IFSCA issued Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs

Mar 11, 2025 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe International Financial Services Centres Authority (IFSCA) on March 10, 2025, issued Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs.

The key components of guidelines are categorized into: -

• Governance - organizations shall establish a governance mechanism for cyber risk management, overseen by a designated body, which may include senior management roles like the MD, CISO, CTO, or compliance officers.

• Cyber Security and Cyber Resilience Framework – it ensures confidentiality, integrity, and availability while helping entities anticipate, withstand, and recover from cyberattacks. 

• Third Party Risk Management - REs shall implement a collaborative security approach with third-party vendors, set clear data security expectations, conduct risk-based reviews every six months for critical service providers, and establish communication channels for addressing risks. 

• Communication & Awareness - REs shall conduct regular cybersecurity training for employees on topics like phishing, social engineering, and password hygiene while ensuring clear reporting channels for cyber threats and vulnerabilities.

• Audit - REs shall conduct periodic independent audits of their cybersecurity measures through CERT-In empaneled auditors or qualified professionals with certifications like CISA, CISM, GSNA, or CISSP. 

• This shall come into effect from April 01, 2025.

[Notification no. - IFSCA-CSD0MSC/13/2025-DCS]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT