SEBI modifies Cyber Security & Cyber Resilience Framework for KRAs

  • Blog|News|Company Law|
  • < 1 minute
  • By Chetan Kulasri
  • |
  • Last Updated on 1 June, 2022

KYC Registration Agencies

Circular no. SEBI/HO/MIRSD/DoP/P/CIR/2022/74, Dated: 30.05.2022

The SEBI has modified the framework prescribed for Cyber Security & Cyber Resilience for KYC Registration Agencies (KRAs). As per the modified framework, more detailed norms are provided for the classification/designation of the critical assets.

The critical assets shall include business critical systems, internet facing applications /systems, systems that contain sensitive data, sensitive personal data, sensitive financial data, Personally Identifiable Information (PII) data, etc. All the ancillary systems used for accessing/communicating with critical systems either for operations or maintenance shall also be classified as critical system. The Board of the KRAs shall approve the list of critical systems

Further, the final report of the Vulnerability Assessment and Penetration Testing (VAPT) is required to be submitted to the SEBI within 1 month of the completion of VAPT activity. The circular is made effective immediately.

Click Here To Read The Full Notification

Disclaimer: The content/information published on the website is only for general information of the user and shall not be construed as legal advice. While the Taxmann has exercised reasonable efforts to ensure the veracity of information/content published, Taxmann shall be under no liability in any manner whatsoever for incorrect information, if any.

Leave a Reply

Your email address will not be published. Required fields are marked *

Everything on Tax and Corporate Laws of India

To subscribe to our weekly newsletter please log in/register on Taxmann.com