SEBI modifies Cyber Security and Cyber Resilience framework of Stock Exchanges, Clearing Corporations and Depositories

May 20, 2022 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Secretarial ComplianceThe Securities and Exchange Board of India (SEBI) on May 20, 2022 has issued a notification regarding the modification in the Cyber Security and Cyber Resilience framework of Stock Exchanges, Clearing Corporations and Depositories which has been issued by SEBI vide circular no. SEBI/CIR/MRD/DP/13/2015 dated July 06, 2015.

The following modifications have been made:

• In the annexure A of the above stated notification paragraph 11, has been substituted, namely:

11. MII should identify and classify/designate critical assets based on their sensitivity and criticality for business operations, services and data management. The critical assets should include business critical systems, internet facing applications /systems, systems that contain sensitive data, sensitive personal data, sensitive financial data, Personally Identifiable Information (PII) data, etc. All the ancillary systems used for accessing/communicating with critical systems either for operations or maintenance should also be classified as critical system. The Board of the

MII shall approve the list of critical systems. To this end, MII should maintain up-to-date inventory of its hardware and systems, software and information assets (internal and external), details of its network resources, connections to its network and data flows.

• In the annexure A of the above stated notification paragraph 40, has been substituted, namely:

40. MIIs should carry out periodic vulnerability assessment and penetration testing (VAPT) which inter-alia includes all critical assets and infrastructure components like Servers, Networking systems, Security devices, load balancers, other IT systems pertaining to the activities done as a role of MII etc., in order to detect security vulnerabilities in the IT environment and in-depth evaluation of the security posture of the system through simulations of actual attacks on its systems and networks.

MIIs should conduct VAPT at least once in a financial year. However, for the MIIs, whose systems have been identified as “protected system” by National Critical Information Infrastructure Protection Centre (NCIIPC), VAPT shall be conducted at least twice in a financial year. Further, all MIIs are required to engage only CERT-In empaneled organizations for conducting VAPT. The final report on said VAPT should be submitted to SEBI after approval from Standing Committee on Technology (SCOT) of respective MIIs, within 1 month of completion of VAPT activity.

• In the annexure A of the above stated notification paragraph 41, has been substituted, namely:

41. Any gaps/vulnerabilities detected have to be remedied on immediate basis and compliance of closure of findings identified during VAPT shall be submitted to SEBI within 3 months post the submission of final VAPT report to SEBI.

• In the annexure A of the above stated notification paragraph 42, has been substituted, namely:

42. In addition, MIIs should also perform vulnerability scanning and conduct penetration testing prior to the commissioning of a new system which is a critical system or part of an existing critical system.

The MIIs are mandated to conduct comprehensive cyber audit at least 2 times in a financial year. Along with the Cyber audit reports, henceforth, all MIIs are directed to submit a declaration from the MD/ CEO certifying compliance by the MII with all SEBI Circulars and advisories related to Cyber security issued from time to time.

MIIs are required to take necessary steps to put in place systems for implementation of the circular, including necessary amendments to the relevant bye-laws, rules and regulations, if any.

All MIIs are directed to communicate the status of the implementation of the provisions of this circular to SEBI within 10 days from the date of this Circular.

[Circular No. SEBI/HO/MRD1/MRD1_DTCS/P/CIR/2022/68]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT