Home India Securities and Exchange Board of India Modification in Cyber Security and Cyber resilience framewor...
Date: 2022-06-30 Category: Not Applicable State: Union Government Country: India

Modification in Cyber Security and Cyber resilience framework for Stock Brokers / Depository Participants

Issued by Securities and Exchange Board of India · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Summary:** This circular, reference number SEBI/HO/MIRSD/DTP/CIR/2022/93 dated June 30, 2022, issued by the Securities and Exchange Board of India (SEBI), modifies the existing cyber security and cyber resilience framework for Stock Brokers and Depository Participants. This circular amends Annexure 1 of the SEBI circular dated December 03, 2018, specifically paragraph 52, concerning the reporting of cyber incidents. The key change mandates that all Cyberattacks, threats, cyber incidents, and breaches experienced by Stock Brokers and Depository Participants must be reported to Stock Exchanges, Depositories, and SEBI within 6 hours of detection or notification. Reports to SEBI should be submitted via the dedicated email address: sbdpcyberincidents@sebi.gov.in. Furthermore, incidents must also be reported to the Indian Computer Emergency Response Team (CERT-In) in accordance with CERT-In guidelines. Stock Brokers and Depository Participants whose systems are identified as "Protected systems" by the National Critical Information Infrastructure Protection Centre (NCIIPC) must also report incidents to NCIIPC. Quarterly reports detailing cyberattacks, threats, incidents, breaches, and mitigation measures, including information on bugs and vulnerabilities, must be submitted to Stock Exchanges and Depositories within 15 days from the end of each quarter (June, September, December, and March). Stock Exchanges and Depositories are directed to amend their byelaws, rules, and regulations to implement these changes and to disseminate the circular's provisions to their members/participants and on their websites. The circular takes effect immediately and is issued under Section 11(1) of the Securities and Exchange Board of India Act, 1992, to protect investors' interests and regulate the securities market. For further information, contact Vishal M Padole, Deputy General Manager, MIRSD, at Tel. No: 022 26449247 or via email at vishalps@sebi.gov.in.

Key Entities Referenced

Securities and Exchange Board of India (SEBI): Regulatory body for the securities market in India, responsible for protecting investors and regulating the market. Stock Exchanges: Organizations that provide a platform for trading stocks and other securities. Depositories: Organizations that hold securities in electronic form, enabling efficient trading and settlement. Stock Brokers: Intermediaries that execute buy and sell orders for securities on behalf of investors. Depository Participants: Agents of depositories that provide depository services to investors. Cyber Security and Cyber Resilience framework: Framework prescribed by SEBI to protect Stock Brokers and Depository Participants from cyber threats and ensure business continuity. Indian Computer Emergency Response Team (CERT-In): National agency responsible for responding to computer security incidents in India. National Critical Information Infrastructure Protection Centre (NCIIPC): Agency responsible for protecting critical information infrastructure in India.
Official Source Record View Original Source →
See Full Document Text
CIRCULAR SEBI/HO/MIRSD/TPD/P/CIR/2022/93 June 30, 2022 To All Recognized Stock Exchanges and Depositories Dear Sir/ Madam, Sub: - Modification in Cyber Security and Cyber resilience framework for Stock Brokers / Depository Participants 1. SEBI vide circular dated 03 December 2018, 15 October 2019 and 07 June 2022 prescribed framework for Cyber Security and Cyber Resilience for Stock Brokers / Depository Participants. 2. In partial modification to Annexure 1 of SEBI circular dated December 03,2018 the paragraph-52 shall be read as under: 52. All Cyber-attacks, threats, cyber-incidents and breaches experienced by Stock Brokers / Depositories Participants shall be reported to Stock Exchanges / Depositories & SEBI within 6 hours of noticing / detecting such incidents or being brought to notice about such incidents. This information shall be shared to SEBI through the dedicated e-mail id: sbdp-cyberincidents@sebi.gov.in. The incident shall also be reported to Indian Computer Emergency Response team (CERT-In) in accordance with the guidelines / directions issued by CERT-In from time to time. Additionally, the Stock Brokers / Depository Participants, whose systems have been identified as “Protected system” by National Critical Information Infrastructure Protection Centre (NCIIPC) shall also report the incident to NCIIPC. Page 1 of 2The quarterly reports containing information on cyber-attacks, threats, cyber-incidents and breaches experienced by Stock Brokers / Depository Participants and measures taken to mitigate vulnerabilities, threats and attacks including information on bugs / vulnerabilities, threats that may be useful for other Stock Brokers / Depository Participants / Exchanges /Depositories and SEBI, shall be submitted to Stock Exchanges / Depositories within 15 days from the quarter ended June, September, December and March of every year. 3. Stock Brokers / Depository Participants shall take necessary action for implementation of the circular. 4. Stock Exchanges and Depositories shall; a) make necessary amendments to the relevant byelaws, rules and regulations for the implementation of the above direction and b) bring the provisions of this circular to the notice of their members/participants and also disseminate the same on their websites. 5. The provisions of the Circular shall come into force with immediate effect. 6. This circular is being issued in exercise of powers conferred under Section 11 (1) of the Securities and Exchange Board of India Act, 1992 to protect the interests of investors in securities and to promote the development of, and to regulate the securities market. Yours faithfully, Vishal M Padole Deputy General Manager MIRSD Tel. No: 022 26449247 Email ID: vishalp@sebi.gov.in Page 2 of 2

Continue your research