The Multi Commodity Exchange of India Limited (MCX) on December 23, 2024, issued the notification regarding the Submission of VAPT report and/or Action taken report (ATR)/Compliance Report – Reminder.
The following has been stated namely: -
• Trading Members are required to conduct Vulnerability Assessment and Penetration Testing (VAPT) between September and November for FY 2024-25, as per SEBI guidelines.
• The VAPT should include critical applications (trading, back office, and related) and infrastructure such as servers, network systems, security devices, and load balancers.
• Key areas for testing include grey box assessments of web/mobile applications, authenticated vulnerability assessments of infrastructure, and external penetration testing of public-facing URLs/IPs.
• The network architecture, firewall rules, and infrastructure configurations must also be reviewed. Wireless penetration testing is also part of the scope.
• A detailed VAPT report, including findings and a checklist of test cases with "PASS" or "FAIL" status, should be prepared.
• The report must be digitally signed by a CERT-In empaneled entity. This final report, approved by the Technology Committee, must be submitted through the enhanced portal to the Stock Exchange by December 31, 2024.
• The submission should include a summary of the findings in the specified format. The report will help ensure that all systems related to stock broking activities meet security standards.
• Any gaps/vulnerabilities detected shall be remedied on immediate basis and compliance of closure of findings identified during VAPT shall be submitted to the Stock Exchanges within 3 months post the submission of final VAPT report.
• For any open vulnerabilities as reported and submitted in VAPT report, members are required to submit ATR/Compliance Report along with Closure report of all the vulnerabilities closed digitally signed by the CERT-In empaneled entity as appointed by the member by March 31, 2025, on member portal.
[Notification No. MCX/TECH/838/2024]