Home India Securities and Exchange Board of India Modification in Cyber Security and Cyber resilience framewor...
Date: 2022-05-27 Category: Not Applicable State: Union Government Country: India

Modification in Cyber Security and Cyber resilience framework of Qualified Registrars to an Issue and Share Transfer Agents (“QRTAs”)

Issued by Securities and Exchange Board of India · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: This circular, issued by SEBI on May 27, 2022, modifies the Cyber Security and Cyber Resilience framework for Qualified Registrars to an Issue and Share Transfer Agents (QRTAs). It mandates periodic vulnerability assessments and penetration tests (VAPT), comprehensive cyber audits, and requires QRTAs to submit a declaration of compliance. QRTAs must communicate their implementation status to SEBI within 10 days of the circular's date. Key Points / Main Content: * **Critical Asset Management:** * QRTAs must identify and classify critical assets, including systems containing sensitive data. * The Board of QRTAs must approve the list of critical systems. * Maintain up-to-date inventory of hardware, software, and information assets. * **Vulnerability Assessment and Penetration Testing (VAPT):** * QRTAs must conduct VAPT at least once a financial year. * QRTAs identified as protected systems by NCIIPC must conduct VAPT at least twice a financial year. * Only CERT-In empaneled organizations can conduct VAPT. * The final VAPT report, approved by the Technology Committee, must be submitted to SEBI within 1 month of completion. * Vulnerability scanning and penetration testing must be performed before commissioning new critical systems. * **Remediation and Compliance:** * Identified gaps/vulnerabilities must be remedied immediately. * Compliance on closure of VAPT findings must be submitted to SEBI within 3 months of the final VAPT report. * **Cyber Audit and Compliance Declaration:** * QRTAs must conduct comprehensive cyber audits at least twice a financial year. * A declaration from the MD/CEO certifying compliance with SEBI's cybersecurity circulars and advisories must be submitted along with the cyber audit reports. * **Implementation and Reporting:** * QRTAs must implement the provisions of this circular. * QRTAs must communicate the status of implementation to SEBI within 10 days of the circular's date. * The circular is effective immediately. Impact Analysis: * **Qualified Registrars to an Issue and Share Transfer Agents (QRTAs):** * Impact: Stricter cybersecurity requirements including more frequent VAPT and cyber audits, plus updated critical asset management and reporting obligations. * Action Required: Identify and classify critical assets, conduct VAPT and cyber audits, remediate vulnerabilities, submit reports and compliance declarations to SEBI, and communicate implementation status within 10 days. * **Securities and Exchange Board of India (SEBI):** * Impact: Increased oversight of QRTAs' cybersecurity practices. * Action Required: Review VAPT reports, compliance submissions, and implementation status reports from QRTAs.

Key Entities Referenced

SEBI: Securities and Exchange Board of India, the regulatory body issuing the circular. Qualified Registrars to an Issue and Share Transfer Agents (QRTAs): Entities regulated by SEBI, subject to the cybersecurity framework. Cyber Security and Cyber Resilience: The main subject of the circular, focusing on improving the cybersecurity posture of QRTAs. SEBIHOMIRSDCIRP2017100: Reference to a previous SEBI circular dated September 08, 2017, establishing the initial cybersecurity framework. Vulnerability Assessment and Penetration Tests (VAPT): A security assessment process that QRTAs are required to conduct periodically. NCIIPC: National Critical Information Infrastructure Protection Centre, an organization that identifies protected systems under the IT Act, 2000. Information Technology IT Act, 2000: Law under which NCIIPC identifies protected system CERT-In: Indian Computer Emergency Response Team, the organization whose empaneled organizations are to be engaged for conducting VAPT.
Official Source Record View Original Source →
See Full Document Text
CIRCULAR SEBI/HO/MIRSD/MIRSD_RTAMB/P/CIR/2022/73 May 27, 2022 To, Registered Registrar to an Issue and Share Transfer Agents Dear Sir/ Madam, Subject: - Modification in Cyber Security and Cyber resilience framework of Qualified Registrars to an Issue and Share Transfer Agents (“QRTAs”) 1. SEBI vide circular SEBI/HO/MIRSD/CIR/P/2017/100 dated September 08, 2017 prescribed framework for Cyber Security and Cyber Resilience for Qualified Registrars to an Issue and Share Transfer Agents (“QRTAs”) 2. In partial modification to Annexure A of SEBI circular dated September 08, 2017, the paragraph-11, 40, 41 and 42 shall be read as under: 11. QRTAs shall identify and classify critical assets based on their sensitivity and criticality for business operations, services and data management. The critical assets should include business critical systems, internet facing applications /systems, systems that contain sensitive data, sensitive personal data, sensitive financial data, Personally Identifiable Information (PII) data, etc. All the ancillary systems used for accessing/communicating with critical systems either for operations or maintenance should also be classified as critical system. The Board of the QRTAs shall approve the list of critical systems. To this end, QRTAs should maintain up-to-date inventory of its hardware and systems, software and information assets (internal and external), details of its network resources, connections to its network and data flows. Page 1 of 340. QRTAs shall carry out periodic vulnerability assessment and penetration tests (VAPT) which inter-alia include critical assets and infrastructure components like Servers, Networking systems, Security devices, load balancers, other IT systems etc. pertaining to the activities done as a QRTAs in order to detect security vulnerabilities in the IT environment and in-depth evaluation of the security posture of the system through simulations of actual attacks on its systems and networks. QRTAs shall conduct VAPT at least once in a financial year. However, for the QRTAs, whose systems have been identified as “protected system” by NCIIPC under the Information Technology (IT) Act, 2000, VAPT shall be conducted at least twice in a financial year. Further, all QRTAs are required to engage only CERT-In empaneled organizations for conducting VAPT. The final report on said VAPT shall be submitted to SEBI after approval from Technology Committee of respective QRTAs, within 1 month of completion of VAPT activity. 41. Any gaps/vulnerabilities detected shall be remedied on immediate basis and compliance of closure of findings identified during VAPT shall be submitted to SEBI within 3 months post the submission of final VAPT report. 42. In addition, QRTAs shall perform vulnerability scanning and conduct penetration testing prior to the commissioning of a new system which is a critical system or part of an existing critical system. 3. Further, the QRTAs are mandated to conduct comprehensive cyber audit at least twice in a financial year. All QRTAs shall submit a declaration from the MD/ CEO certifying compliance by the QRTAs with all SEBI Circulars and advisories related to Cyber security from time to time, along with the Cyber audit reports. Page 2 of 34. QRTAs are required to take necessary steps to put in place systems for implementation of the circular. 5. All QRTAs are directed to communicate the status of the implementation of the provisions of this circular to SEBI within 10 days from the date of this Circular. 6. The provisions of the Circular shall come into force with immediate effect. 7. This circular is being issued in exercise of powers conferred under Section 11 (1) of the Securities and Exchange Board of India Act, 1992 to protect the interests of investors in securities and to promote the development of, and to regulate the securities market. 8. The circular is issued with the approval of the competent authority. 9. This circular is available on SEBI website at www.sebi.gov.in under the categories “Legal Framework” and “Circulars”. Yours faithfully, Aradhana Verma Deputy General Manager Market Intermediaries Regulation and Supervision Department Tel. No. 022-2644 9633 Email id - aradhanad@sebi.gov.in Page 3 of 3

Continue your research