Home India Securities and Exchange Board of India Modification in Cyber Security and Cyber Resilience framewor...
Date: 2022-05-20 Category: Not Applicable State: Union Government Country: India

Modification in Cyber Security and Cyber Resilience framework of Stock Exchanges, Clearing Corporations and Depositories

Issued by Securities and Exchange Board of India · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: SEBI issued a circular modifying the Cyber Security and Cyber Resilience framework for Stock Exchanges, Clearing Corporations, and Depositories. It mandates updates to critical asset management, vulnerability assessments, and cyber audits. MIIs must submit implementation status to SEBI within 10 days of the circular and a declaration of compliance with cybersecurity circulars from the MD/CEO along with cyber audit reports. The circular takes effect immediately. Key Points / Main Content: * **Critical Asset Management:** * MIIs must identify, classify, and designate critical assets based on sensitivity and criticality. * The Board of the MII shall approve the list of critical systems. * Maintain an up-to-date inventory of hardware, software, information assets, network resources, and data flows. * **Vulnerability Assessment and Penetration Testing (VAPT):** * Conduct periodic VAPT, including all critical assets and infrastructure components, at least once per financial year. * MIIs identified as protected systems by NCIIPC must conduct VAPT at least twice per financial year. * Engage only CERT-In empaneled organizations for conducting VAPT. * Submit the final VAPT report to SEBI within 1 month of completion, after SCOT approval. * Remedy detected gaps/vulnerabilities immediately and submit compliance on closure of findings to SEBI within 3 months of VAPT report submission. * Perform vulnerability scanning and penetration testing prior to commissioning new or modifying existing critical systems. * **Cyber Audit and Compliance:** * Conduct comprehensive cyber audits at least twice in a financial year. * Submit a declaration from the MD/CEO certifying compliance with all SEBI cybersecurity circulars and advisories along with cyber audit reports. * **Implementation and Communication:** * MIIs must implement the circular's provisions, including necessary amendments to relevant byelaws, rules, and regulations. * MIIs must communicate the status of implementation to SEBI within 10 days of the circular. Impact Analysis: Stock Exchanges: * Impact: Required to update and enhance their cybersecurity framework in line with the new directives, including asset management, VAPT, and audit processes. * Action Required: Implement the provisions of the circular, amend byelaws if needed, communicate implementation status to SEBI within 10 days, and ensure compliance with all directives. Clearing Corporations: * Impact: Must adhere to the revised cybersecurity guidelines to protect critical infrastructure and data. * Action Required: Implement the provisions of the circular, amend byelaws if needed, communicate implementation status to SEBI within 10 days, and ensure compliance with all directives. Depositories: * Impact: Must strengthen their cybersecurity measures as per the modified framework to safeguard sensitive information and maintain system resilience. * Action Required: Implement the provisions of the circular, amend byelaws if needed, communicate implementation status to SEBI within 10 days, and ensure compliance with all directives.

Key Entities Referenced

Securities and Exchange Board of India (SEBI): The regulatory body issuing the circular, responsible for regulating the securities market in India. Stock Exchanges: Entities involved in the trading of stocks and other securities, regulated by SEBI. Clearing Corporations: Organizations that facilitate the clearing and settlement of securities transactions, regulated by SEBI. Depositories: Organizations that hold securities in electronic form, regulated by SEBI. Cyber Security and Cyber Resilience framework: The framework that outlines the guidelines and measures for protecting the IT systems of Stock Exchanges, Clearing Corporations and Depositories against cyber threats. Vulnerability Assessment and Penetration Testing (VAPT): A security testing process that involves identifying vulnerabilities in IT systems and simulating attacks to evaluate the security posture. National Critical Information Infrastructure Protection Centre (NCIIPC): The agency responsible for protecting critical information infrastructure in India. Standing Committee on Technology (SCOT): A committee within Market Infrastructure Institutions (MIIs) responsible for technology-related matters, including the approval of VAPT reports.
Official Source Record View Original Source →
See Full Document Text
¼ããÀ¦ããè¾ã ¹ãÆãä¦ã¼ãîãä¦ã ‚ããõÀ ãäÌããä¶ã½ã¾ã ºããñ¡Ã Securities and Exchange Board of India CIRCULAR SEBI/HO/MRD1/MRD1_DTCS/P/CIR/2022/68 May 20, 2022 To All Stock Exchanges, All Clearing Corporations, All Depositories Dear Sir / Madam, Modification in Cyber Security and Cyber Resilience framework of Stock Exchanges, Clearing Corporations and Depositories 1. SEBI vide circular no. SEBI/CIR/MRD/DP/13/2015 dated July 06, 2015 prescribed framework for Cyber Security and Cyber Resilience for stock exchanges, clearing corporations and depositories. 2. In partial modification to Annexure A of SEBI circular dated July 06, 2015, the paragraph-11, 40, 41 and 42 shall be read as under: 11. MII should identify and classify/designate critical assets based on their sensitivity and criticality for business operations, services and data management. The critical assets should include business critical systems, internet facing applications /systems, systems that contain sensitive data, sensitive personal data, sensitive financial data, Personally Identifiable Information (PII) data, etc. All the ancillary systems used for accessing/communicating with critical systems either for operations or maintenance should also be classified as critical system. The Board of the MII shall approve the list of critical systems. To this end, MII should maintain up-to-date inventory of its hardware and systems, software and information assets (internal and external), details of its network resources, connections to its network and data flows. Page 1 of 3¼ããÀ¦ããè¾ã ¹ãÆãä¦ã¼ãîãä¦ã ‚ããõÀ ãäÌããä¶ã½ã¾ã ºããñ¡Ã Securities and Exchange Board of India 40. MIIs should carry out periodic vulnerability assessment and penetration testing (VAPT) which inter-alia includes all critical assets and infrastructure components like Servers, Networking systems, Security devices, load balancers, other IT systems pertaining to the activities done as a role of MII etc., in order to detect security vulnerabilities in the IT environment and in-depth evaluation of the security posture of the system through simulations of actual attacks on its systems and networks. MIIs should conduct VAPT at least once in a financial year. However, for the MIIs, whose systems have been identified as “protected system” by National Critical Information Infrastructure Protection Centre (NCIIPC), VAPT shall be conducted at least twice in a financial year. Further, all MIIs are required to engage only CERT-In empaneled organizations for conducting VAPT. The final report on said VAPT should be submitted to SEBI after approval from Standing Committee on Technology (SCOT) of respective MIIs, within 1 month of completion of VAPT activity. 41. Any gaps/vulnerabilities detected have to be remedied on immediate basis and compliance of closure of findings identified during VAPT shall be submitted to SEBI within 3 months post the submission of final VAPT report to SEBI. 42. In addition, MIIs should also perform vulnerability scanning and conduct penetration testing prior to the commissioning of a new system which is a critical system or part of an existing critical system. 3. Further, the MIIs are mandated to conduct comprehensive cyber audit at least 2 times in a financial year. Along with the Cyber audit reports, henceforth, all MIIs are directed to submit a declaration from the MD/ CEO certifying compliance by the MII with all SEBI Circulars and advisories related to Cyber security issued from time to time. 4. MIIs are required to take necessary steps to put in place systems for implementation of the circular, including necessary amendments to the relevant bye-laws, rules and regulations, if any. 5. All MIIs are directed to communicate the status of the implementation of the provisions of this circular to SEBI within 10 days from the date of this Circular. 6. The provisions of the Circular shall come into force with immediate effect. Page 2 of 3¼ããÀ¦ããè¾ã ¹ãÆãä¦ã¼ãîãä¦ã ‚ããõÀ ãäÌããä¶ã½ã¾ã ºããñ¡Ã Securities and Exchange Board of India 7. This circular is being issued in exercise of powers conferred under Section 11 (1) of the Securities and Exchange Board of India Act, 1992 to protect the interests of investors in securities and to promote the development of, and to regulate the securities market. 8. The circular is issued with the approval of the competent authority. 9. This circular is available on SEBI website at www.sebi.gov.in under the categories “Legal Framework” and “Circulars”. Yours faithfully, Ansuman Dev Pradhan Deputy General Manager +91-22-26449622 ansumanp@sebi.gov.in Page 3 of 3

Continue your research