News Details- (Get Professional Updates on Whatsapp, Msg on
8285393786) More
News
SEBI issues cybersecurity framework for KYC Registration Agencies
Amid concerns over possible data breaches, markets regulator Sebi on Tuesday put in place a detailed cybersecurity framework for KYC registration agencies, requiring them to define responsibilities of employees, including outsourced staff, who have privileged access to networks. Besides, the watchdog said that no person should have any intrinsic right to access confidential data by virtue of their rank or position.
With the new norms, to be effective from January 1, 2020, KYC registration agencies or KRAs would be required to define the responsibilities of its employees, including outsourced staff, who have privileged access to the networks, the Securities and Exchange Board of India (Sebi) said in a circular.
Sebi said that rapid technological developments in securities market have highlighted the need for maintaining robust cyber security and cyber resilience framework to protect the integrity of data and guard against breaches of privacy.
Cybersecurity framework includes measures, tools and processes that are intended to prevent cyber-attacks and improve cyber resilience.
"Since KRAs perform important function of maintaining KYC records of the clients in the securities market, it is desirable that KRAs have robust Cyber Security and Cyber Resilience framework in order to provide essential facilities and perform systemically critical functions relating to securities market," Sebi noted.
Accordingly, Sebi has asked KRAs to formulate a comprehensive cybersecurity and cyber resilience policy document encompassing the framework.
The policy document should be approved by the board of KRAs and in case of deviations from the suggested framework, reasons for such deviations, technical or otherwise, should be provided in the policy document. The document should be reviewed by the board of KRAs at least annually.
KRAs will have to define responsibilities of its employees, outsourced staff, and employees of vendors, members and other entities, who may have privileged access to the networks. Further, such staff should also be subject to stringent supervision, monitoring and access restrictions.
They need to establish a reporting procedure to facilitate communication of unusual activities and events to the designated officer in a timely manner.
KRAs should establish appropriate security monitoring systems and processes to facilitate continuous monitoring of security events and timely detection of unauthorised or malicious activities, held in contractual or fiduciary capacity, by internal and external parties.
Sebi said that alerts generated from monitoring and detection systems need to be suitably investigated in order to determine activities that are to be performed to prevent expansion of such incident of cyber attack or breach, mitigate its effect and eradicate the incident. #casansaar (Source - PTI, SEBI, MoneyControl)
With the new norms, to be effective from January 1, 2020, KYC registration agencies or KRAs would be required to define the responsibilities of its employees, including outsourced staff, who have privileged access to the networks, the Securities and Exchange Board of India (Sebi) said in a circular.
Sebi said that rapid technological developments in securities market have highlighted the need for maintaining robust cyber security and cyber resilience framework to protect the integrity of data and guard against breaches of privacy.
Cybersecurity framework includes measures, tools and processes that are intended to prevent cyber-attacks and improve cyber resilience.
"Since KRAs perform important function of maintaining KYC records of the clients in the securities market, it is desirable that KRAs have robust Cyber Security and Cyber Resilience framework in order to provide essential facilities and perform systemically critical functions relating to securities market," Sebi noted.
Accordingly, Sebi has asked KRAs to formulate a comprehensive cybersecurity and cyber resilience policy document encompassing the framework.
The policy document should be approved by the board of KRAs and in case of deviations from the suggested framework, reasons for such deviations, technical or otherwise, should be provided in the policy document. The document should be reviewed by the board of KRAs at least annually.
KRAs will have to define responsibilities of its employees, outsourced staff, and employees of vendors, members and other entities, who may have privileged access to the networks. Further, such staff should also be subject to stringent supervision, monitoring and access restrictions.
They need to establish a reporting procedure to facilitate communication of unusual activities and events to the designated officer in a timely manner.
KRAs should establish appropriate security monitoring systems and processes to facilitate continuous monitoring of security events and timely detection of unauthorised or malicious activities, held in contractual or fiduciary capacity, by internal and external parties.
Sebi said that alerts generated from monitoring and detection systems need to be suitably investigated in order to determine activities that are to be performed to prevent expansion of such incident of cyber attack or breach, mitigate its effect and eradicate the incident. #casansaar (Source - PTI, SEBI, MoneyControl)
Category : SEBI | Comments : 0 | Hits : 449
Get Free Daily Updates Via e-Mail on Income Tax, Service tax, Excise and Corporate law
Search News
News By Categories More Categories
- Income Tax Dept serves notices to salaried individuals for documentary proof to claim exemptions
- Bank Branch Audit 2021 - Update on allotment of Branches
- Bank Branch Audit 2020 Updates
- Bank Branch Audit 2021 Updates
- Bank Branch Audit 2020 - Update on Allotment of Branches
- Police Atrocities towards CA in Faridabad - Its Time to be Unite
- Bank Branch Statutory Audit Updates 2019
- Bank Branch Statutory Audit Updates
- Bank Branch Audit 2022 Updates
- Bank Branch Statutory Audit Updates
- NFRA Imposes Monetary penalty of Rs 1 Crore on M/s Dhiraj & Dheeraj
- ICAI notifies earlier announced CA exam dates despite pending legal challenge before SC
- NFRA debars Auditors, imposes Rs 50 lakh penalties for lapses in Brightcom, CMIL cases
- GST Important Update - Enhancement in the GST Portal
- NFRA Slaps Rs 5 lakh Penalty on Audit Firm for lapses in Vikas WSP Audit Case
- CBDT extends due date for filing Form 10A/10AB upto 30th June, 2024
- RBI comes out with FEMA regulations for direct listing on international exchange
- RBI directs payment firms to track high-value, fishy transactions during elections
- NCLT orders insolvency proceedings against Subhash Chandra
- Income Tax dept starts drive to dispose of appeals, 0.54 million at last count
- Payment of MCA fees –electronic mode-regarding
- Budget '11-12' Parliament Completes Approval Exercise
- Satyam restrained from operating its accounts
- ICICI a foreign firm, subject to FDI norms: Govt
- Maha expects Rs 15 crore entertainment tax revenue from IPL
- CAG blames PMO for not acting against Kalmadi
- No service tax on visa facilitators: CBEC
- Provision of 15-minutes reading and planning time allowance to the candidates of Chartered Accountants Examinations
- Companies Bill to be taken up in Monsoon Session
- File Service Tax Return in time as Maximum Penalty increased 10 times to Rs. 20000

Comments