Compliance/India/RBI Cyber Security
Seven chapters: nine paragraphs leave evidence in the file.
The Directions make the regulated entity answerable for its information assets, wherever they are used. Vaultize adds records that stay with the data.
- RBI/2023-24/107
- In force from 1 April 2024
- Capability mapping, not supervisory assessment
The answer in 30 seconds
Vaultize adds file-level records to nine paragraphs under IT Infrastructure and Services Management, the IT and Information Security Risk Management Framework, and Disaster Recovery Management. Governance, risk assessment, VA/PT and IS audit belong to the regulated entity and its auditors.
The Directions in one view
Seven chapters. Thirty-two paragraphs. Where file evidence lands.
The Master Direction runs in seven chapters. Select a chapter to see which of its paragraphs a governed file can evidence.
I
Preliminary
Paragraphs 1 to 3. Title, commencement, applicability and definitions.
Outcomes the file can evidence
None on this page.
- How Vaultize contributes
- Applicability is decided by the regulated entity and its counsel.
- Evidence to retain
- None from Vaultize.
Paragraph by paragraph
What each paragraph asks. What the file can answer.
Paragraph wording is quoted from the Master Direction as published by the Reserve Bank; longer paragraphs are excerpted. Each row is a capability mapping, not a supervisory assessment.
Using this page
Where these rows fit under the Directions.
The Directions apply from 1 April 2024 to the regulated entities named in paragraph 2. The rows above are evidence for the paragraphs that touch documents.
- 1
Confirm applicability
Paragraph 2. Which category of regulated entity, and which paragraphs apply.
- 2
Set the standards
Chapter II. Board, IT Strategy Committee and documented procedures.
- 3
Operate the controls
Chapter III. Access, cryptography, audit trails, third parties. These rows belong here.
Bring the nine rows above as evidence for the paragraphs that cover documents.
- 4
Test and recover
Chapter V. Backups, restores and DR drills.
- 5
Audit and report
Chapter VI, and incident reporting to the Reserve Bank.
Responsibility boundary
Controls support supervision. A product does not satisfy it.
Vaultize contributes technical controls and evidence for information held in documents. It does not decide applicability, replace the regulated entity’s governance, policies or IS audit, or stand in for supervisory assessment by the Reserve Bank. Read the Directions and the 2016 Cyber Security Framework, and take qualified advice before relying on this page.
“Access to information assets shall be allowed only where a valid business need exists.”
Paragraph 19(a), RBI IT Governance Directions, 2023
Official references
Read the source before relying on the mapping.
Paragraph wording comes from the first item. The others are the Reserve Bank’s own instruments.
- RBI IT Governance, Risk, Controls and Assurance Practices Directions, 2023RBI/2023-24/107 of 7 November 2023, in force from 1 April 2024. Every paragraph quoted on this page is from it.
- Cyber Security Framework in Banks, 2 June 2016RBI/2015-16/418. Protection of customer information, the Cyber Crisis Management Plan, the SOC and incident reporting to the Reserve Bank.
- RBI Outsourcing of IT Services Directions, 2023Third-party arrangements that fall inside these Directions rather than paragraph 10.
A practical next step
Bring one document a customer or vendor receives.
We will show which paragraphs the governed document can evidence today. We will name the control owner responsible for the rest.
