Sebi comes up with cybersecurity norms for portfolio managers


By MYBRANDBOOK


Sebi comes up with cybersecurity norms for portfolio managers

Capital markets regulator Sebi has come out with a cybersecurity framework for all portfolio managers having an asset base of at least Rs 3,000 crore. The new guidelines will come into force from October 1, 2023.

 

Under the framework, Sebi asked portfolio managers to report all cyber-attacks and breaches experienced by them within 6 hours of detecting such incidents.

 

"The response and recovery plan of the portfolio manager should aim at the timely restoration of systems affected by incidents of cyber-attacks or breaches. Portfolio managers should have Recovery Time Objective and Recovery Point Objective not more than 4 hours and 30 minutes, respectively," Sebi said.

 

The regulator said that with rapid technological advancement in the securities market, there is a greater need for maintaining robust cyber security and to have a cyber-resilience framework to protect the integrity of data and guard against breaches of privacy.

 

As part of the operational risk management, the portfolio managers need to have a robust cyber security and cyber resilience framework in order to provide essential facilities and services and perform critical functions in the securities market, Sebi said.

 

Accordingly, all portfolio managers with assets under management of Rs 3,000 crore or more, under discretionary and non-discretionary portfolio management service taken together, as on the last date of the previous calendar month will comply with the provisions of cybersecurity and cyber-resilience.

 

The policy document should be approved by the board and in case of deviations from the suggested framework, reasons for such deviations should also be provided in the policy document.

 E-Magazine 
 VIDEOS  Placeholder image

Copyright www.mybrandbook.co.in @1999-2024 - All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.
Other Initiatives : www.varindia.com | www.spoindia.org