SEBI modifies Cyber Security and Cyber Resilience Framework of Mutual Funds/ Asset Management Companies (AMCs)

Jun 09, 2022 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Secretarial ComplianceThe Securities and Exchange Board of India (SEBI) on June 09, 2022 has modified Cyber Security and Cyber Resilience Framework of Mutual Funds/ Asset Management Companies (AMCs) by making amendment in Circular No. SEBI/HO/IMD/DF2/CIR/P/2019/12 dated January 10, 2019.

The following amendments have been made:

• Paragraph 11, which comes under heading Identity, has been substituted, namely:

“11. Mutual Funds/ AMCs shall identify and classify critical assets based on their sensitivity and criticality for business operations, services and data management. The critical assets shall include business critical systems, internet facing applications/ systems, systems that contain sensitive data, sensitive personal data, sensitive financial data, Personally Identifiable Information (PII) data, etc. All the ancillary systems used for accessing/ communicating with critical systems either for operations or maintenance shall also be classified as critical assets. The Board of the AMCs and Trustees shall approve the list of critical assets.

To this end, Mutual Funds/ AMCs shall maintain up-to-date inventory of its hardware and systems, software and information assets (internal and external), details of its network resources, connections to its network and data flows.”

• Paragraph 40, 41 and 42 , which comes under heading “Vulnerability Assessment and Penetration Testing (VAPT) has been substituted, namely:

“40. Mutual Funds/ AMCs shall carry out periodic VAPT, inter-alia, including critical assets and infrastructure components like servers, networking systems, security devices, load balancers, other IT systems pertaining to the activities done as a role of Mutual Funds/ AMCs, etc., in order to detect security vulnerabilities in the IT environment and in-depth evaluation of the security posture of the system through simulations of actual attacks on its

systems and networks.

Mutual Funds/ AMCs shall conduct VAPT at least once in a financial year. However, for the Mutual Funds/ AMCs, whose systems have been identified as “protected system” by National Critical Information Infrastructure Protection Centre (NCIIPC) under the Information Technology (IT) Act, 2000, VAPT shall be conducted at least twice in a financial year.

Further, all Mutual Funds/ AMCs shall engage only Indian Computer Emergency Response Team (CERT-In) empanelled organizations for conducting VAPT. The final report on said VAPT shall be submitted to SEBI after approval from Technology Committee of respective Mutual Funds/ AMCs, within 1 month of completion of VAPT activity.

41. Any gaps or vulnerabilities detected shall be remedied on immediate basis and compliance of closure of findings identified during VAPT shall be submitted to SEBI within 3 months post the submission of final VAPT report.

42. In addition, Mutual Funds/ AMCs shall perform vulnerability scanning and conduct penetration testing prior to the commissioning of a new system which is a critical system or part of an existing critical system.”

• Paragraph 51, which comes under heading “Sharing of information” has been substituted, namely:

“51. All cyber-attacks, threats, cyber-incidents, and breaches experienced by Mutual Funds/ AMCs shall be reported to SEBI within 6 hours of noticing/ detecting such incidents or being brought to their notice about such incidents. The incident shall also be reported to CERT-In in accordance with

the guidelines/ directions issued by CERT-In from time to time. Additionally, the Mutual Funds/ AMCs, whose systems have been identified as “protected system” by NCIIPC, shall also report the incident to NCIIPC. The quarterly reports containing information on cyber-attacks, threats, cyber-incidents, and breaches experienced by Mutual Funds/ AMCs and measures taken to mitigate vulnerabilities, threats and attacks including information on bugs/ vulnerabilities/ threats that may be useful for other Mutual Funds/ AMCs shall be submitted to SEBI within 15 days from the quarter ended June, September, December and March of every year.

It is mandatory for all the the Mutual Funds/ AMCs to conduct comprehensive cyber audit at least 2 times in a financial year. Along with the cyber audit reports, henceforth, all Mutual Funds/ AMCs are directed to submit a declaration from the Managing Director (MD)/ Chief Executive Officer (CEO) certifying compliance by the Mutual Funds/ AMCs with all SEBI Circulars and advisories related to cyber security from time to time.

The provisions of this Circular shall come into force with effect from July 15, 2022.

[Circular No. SEBI/HO/IMD/IMD-I/DOF2/P/CIR/2022/81]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT