorised signatory declaration: I/We hereby confirm that the information provided herein is verified by me/ us and I/ we shall take the responsibility and ownership of this VAPT report. Signature: Name of the signatory: Designation (choose whichever applicable): Company stamp: Annexures: 1. Minutes of the Meeting (MoM) of 'IT Committee for REs' in which the VAPT report was approved. 2. VAPT report as submitted by the auditor Page 133 of 205 Version 1.0 5=31 Table of Contents 1. Auditor's Declaration: 2. Executive Summary: 3. Scope of Audit: 4. Tools used: 5. Exclusions, if any: 6. Summary of the VAPT Report- 6.1. Details of Vulnerability Ass....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... of the Tool: 4.2. Type: Open source/ Commercial 4.3. Operations: manual/ automated/ both 5. Exclusions, if any: Il Please enclose attachments regarding exclusions as approved by 'IT Committee for REs' along with MoM of the meeting where the exclusions were approved. Version 1.0 Page 136 of 205 S331 6. Summary of the VAPT Report: 6.3. Details of Vulnerability Assessment findings: CSCRF Vulnerability Assessment Findings Details Annexure-A Sr. No. 1. Auditor (Name) for VA: 2. VA Start Date: 3. VA End Date: 4. 5. Scope 6. Vulnerability Assessment Number of Identified vulnerabilities Closure Timelines Open vulnerabilities (Shall be applicable during final submission) Auditor Remarks Critical High Medium Low Total Critical High Medium Low Total 7. Critical Assets 8. VA of infrastructure - Internal and External 9. VA of Applications - Internal and External 10. WiFi Testing 11 API Security Testing 12. Network Segmentation 13. VA of mobile applications 14. OS and DB Assessment 15. VA of cloud deployments Page 137 of 205 Version 1.0 S31 16 17. Configuration Audit Others, please specify Version 1.0 Page 138 of 205 CSCRF Annex....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....o ‘IT Committee for REs' : RE's Authorised signatory declaration: I/We hereby confirm that the information provided herein is verified by me/ us and I/ we shall take the responsibility and ownership of this cyber audit report. Further, this is to certify that: a. Comprehensive measures and processes including suitable incentive/ disincentive structures, have been put in place for identification/detection and closure of vulnerabilities in the organization's IT systems. b. Adequate resources have been hired for staffing our Security Operations Centre (SOC). c. There is compliance by us with CSCRF. Signature: Name of the signatory: Designation (choose whichever applicable): Company stamp: Annexures: 1. Minutes of the Meeting (MoM) of 'IT Committee for RES' in which the cyber audit report was approved. 2. Cyber audit report as submitted by the auditor 5=31 Table of Contents CSCRF Annexure-B 1. Auditor's Declaration: 2. Executive Summary: 3. Scope of Audit 3.1. List of SEBI Circulars and Advisories covered 3.2. List of all IT infrastructure and geographical locations (including IT systems of PDC, DR, Near site, Co-lo facility) covered under audit 3.....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....iting Organization) 5. Summary of findings (including identification tests, tools used and results of tests performed) S.No Number of Non- Number of Risk rating conformity observations Critical High Medium Low Any other comments 1 S.N 6. Control-wise Compliance status of SEBI CSCRF: Standards Description Name of Status/natu Risk ° prescribed of the re of by SEBI CSCRF Finding(s)/ Observation( system belongs findings rating (C/H/M/ C/I/A Test Root affecte case Cause d Analysi S Impact analysi Auditor Deadline Manageme Wheth recommendatio (Clause s) to RE or L) of the finding used S ns/ Corrective actions of correcti nt er response ve action(s) number and text) third- party vendor d in the last similar issue was reporte three audits. *List of documenta ry evidence including physical inspection/ sample size taken by auditor the 1 GV.OC. S1 2 GV.OC. S2 ... N EV.ST.S 5 *Explicit reference to the key auditee organisational documents (by date or version) including policy and procedure documents 7. A brief description of the above-mentioned compliance requirements is as follows- i. Standards ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....Deadline of corrective action(s) -The RE shall specify the deadline not only for the corrective action(s) to be taken on the system(s) where NC/ observation was found, but also specify the deadline for corrective action on systems with related functionalities/configurations where similar observations could have been found/are found. xii. Management response recommendation - Management action plan/taken to address the observation and/ or implementation of auditor's xiii. Whether similar issue was reported in the last three audits - Yes/No xiv. List of documentary evidence including physical inspection/ sample size taken by the auditor 8. Format for exception reporting by the RE: These exceptions shall be approved by the IT Committee for RES S. No Standard of CSCRF Descriptio n of non- complianc Auditor observatio Auditor recommendati Managemen t comments n on e Comment of 'IT Committe e for RES' Comments of Board of RE Comments of Board of Trustee (wherever applicable) Status of non- compliance (open/closed) Repeat observation in last 3 audits Deadline for Risk category of corrective action non- compliance 9. The audit report sha....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ed from the infected devices? Resolving the cause of the incident: a. Removing malware, b. Patching vulnerabilities, c. Taking other measures etc. Please specify resolution method. Version 1.0 Page 150 of 205 SZ31 2 v. Recovery checklist CSCRF Annexure-C a. Recover lost or corrupted data, b. Restore normal operations by returning systems and networks to a known good state c. Taking other measures etc. Cybersecurity incident recovery plan scenarios Key assumptions and pre-requisites Authorization Details of the Incident Response Team (IRT) (Internal/External) Details of other teams involved (Internal/External) Cybersecurity incident recovery invocation 3 Categorization of incidents 4 5 6 7 8 9 10 11 12 13 14 Off site location address where 'golden' copy of server images and data are stored Recover System(s) and Services Recovery Actions Lessons learned: Document lessons learned from the incident and incorporate them into incident response and recovery plans. Post-incident: Measures taken to avoid reoccurrence of the cyber incident Perform Hotwash Version 1.0 Page 151 of 205 S=31 CSCRF Part IV: CSCRF Annexures and References Annexu....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....1.0 Page 152 of 205 SZ31 CSCRF Annexure-D b. All audit reports shall be submitted strictly as per the format provided in CSCRF. c. The coverage of the audit shall be as follows: i. REs which have been declared as Clls by NCIIPC shall follow the guidelines/ circulars issued by NCIIPC for selecting sample size for critical/non-critical assets. ii. Rest of the REs shall take the sample size as mentioned in 'CSCRF Compliance, Audit Report'. iii. RE shall ensure that 100% of their critical systems should get covered under cyber audit. Further, RE shall ensure that for 25% of non-critical systems, sample size and sampling method should be mentioned explicitly in the audit report with the rationale of checking it on sample basis and the chosen sample size. iv. As part of audit of the RE, the auditor shall verify, and certify, whether there is a clear delineation/ demarcation of roles and responsibilities between the RE and Hosted service provider (as given in definitions section). The auditor shall also verify, and certify, whether the above- mentioned demarcations of roles and responsibilities have been incorporated in the agreement/ contract signed between the RE ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....n 1.0 SZ31 Annexure-E: Scenario-based Cyber Resilience Testing Scenario-based Cyber Resilience Testing CSCRF Annexure-E This is a sample template for Stock Exchange. REs are encouraged to make their scenarios in consultation with their IT Committee for REs. Sample scenarios that are targeted to cover in Cyber Response plan as well as Cyber Resiliency Testing (Types of Attack × Potential Targeted Time intervals- On Core Systems): Pre-open Sessions Cyber Attack-> DNS DDoS Time Interval Malware/ Malicious Code Attack Application Level Attacks (SaaS Model) Based Brute Attacks Force/Authentication (Internal & based attack Internet) AD attack Before BOD/early Morning Before 9:00 hrs B/W 9:00 9:15 hrs - Regular 09:15 - Trading Sessions 15:30 hrs 15:30-16:00 Closing Session hrs Post 16:00 hrs Version 1.0 Page 155 of 205 5331 Attack Scenario Category Types of attacks Impact DDOS Service Unavailability Ransomware Spyware Malware Attacks Trojans Worms Bots Injection Broken Authentication & Session Application Level Attacks Management Version 1.0 Cross-Site Scripting/request forgery CSCRF Annexure-E Response & Reco....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....w.sebi.gov.in/legal/circulars/sep-2017/outsourcing-of- activities-by-stock-exchanges-and-clearing-corporations 35932.html) 'Outsourcing by Depositories' dated Dec 09, 2015 (Refer: https://www.sebi.gov.in/legal/circulars/dec-2015/outsourcing-by- depositories 31219.html) 'Guidelines on Outsourcing of Activities by Intermediaries' dated Dec 15, 2011 (Refer: https://www.sebi.gov.in/legal/circulars/dec-2011/guidelines-on- outsourcing-of-activities-by-intermediaries 21752.html) Version 1.0 Page 158 of 205 S=31 Annexure-G: Application Authentication Security Illustrative Measures for Application Authentication Security are given below: CSCRF 1. Any Application offered by REs to Customers containing sensitive, private, or critical data such as IBTS, SWSTS, Back office etc. referred to as "Application" hereafter) over the Internet should be password protected. A reasonable minimum length (and no arbitrary maximum length cap or character class requirements) should be enforced. While it is difficult to quantify password "complexity", longer passphrases have more entropy and offer better security in general. REs should attempt to educate Customers of these best practices. ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ata shown to the Customer on the frontend application to ensure that only what is deemed absolutely necessary is transmitted and displayed. 2. Wherever possible, mask portions of sensitive data. For instance, rather than displaying the full phone number or a bank account number, display only a portion of it, enough for the Customer to identify, but useless to an unscrupulous party who may obtain covertly obtain it from the Customer's screen. For instance, if a bank account number is "123 456 789”, consider displaying something akin to “XXX XXX 789" instead of the whole number. This also has the added benefit of not having to transmit the full piece of data over various networks. 3. Analyse data and databases holistically and draw out meaningful and “silos” (physical or virtual) into which different kinds of data can be isolated and cordoned off. For instance, a database with personal financial information need not be a part of the system or network that houses the public facing websites of the REs. They should ideally be in discrete silos or DMZs. 4. Implement strict data access controls amongst personnel, irrespective of their responsibiliti....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....he internet, a valid, properly configured TLS (SSL) certificate on the web server is mandatory, making the transport channel HTTP(S). 3. Avoid the use of insecure protocols such as FTP (File Transfer Protocol) that can be easily compromised with MITM attacks. Instead, adopt secure protocols such as FTP(S), SSH and VPN tunnels, etc. Page 161 of 205 Version 1.0 5=31 CSCRF Annexure-J: Framework for Adoption of Cloud Services SEBI's 'Framework for Adoption of Cloud Services by SEBI Regulated Entities (RES)' circular dated March 06, 2023: (Refer: https://www.sebi.gov.in/legal/circulars/mar-2023/framework-for-adoption-of- cloud-services-by-sebi-regulated-entities-res- 68740.html) Version 1.0 Page 162 of 205 S=31 CSCRF Annexure-K: Cyber Capability Index (CCI) REPORTING FORMAT FOR MIIS AND QUALIFIED RES TO SUBMIT THEIR CCI SCORE NAME OF THE ORGANISATION: ENTITY TYPE: ENTITY CATEGORY: RATIONALE FOR THE CATEGORY: <> PERIOD: <> NAME OF THE AUDITING ORGANISATION (applicable for MIls): RE's Authorised signatory declaration: I/We hereby confirm that Cyber Capability Index (CCI) has been verified by me/ us and I/We shall take the responsibility and ownership of the C....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....Authority for the same. 1. Confirmation 18% that VAPT is done by CERT- In empanelled IS auditing organization and as per the scope prescribed by SEBI Version 1.0 Page 165 of 205 MIls) S31 S No Measure ID Goal/Objective Measure Measure Туре Formula Targ Implementation et Evidence 2. VAPT report and its closure report. CSCRF Annexure-K Self- Auditor asses comment Weig sment htage score s w.r.t. cyber audit (for Mils) 3. Security Information Percentage Training Measure Security Goal: (%) of Implement ation organization's [PR.AT.S 1] Ensure that information personnel are security adequately trained to carry system of 100 % (Number information system security personnel that have completed security training within the past year/total number information personnel that have received out their security of assigned training within information security-related the past one years. system security personnel) x100 duties and responsibilities 3. Time taken to close identified vulnerabilities. the 1. Details of the 5% training/ awareness sessions scheduled within the past 1 year. 2. C....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

..... Is logging 2% activated on the system? 2. Does the organization [DE.CM.S system audit critical systems) have clearly 1] ×100 records to the extent needed to enable monitoring, analysis, investigation, the and reporting of unlawful, unauthorized, suspicious or abnormal activity. defined criteria for constitutes what evidence of "suspicious or abnormal" activity within system audit logs? 3. For the reporting period, how many Version 1.0 Page 169 of 205 system audit logs have been reviewed for past six months for suspicious or abnormal activity. S31 CSCRF Annexure-K S Self- Auditor No Measure ID Goal/Objective Measure Measure Type Formula et Targ Implementation Weig Evidence htage asses sment comment score s w.r.t. cyber audit (for Mils) 6. Configurat Information Percentage ion Security Goal: (%) approved Implement ation (Number Changes Establish and and implemented Measure maintain implemented baseline configuration [DE.CM.S changes configuration 5] and inventories the of organizational information systems (including hardware, software, firmware, and documentation) through....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....s successfully were tested within the past 1 year? 4. Reports of the contingency plan testing conducted past one year. in Version 1.0 Page 172 of 205 Mils) SZ31 8. User Accounts Measure [PR.AA.S 7] Version 1.0 CSCRF Annexure-K Information Percentage Effectiven (Number Security Goal: (%) All privilege privileged users are access identified and through PIM. of ess systems of 100 % 1. Organization 3% should have a documented and approved authenticated in accordance with information security policy. accessed through PIM/ total number of systems) ×100 access control policy systems, applications, networks, for databases etc. 2. How many users have access to the system? 3. How many users access shared accounts? have to 4. Cyber audit observation against Page 173 of 205 Standard mentioned 7 in 'Protect: Identity Management, Authentication, and Access Control' header in CSCRF Part-I and respective guidelines in Part-II. S31 CSCRF Annexure-K S Self- Auditor No asses comment Measure Goal/Objective ID Measure Measure Type Formula et Targ Implementation Weig sment Evidence htage score ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....or reuse. released reuse) × 100 for followed. 3. Cyber audit observation against Standard 14 mentioned in 'Protect: Identity (Number of 0% physical security containing information systems/total number of physical security incidents) ×100 Management, Authentication, and Access Control' header in CSCRF Part-I and respective guidelines in Part-II. 1.Policy/procedu 1% re ensuring the secure physical access to critical systems? 2. How many physical security incidents occurred during the specified period? 3. How many of the physical 12. Physical Information Percentage Effectiven Security Security Goal: (%) of ess Incidents Integrate physical incidents Measure physical and security allowing information incidents unauthorized [PR.AA.S allowing security entry into 10 unauthorized facilities protection entry into ] mechanisms to Version 1.0 ensure appropriate facilities containing information protection of the systems. organization's Page 176 of 205 Mils) S31 CSCRF Annexure-K S Self- Auditor No asses comment Measure Goal/Objective ID Measure Measure Type Formula et Targ Implementatio....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... systems) × 100 1. How many 1% been granted organizational information and information systems? 2. What is the number of individuals who have completed personnel screening? individuals have access to 15. Risk Objective of this Percentage Assessme measure is to of nt periodically organization' Measure [ID.RA.S2 ] assess the risk s information to organization's systems, and IT assets and operations. Cybersecurity risks to the organization's assets covered under risk assessment. Version 1.0 Implement (Number of 100 ation Measure organization's % information systems, and assets covered under risk assessment/Tot al number of organization information Page 179 of 205 1. Has the 5% organization completed a cyber-risk assessment? 3. Cyber Audit observation against Standard mentioned 'Identify: this 2 in Risk S31 CSCRF Annexure-K S Self- Auditor No asses comment Measure Goal/Objective ID Measure Measure Type Formula et Targ Implementation Weig sment Evidence htage score s w.r.t. cyber audit (for information systems, and assets are understood and assessed. 16. Service Information Acquisitio....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....implementation waivers? S31 CSCRF Annexure-K S Self- Auditor No asses comment Measure ID Goal/Objective Measure Measure Type Formula et Targ Implementation Weig sment Evidence htage score s w.r.t. cyber audit (for 18. Risk Based on risk Percentage Effectiven Managem ent appetite of the (%) of ess (Number organization of 100 % 1. Does 8% organization organization, organization information cybersecurity information [GV.RM.S risks are 1, identified, GV.RM.S2 analysed, ] evaluated, prioritized, responded, and monitored. systems, and assets covered under risk management systems, and assets covered under management/To tal number of organization information systems, assets) ×100 and have a cyber- risk management framework? 2. Has the organization established, communicated, and maintained its risk appetite and tolerance statements? risk risk Version 1.0 Page 183 of 205 3. Has organization responded to observations risk based on its risk appetite? Mils) S31 CSCRF Annexure-K S Self- Auditor No asses comment Measure ID Goal/Objective Measure Measure Type Formula et Targ Imp....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....re SOC efficacy % (Annexure-N) 100 1. How effective 5% ess is the functioning of RE'S SOC? 23. Automate d Develop an Percentage Maturity automated tool (%) of measure complianc (preferably standards e with CSCRF integrated with compliance log aggregator) to compliance with CSCRF. automated submit Version 1.0 of 100 (Number standards for % which compliance has been automated for CSCRF compliance/Tota number of CSCRF standards)x100 1. Automated 5% dashboard to get detailed reports of standards CSCRF compliance. Page 186 of 205 531 CSCRF 5. Based on the value of the index, the cybersecurity maturity level of the MIls and Qualified REs shall be determined as follows: SN. Rating Index Score Rating 1 Exceptional Cybersecurity Maturity 100-91 2 Optimal Cybersecurity Maturity 90-81 3 Manageable Cybersecurity Maturity 80-71 4 Developing Cybersecurity Maturity 70-61 5 Bare Minimum Cybersecurity Maturity 60-51 6 Fail ENTITY TYPE: ENTITY CATEGORY: RATIONALE FOR THE CATEGORY: <> PERIOD: <> CSCRF Annexure-N RE's Authorised signatory declaration: I/We hereby confirm that report of functional efficacy of SOC has been....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... Systems Count of Systems to be Count of Systems Sr. SOC Weightage ID integrated No. Technologies (%) (W) applicabl e (x) [to be identified Actually Coverage Weighte Integrated Score d Score and Z=(y/x) (ZXW) covered from table 29] (y) S1, S2, S4, S5, 1 PAM 10 S6 Anti-virus/ 2 EPP 10 S3, S6 3 EDR 10 S3, S6 4 DLP 10 5 DAM 10 S5 6 WAF 10 10 S4 Email- 7 gateway* 10 Web- gateway/ 8 Proxy* 10 9 DDoS* 10 S1, S2, 1 S4, S5, SIEM 10 S6 n Technology-Asset-Coverage-percentage с b) SOC Operations: To determine the efficiency of the periodic activities carried out by SOC personnel for effective threat management and regular maintenance of SOC technologies. Table 31: Methodology to assess the performance of SOC operations Sr. No. Metric Value Weightage (W) (%) Weighted Score 1 Log ingestion into SIEM Log sources reporting to SIEM [A] A 5 (A/B)*W Total No. of Log Sources (from Table 29) [B] B Latency in Log Ingestion (benchmarking 2 against 5 minutes) IF C=5 then score = 0 Version 1.0 Page 192 of 205 5=31 CSCRF Annexure-N Sr. Weightage Weighted No. Metric Value (W) (%) Score 3 SOC techn....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....etency of deployed SOC personnel Sr. No. Categor y of engineer Minimum Weight Certificatio age of Years of Experie n requireme S nt categor y [C] (%) nce Count of Engineer Weighta s having ge of minimum sub- required category certificati Actual sub- categor Weight catego y-wise ed ry Score Score (YoE) [w] ons# [z] = [x] score = [A] Sum [z] W Sum[x] [A] × [C] [B] [w] 1 2 0.25 2 3 0.50 L1 CEH 35 3 4 0.75 4 5 1.00 5 L2 60 CEH+Any product OEM certificatio n 6 0.33 25 25 7 0.66 7 00 8 1.00 3 L3 CISM 40 % 0.25 Version 1.0 Page 194 of 205 5=31 CSCRF Annexure-N Sr. No. Categor y of engineer n requireme Minimum Weight Certificatio age of categor y Weighta Count of Engineer s having Actual sub- categor Weight Years of ge of categoy-wise ed Experie nce minimum sub- required category certificati ry score Score Score [A] = [B] = S (YoE) nt [C] (%) [w] ons# [z] = Sum [z] [A] × [x] × [x] / Sum[x] [C] [w] 10 11 0.75 11 >=12 1.00 Final Score of Manpower P #Fractional YoE shall be converted to be the floor value of the experience for calculation. Example....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ed [T] Total no. of different SOAR actions created [S] 4 | Technologies implemented Version 1.0 Decoy LO 5 (X/T)*W LO 5 (Y/T)*W 5 (Z/T) W A*W LO 5 LO 5 (T/S) W Yes=1, No=0 AxW 3 Page 196 of 205 S=31 CSCRF Annexure-N Weighted Sr. Weightage No. Metric Value(A) (W)(%) Score Sandboxing Solution Yes=1, A*W No=0 3 UEBA Yes=1, AxW No=0 3 Vulnerability Management Yes=1, AxW Solution No=0 3 Yes=1, Encrypted Traffic Management AxW No=0 ♡ Yes=1, AxW DNS Security No=0 3 Yes=1, Intrusion prevention system AxW No=0 3 Yes=1, Data classification solution AxW No=0 3 Total 75 E *The above metric for SOC operations is not exhaustive, REs are required to add other metrics depending upon the maturity of their cybersecurity infrastructure and availability of tools and technologies. 25% weightage is left for this to the REs. Version 1.0 Page 197 of 205 5=31 CSCRF Annexure-O Annexure-O: Classification and Handling of Cybersecurity Incidents A: Guidelines on Classification of Cybersecurity Incidents Threshold for classifying incidents: 1. Any incident stated under CERT-In Cybersecurity directions 35 and meeting below....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ve financial or public relations impact, etc. Successful penetration or Denial of Service attacks detected with significant impact on operations; ransomware attack; exfiltration of market sensitive data; widespread instances of data corruption causing impact on operations; significant risk of negative financial or public relations impact, etc. 4. Any cyber incident that results in disruption, stoppage or variance in the normal functions/operations of systems of the entity thereby impacting normal/ regular service delivery and functioning of the entity, must be classified as High or Critical incident. Version 1.0 Page 199 of 205 S=31 B: Guidelines on Handling of Cybersecurity Incidents CSCRF Annexure-O 1. Any cyber-attack(s), cybersecurity incident(s) and breach(es) experienced by RES falling under CERT-In Cybersecurity directions 37 shall be notified to SEBI and CERT-In within 6 hours of noticing/ detecting such incidents or being brought to notice about such incidents. This information shall be shared to SEBI through the email ID [email protected] within 6 hours and SEBI Incident Reporting Portal within 24 hours. Stock Brokers/ Depository Participant....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....) has been performed by RE. f. Whether lessons learnt have been implemented by RE. g. Whether the issues/loopholes identified in RCA stage have been addressed/plugged by the RE. h. Whether RE has hired any independent agency to conduct IS Audit/ forensic audit related to the incident (as per applicability). i. Whether RE has addressed/plugged vulnerabilities identified in the audit mentioned in point h above. 3.3. RE shall undertake the necessary activities and submit the relevant reports as per the following timelines: Table 36: Timelines for post-cyber incident activity(ies) and report submission Sr. No. Name of the Report/ Activity 1 Interim Report* Timeline for Submission (from the date of reporting the incident or being brought to notice about the incident) 3 Days 2 Mitigation measure 3 4 5 Root Cause Analysis (RCA) report** Forensic Audit Report (on the incident) and its closure report Vulnerability Assessment and Penetration Testing (VAPT) for the incident and its closure reports 6 Any other report as required by SEBI 7 Days 30 Days# Refer clause 3.4 below 45 days To be submitted as per SEBI direction *The interim report must contain, ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....by MIls, Qualified REs, and Mid-size REs shall be mandatorily put up for the review for HPSC-CS. Remaining incidents i.e., low and medium for all REs, and high and critical severity incidents for small-size and self-certification REs shall be processed by SEBI internally. The review by HPSC-CS and SEBI shall be as follows: 3.8.1. Review by HPSC-CS Version 1.0 i. For all the incidents placed before HPSC-CS, the committee may confirm the severity or may recommend a different severity on the basis of its analysis. ii. The committee will examine the reports, review the severity of the incident and provide its recommendations on the same. Page 202 of 205 SZ31 CSCRF Annexure-O iii. Further, if the committee determines that the incident occurred on account of non-compliance of SEBI cybersecurity framework/ advisories, appropriate regulatory action may be taken by SEBI on the RE notwithstanding any action levied above. iv. The recommendations of the committee shall be implemented by the RE in a time-bound manner. The timelines for the implementation shall be decided by the committee based on the discussion with relevant stakeholders (i.e. SEBI and the RE). V. RE m....