SEBI issues consultation paper on cyber security, resilience framework for regulated entities
New Delhi, July 5, 2023
SEBI’s consultation paper looks at providing a common structure for multiple approaches to cyber security to prevent any cyber-risks/incidents
SEBI, on Tuesday, came out with a consultation paper on boosting cyber security framework for entities regulated by it.
The consultation paper on 'Consolidated Cyber Security and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities' looks at providing a common structure for multiple approaches to cyber security to prevent any cyber-risks/incidents.
SEBI said the framework is based on five concurrent and continuous functions of cyber security as defined by NIST -- Identify, Protect, Detect, Respond, and Recover.
NIST refers to the National Institute of Standards and Technology.
"All REs shall formulate an up-to-date Cyber Crisis Management Plan (CCMP)," the consultation paper said, adding that they would also have to put in place a comprehensive incident response management plan and respective Standard Operating Procedures (SOPs).
"Alerts generated from monitoring and detection systems shall be suitably investigated for Root Cause Analysis (RCA)," it noted.
Comments on the consultation paper can be submitted to the regulator till July 25.
[The Hindus Business Line]