Sebi clarifies on cybersecurity and cyber resilience framework
Markets regulator Sebi on Thursday clarified that the cybersecurity and cyber resilience framework (CSCRF) applies only to systems used exclusively for its regulated activities. Shared infrastructure will also be audited if not already covered by the RBI or another regulator. Further, if regulated entities (REs) comply with RBI (or other regulator) cybersecurity rules that are equivalent to Sebi's, such compliance will be accepted by the markets watchdog. In its circular, Sebi also elaborated on the definition of critical systems, stating that it includes all systems that affect core operations, store or transmit regulatory data, client-facing applications, internet-facing systems, and other systems on the same network. REs have been asked to adopt zero-trust principles such as network segmentation, high availability, and avoiding single points of failure with approval from their IT Committees. The regulator said that guidelines relating to mobile applications are recommendatory, ...