SEBI issued a Consultation Paper on Consolidated Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities

Jul 05, 2023 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Secretarial ComplianceThe Securities and Exchange Board of India (SEBI) on July 04, 2023, issued a Consultation Paper on Consolidated Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities.

The SEBI issued the consultation paper to enhance the scope of cybersecurity and cyber resilience framework, to address the need for uniformity of cybersecurity guidelines for all Res, and to strengthen the mechanism to deal with cyber risks/threats/incidents, the master framework on cybersecurity and cyber resilience has been drafted after discussion with SEBI's High Powered Steering Committee - Cyber Security (HPSC-CS).

The framework provides a common structure for multiple approaches to cybersecurity to prevent any cyber risks/incidents. The framework follows a graded approach and divides the guidelines into three parts:

• Applicable to all RES

• Applicable to specified RES²

• Applicable to Market Infrastructure Institutions (MIIs)

The framework is based on five concurrent and continuous functions of cybersecurity as defined by NIST-Identify, Protect, Detect, Respond, and Recover. It references globally recognized standards, e.g., NIST Special Publication 800-53 Revision 5, COBIT 5, and CIS controls for cybersecurity controls, outcomes, and guidance to achieve those outcomes.

Kindly find the complete consultation paper attached to the document. 


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT