The National Bank for Agriculture and Rural Development (NABARD) on December 17, 2024, notified regarding the Conduct of Information Technology/Cyber Security Audit.
There has been an increasing number of cyber incidents and attacks that require all systems to be alert and vigilant regarding potential threats. This is primarily due to the existence of vulnerabilities in software, applications, websites and configurations of IT infrastructure. Moreover, due to application of emerging technologies such as Artificial Intelligence/ Machine Learning, Internet of Things, etc. threat vectors are evolving and becoming more complex.
The following have been advised:
• In order to take preventive measures and minimize the security risk & exposures, all Supervised Entities of NABARD (viz. State Cooperative Banks, District Central Cooperative Banks and Regional Rural Banks) should get their IT infrastructure, websites and applications (including APIs) audited on a regular basis or whenever there are any changes/updates in infrastructure or websites/applications.
• Audits should be conducted against comprehensive frameworks and should follow MeitY/CERT-In Guidelines released/updated from time to time (enclosed). The list of empanelled agencies who can do the cyber security audit is available at: https://www.cert-in.org.in/PDF/Empanel org.pdf.
It is also advised to immediately put in place a system of regular conduct of cyber security audit through CERT-In empanelled agencies strictly as per the MeitY/CERT-In guidelines atleast on an annual basis or whenever there are any changes/updates in infrastructure or websites/ applications, in consultation with the Board of Directors of your bank.
[Circular No. 307/DoS-25/2024]