SEBI modifies Cyber Security & Cyber Resilience Framework for KRAs
- Blog|News|Company Law|
- < 1 minute
- By Chetan Kulasri
- |
- Last Updated on 1 June, 2022

Circular no. SEBI/HO/MIRSD/DoP/P/CIR/2022/74, Dated: 30.05.2022
The SEBI has modified the framework prescribed for Cyber Security & Cyber Resilience for KYC Registration Agencies (KRAs). As per the modified framework, more detailed norms are provided for the classification/designation of the critical assets.
The critical assets shall include business critical systems, internet facing applications /systems, systems that contain sensitive data, sensitive personal data, sensitive financial data, Personally Identifiable Information (PII) data, etc. All the ancillary systems used for accessing/communicating with critical systems either for operations or maintenance shall also be classified as critical system. The Board of the KRAs shall approve the list of critical systems
Further, the final report of the Vulnerability Assessment and Penetration Testing (VAPT) is required to be submitted to the SEBI within 1 month of the completion of VAPT activity. The circular is made effective immediately.
Click Here To Read The Full Notification
Disclaimer: The content/information published on the website is only for general information of the user and shall not be construed as legal advice. While the Taxmann has exercised reasonable efforts to ensure the veracity of information/content published, Taxmann shall be under no liability in any manner whatsoever for incorrect information, if any.

CA | CS | CMA