Framework · Last verified
Cyber Security Framework in Banks
RBI's 2016 circular directs scheduled commercial banks (excluding Regional Rural Banks) to build cyber security governance, an SOC, and incident reporting. The circular states: "Use of Information Technology by banks and their constituents has grown rapidly and is now an integral part of the operational strategies of banks." It applies to "All Scheduled Commercial Banks (excluding Regional Rural Banks).".
- Class
- Framework
- Owner
- Reserve Bank of India (RBI), Department of Banking Supervision (DBS)
- Last verified
What it is
The circular is titled "Cyber Security Framework in Banks" and carries the reference RBI/2015-16/418, DBS.CO/CSITE/BC.11/33.01.001/2015-16, dated 2 June 2016.
The RBI opens the circular with its own rationale: "Use of Information Technology by banks and their constituents has grown rapidly and is now an integral part of the operational strategies of banks."
The circular states: "it is mandated that a SOC (Security Operations Centre) be set up at the earliest."
The circular states: "A Cyber Crisis Management Plan (CCMP) should be immediately evolved and should be a part of the overall Board approved strategy."
The circular sets two dates directly in its text: gap-analysis reporting "not later than July 31, 2016 by the Chief Information Security Officer", and full implementation "not later than September 30, 2016."
Who owns it
The circular is issued by the Reserve Bank of India, Department of Banking Supervision (DBS.CO/CSITE cell).
Who asks for it
Statutory (scoped). The circular's own scope line names "All Scheduled Commercial Banks (excluding Regional Rural Banks)" — Regional Rural Banks are not covered by this circular.
The scope line addressed by the circular itself reads: "All Scheduled Commercial Banks (excluding Regional Rural Banks)" — Regional Rural Banks are outside this circular's named scope.
Sources
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.