November 23, 2024 12:57 (IST)
RBI asks banks to boost their cyber security framework
Mumbai, Jun 3 (IBNS) The Reserve Bank of India (RBI) notified all scheduled commercial banks (excluding regional rural banks) that they should immediately put in place a cyber-security policy elucidating the strategy containing an appropriate approach to combat cyber threats given the level of complexity of business and acceptable levels of risk, duly approved by their Board.
In a notification on Thursday, addressed to all bank heads, the RBI said use of Information Technology (IT) by banks and their constituents has grown rapidly and is now an integral part of the operational strategies of banks.
The RBI had provided guidelines on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds (G.Gopalakrishna Committee) vide a circular dated April 29, 2011, wherein it was indicated that the measures suggested for implementation cannot be static and banks need to pro-actively create/fine-tune/modify their policies, procedures and technologies based on new developments and emerging concerns.
Since then, the use of technology by banks has gained further momentum. On the other hand, the number, frequency and impact of cyber incidents / attacks have increased manifold in the recent past, more so in the case of financial sector including banks.
The RBI thus said there an urgent need to put in place a robust cyber security/resilience framework at banks and to ensure adequate cyber-security preparedness among banks on a continuous basis. These would include, but not limited to, putting in place an adaptive Incident Response, Management and Recovery framework to deal with adverse incidents/disruptions, if and when they occur.
The central bank also said that banks should immediately put in place a cyber-security policy elucidating the strategy containing an appropriate approach to combat cyber threats given the level of complexity of business and acceptable levels of risk, duly approved by their Board and send a confirmation in this regard to RBI's Mumbai-bsed Cyber Security and Information Technology Examination (CSITE) Cell of Department of Banking Supervision, Reserve Bank of India, Central Office not later than September 30, 2016.
The notification also mentioned that to address the need for the entire bank to contribute to a cyber-safe environment, the Cyber Security Policy should be distinct and separate from the broader IT policy / IS Security policy so that it can highlight the risks from cyber threats and the measures to address / mitigate these risks.
Having observed that banks are hesitant to share cyber-incidents faced by them, the RBI said, "Experience gained globally indicates that collaboration among entities in sharing the cyber-incidents and the best practices would facilitate timely measures in containing cyber-risks. It is reiterated that banks need to report all unusual cyber-security incidents (whether they were successful or were attempts which did not fructify) to the Reserve Bank."
The notification also mentioned that to address the need for the entire bank to contribute to a cyber-safe environment, the Cyber Security Policy should be distinct and separate from the broader IT policy / IS Security policy so that it can highlight the risks from cyber threats and the measures to address / mitigate these risks.
Having observed that banks are hesitant to share cyber-incidents faced by them, the RBI said, "Experience gained globally indicates that collaboration among entities in sharing the cyber-incidents and the best practices would facilitate timely measures in containing cyber-risks. It is reiterated that banks need to report all unusual cyber-security incidents (whether they were successful or were attempts which did not fructify) to the Reserve Bank."
Support Our Journalism
We cannot do without you.. your contribution supports unbiased journalism
IBNS is not driven by any ism- not wokeism, not racism, not skewed secularism, not hyper right-wing or left liberal ideals, nor by any hardline religious beliefs or hyper nationalism. We want to serve you good old objective news, as they are. We do not judge or preach. We let people decide for themselves. We only try to present factual and well-sourced news.
Support objective journalism for a small contribution.
Latest Headlines
After US fraud indictments over bribery allegations, Adani Group faces global fallout Sat, Nov 23 2024
Mahindra teases sketches of BE 6e, XEV 9e Fri, Nov 22 2024
Ather Energy Limited unveils ‘Eight70 Warranty’ for the battery of its electric scooters Fri, Nov 22 2024
Bitcoin soars to all-time high, nearing the $100,000 milestone Fri, Nov 22 2024