RBI issues new cybersecurity framework for commercial banks


Banks must now conduct vulnerability assessments every six months, annual penetration tests for critical internet-facing systems, and half-yearly disaster recovery drills under the Reserve Bank of India’s new cybersecurity framework. The Reserve Bank of India (RBI) on July 31 issued the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, replacing the existing patchwork of cybersecurity instructions with a single framework. The directions apply immediately to commercial banks, including banking companies, corresponding new banks and the State Bank of India, but exclude small finance banks, payments banks and local area banks.

Data and information assets:

  • Maintain an up-to-date inventory of information assets, including business and customer data, applications, infrastructure and critical personnel.
  • Classify data based on sensitivity.
  • Maintain an enterprise data dictionary.
  • Protect data throughout its lifecycle, whether stored, processed or transmitted internally or by third parties.
  • Implement a data loss prevention strategy and remote wipe capability for mobile devices.

Systems and infrastructure:

  • Put in place formal data migration controls with audit trails and business signoffs.
  • Maintain inventories of authorised and unauthorised software.
  • Block unauthorised software and apply emergency patches for actively exploited vulnerabilities.
  • Define an exception management process for delayed patching.
  • Secure data centres and disaster recovery sites with physical and environmental controls.
  • Ensure primary and disaster recovery sites are geographically separated.
  • Review IT capacity requirements at least annually.

Network and application security:

  • Apply secure baseline configurations across devices, operating systems, databases, applications and security tools.
  • Maintain updated network architecture diagrams and device inventories.
  • Detect and block unauthorised devices on bank networks.
  • Deploy layered network defences, including firewalls, intrusion detection and prevention systems, and traffic filtering.
  • Support IPv6 on public-facing infrastructure.
  • Follow secure software development practices, including threat modelling, security testing and secure coding.
  • Test applications throughout their lifecycle and evaluate emerging technologies before deployment.
  • Obtain source code or escrow arrangements for critical applications supplied by vendors.

Access and customer authentication:

  • Grant system access only where there is a valid business need.
  • Monitor privileged users and log their activities.
  • Enforce centralised identity and access management.
  • Implement multi-factor authentication for privileged users and critical activities.
  • Remove unnecessary administrator rights and disable dormant accounts.
  • Secure remote working with multi-factor authentication and device controls.
  • Establish an authentication framework that allows customers to verify the bank’s identity across channels.

Email, removable media and third parties:

  • Protect email systems against spoofing, phishing and malicious attachments.
  • Implement DMARC for email domains.
  • Restrict removable media and BYOD use through centralised controls.
  • Conduct vendor risk assessments and ensure third parties comply with cybersecurity requirements.
  • Include RBI audit rights and cybersecurity obligations in vendor contracts.
  • Require ATM switch providers to implement prescribed baseline cybersecurity controls.

Operational resilience:

  • Use strong cryptographic standards.
  • Prevent manual changes to data transferred between critical systems through straight-through processing.
  • Establish a Cyber Security Operations Centre (CSOC).
  • Deploy anti-malware across endpoints, servers, gateways and mobile environments.
  • Subscribe to anti-phishing services to identify and remove phishing websites and rogue applications.

Vulnerability testing:

  • Conduct vulnerability assessments and penetration testing for all critical and internet-facing systems.
  • Perform vulnerability assessments at least every six months and penetration testing at least every 12 months for critical customer-facing systems.
  • Conduct testing after implementation of new systems and major upgrades.
  • Fix identified vulnerabilities within defined timelines and monitor closure of findings.
  • Use independent and qualified auditors for testing.

Business continuity and disaster recovery:

  • Conduct disaster recovery drills for critical systems at least every six months.
  • Test disaster recovery sites by operating them as the primary site for at least one full business day.
  • Regularly restore backups to verify their usability.
  • Aim for near-zero Recovery Point Objective (RPO) for critical information systems.
  • Ensure disaster recovery environments mirror production environments.
  • Test resilience across interconnected vendor systems.

Incident response:

  • Put in place a cyber incident response and recovery policy.
  • Cyber security incidents need to be reported on the DAKSH platform within six hours.
  • Define incident classification, reporting mechanisms, communication plans, recovery measures and threat information sharing processes.
  • Allocate responsibilities for employees and outsourced personnel handling incidents.

Board responsibilities: 

  • Boards must approve IT, cybersecurity, information security and business continuity policies.
  • Review these policies at least annually.
  • Constitute a Board-level IT Strategy Committee.
  • The Audit Committee will oversee information systems audits.

Management and organisational structure:

  • Banks must establish an IT governance framework covering strategy, risk, performance and business continuity.
  • Maintain separate information security and cybersecurity policies.
  • The IT Strategy Committee must meet at least quarterly.
  • Senior management must oversee implementation of IT strategy and cybersecurity.
  • Banks must establish an IT Steering Committee and an Information Security Committee.
  • Appoint a senior Head of IT Function and an independent Chief Information Security Officer (CISO), with the CISO reporting to the executive overseeing risk management rather than the Head of IT.
  • The CISO must present cybersecurity preparedness to the Board or relevant committee every quarter.

Risk management: 

  • Include IT and cybersecurity risks in enterprise risk management.
  • Review IT risk policies at least annually.
  • Establish a formal IT and information security risk management framework.
  • Assess information assets using recognised security standards.
  • Review security infrastructure and policies at least annually.
  • Categorise risks based on their severity and evaluate the effectiveness of existing controls.

Also read:



Source link

Recent Articles

spot_img

Related Stories