TMI BlogModification in Cyber Security and Cyber resilience framework for Stock Brokers / Depository ParticipantsX X X X Extracts X X X X X X X X Extracts X X X X ..... ository Participants SEBI vide circular SEBI/HO/MIRSD/CIR/PB/2018/147 dated December 03, 2018 prescribed framework for Cyber Security and Cyber Resilience for Stock Brokers / Depository Participants. 2. In partial modification to Annexure -1 of SEBI circular dated December 03, 2018, the paragraph-11, 41, 42 and 44 shall be read as under: 11. Stock Brokers / Depository Participants shall identi ..... X X X X Extracts X X X X X X X X Extracts X X X X ..... assets (internal and external), details of its network resources, connections to its network and data flows. 41. Stock Brokers / Depository Participants shall carry out periodic Vulnerability Assessment and Penetration Tests (VAPT) which inter-alia include critical assets and infrastructure components like Servers, Networking systems, Security devices, load balancers, other IT systems pertaining ..... X X X X Extracts X X X X X X X X Extracts X X X X ..... ility scanning and conduct penetration testing prior to the commissioning of a new system which is a critical system or part of an existing critical system. 44. Any gaps/vulnerabilities detected shall be remedied on immediate basis and compliance of closure of findings identified during VAPT shall be submitted to the Stock Exchanges / Depositories within 3 months post the submission of final VAP ..... X X X X Extracts X X X X X X X X Extracts X X X X ..... days from the date of this Circular. 6. Stock Exchanges and Depositories shall; a) make necessary amendments to the relevant byelaws, rules and regulations for the implementation of the above direction; and b) bring the provisions of this circular to the notice of their members/participants and also disseminate the same on their websites. 7. The provisions of the Circular shall come into fo ..... X X X X Extracts X X X X X X X X Extracts X X X X
|