Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

RBI ITF-NBFC

16 controls
119 checks mapped

The Reserve Bank of India (RBI) cyber security framework mandates baseline security controls for regulated banks and financial institutions.

Controls assessed

3.1.a Identification and Classification of Information Assets4

NBFCs shall maintain detailed inventory of Information Asset with distinct and clear identification of the asset.

3.1.c Role based Access Control25

Access to information should be based on well-defined user roles (system administrator, user manager, application owner etc.), NBFCs shall avoid dependence on one or few persons for a particular job. There should be clear delegation of authority for right to upgrade/change user profiles and permissions and also key business parameters (eg. interest rates) which should be documented.

3.1.g Incident Management5

The IS Policy should define what constitutes an incident. NBFCs shall develop and implement processes for preventing, detecting, analysing and responding to information security incidents.

3.1.h Trails16

NBFCs shall ensure that audit trails exist for IT assets satisfying its business requirements including regulatory and legal requirements, facilitating audit, serving as forensic evidence when required and assisting in dispute resolution. If an employee, for instance, attempts to access an unauthorized section, this improper activity should be recorded in the audit trail.

3.1.i Public Key Infrastructure (PKI)10

NBFCs may increase the usage of PKI to ensure confidentiality of data, access control, data integrity, authentication and nonrepudiation.

3.3 Vulnerability Management5

A vulnerability can be defined as an inherent configuration flaw in an organization's information technology base, whether hardware or software, which can be exploited by a third party to gather sensitive information regarding the organization. Vulnerability management is an ongoing process to determine the process of eliminating or mitigating vulnerabilities based upon the risk and cost associated with the vulnerabilities. NBFCs may devise a strategy for managing and eliminating vulnerabilities and such strategy may clearly be communicated in the Cyber Security policy.

3.5 Cyber Crisis Management Plan4

A Cyber Crisis Management Plan (CCMP) should be immediately evolved and should be a part of the overall Board approved strategy. CCMP should address the following four aspects: (i) Detection (ii) Response (iii) Recovery and (iv) Containment. NBFCs need to take effective measures to prevent cyber-attacks and to promptly detect any cyber-intrusions so as to respond / recover / contain the fall out. NBFCs are expected to be well prepared to face emerging cyber-threats such as ‘zero-day’ attacks, remote access threats, and targeted attacks. Among other things, NBFCs should take necessary preventive and corrective measures in addressing various types of cyber threats including, but not limited to, denial of service, distributed denial of services (DDoS), ransom-ware / crypto ware, destructive malware, business email frauds including spam, email phishing, spear phishing, whaling, vishing frauds, drive-by downloads, browser gateway fraud, ghost administrator exploits, identity frauds, memory update frauds, password related frauds, etc.

4.4.g Fraud analysis1

Suspicious transaction analysis, embezzlement, theft or suspected money-laundering, misappropriation of assets, manipulation of financial records etc. The regulatory requirement of reporting fraud to RBI should be system driven.

4.4.h Capacity and performance analysis19

Capacity and performance analysis of IT security systems.

4.4.i Incident reporting2

Incident reporting, their impact and steps taken for non-recurrence of such events in the future.

6.3 Backup and Recovery15

NBFCs shall consider the need to put in place necessary backup sites for their critical business systems and Data centers.

8.1 IT Systems15

IT Systems should be progressively scaled up as the size and complexity of NBFC's operations increases.

8.I Basic Security Aspects48

Basic security aspects such as physical/ logical access controls and well defined password policy.

8.II User Role13

A well-defined user role.

8.III Maker-Checker Concept1

A Maker-checker concept to reduce the risk of error and misuse and to ensure reliability of data/information.

8.IX Backup and Recovery13

Arrangement for backup of data with periodic testing.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.