Loading Vaultize
Skip to main content

Compliance/India/RBI Cyber Security

Seven chapters: nine paragraphs leave evidence in the file.

The Directions make the regulated entity answerable for its information assets, wherever they are used. Vaultize adds records that stay with the data.

IIIIIIIVVVIVII
IPreliminary0 outcomes
  • RBI/2023-24/107
  • In force from 1 April 2024
  • Capability mapping, not supervisory assessment
9paragraphs across 3 of 7 chapters

The answer in 30 seconds

Vaultize adds file-level records to nine paragraphs under IT Infrastructure and Services Management, the IT and Information Security Risk Management Framework, and Disaster Recovery Management. Governance, risk assessment, VA/PT and IS audit belong to the regulated entity and its auditors.

The Directions in one view

Seven chapters. Thirty-two paragraphs. Where file evidence lands.

The Master Direction runs in seven chapters. Select a chapter to see which of its paragraphs a governed file can evidence.

IIIIIIIVVVIVII

I

Preliminary

Paragraphs 1 to 3. Title, commencement, applicability and definitions.

Outcomes the file can evidence

None on this page.

    How Vaultize contributes
    Applicability is decided by the regulated entity and its counsel.
    Evidence to retain
    None from Vaultize.

    Paragraph by paragraph

    What each paragraph asks. What the file can answer.

    Paragraph wording is quoted from the Master Direction as published by the Reserve Bank; longer paragraphs are excerpted. Each row is a capability mapping, not a supervisory assessment.

    Using this page

    Where these rows fit under the Directions.

    The Directions apply from 1 April 2024 to the regulated entities named in paragraph 2. The rows above are evidence for the paragraphs that touch documents.

    1. 1

      Confirm applicability

      Paragraph 2. Which category of regulated entity, and which paragraphs apply.

    2. 2

      Set the standards

      Chapter II. Board, IT Strategy Committee and documented procedures.

    3. 3

      Operate the controls

      Chapter III. Access, cryptography, audit trails, third parties. These rows belong here.

      Bring the nine rows above as evidence for the paragraphs that cover documents.

    4. 4

      Test and recover

      Chapter V. Backups, restores and DR drills.

    5. 5

      Audit and report

      Chapter VI, and incident reporting to the Reserve Bank.

    Responsibility boundary

    Controls support supervision. A product does not satisfy it.

    Vaultize contributes technical controls and evidence for information held in documents. It does not decide applicability, replace the regulated entity’s governance, policies or IS audit, or stand in for supervisory assessment by the Reserve Bank. Read the Directions and the 2016 Cyber Security Framework, and take qualified advice before relying on this page.

    “Access to information assets shall be allowed only where a valid business need exists.”

    Paragraph 19(a), RBI IT Governance Directions, 2023

    A practical next step

    Bring one document a customer or vendor receives.

    We will show which paragraphs the governed document can evidence today. We will name the control owner responsible for the rest.

    Request a compliance mapping session