TMI BlogModification in Cyber Security and Cyber resilience framework of Qualified Registrars to an Issue and Share Transfer Agents (“QRTAs”)X X X X Extracts X X X X X X X X Extracts X X X X ..... rity and Cyber resilience framework of Qualified Registrars to an Issue and Share Transfer Agents ("QRTAs") 1. SEBI vide circular SEBI/HO/MIRSD/CIR/P/2017/100 dated September 08, 2017 prescribed framework for Cyber Security and Cyber Resilience for Qualified Registrars to an Issue and Share Transfer Agents ("QRTAs") 2. In partial modification to Annexure A of SEBI circular dated September 08, 20 ..... X X X X Extracts X X X X X X X X Extracts X X X X ..... ssets (internal and external), details of its network resources, connections to its network and data flows. 40. QRTAs shall carry out periodic vulnerability assessment and penetration tests (VAPT) which inter-alia include critical assets and infrastructure components like Servers, Networking systems, Security devices, load balancers, other IT systems etc. pertaining to the activities done as a Q ..... X X X X Extracts X X X X X X X X Extracts X X X X ..... asis and compliance of closure of findings identified during VAPT shall be submitted to SEBI within 3 months post the submission of final VAPT report. 42. In addition, QRTAs shall perform vulnerability scanning and conduct penetration testing prior to the commissioning of a new system which is a critical system or part of an existing critical system. 3. Further, the QRTAs are mandated to conduc ..... X X X X Extracts X X X X X X X X Extracts X X X X ..... stors in securities and to promote the development of, and to regulate the securities market. 8. The circular is issued with the approval of the competent authority. 9. This circular is available on SEBI website at www.sebi.gov.in under the categories "Legal Framework" and "Circulars". Yours faithfully, Aradhana Verma Deputy General Manager Market Intermediaries Regulation and Supervision De ..... X X X X Extracts X X X X X X X X Extracts X X X X
|