The Reserve Bank of India’s (RBI) directions transition cybersecurity from a standard compliance requirement into a board-driven enterprise risk management priority. The new framework replaces fragmented earlier circulars, this augmented singular framework establishes a comprehensive rulebook for commercial banks.
Key Governance & Operational Directives
-
Board Oversight & Accountability
The Board of Directors, the Risk Management Committee of the Board (RMCB), and the IT Strategy Committee (ITSC) hold direct responsibility for supervising technology strategy, cyber risk postures, and resilience outcomes.
-
Committee Composition: At least 50% of ITSC members must possess direct domain expertise in IT or information security, with at least one member holding technical field experience.
-
-
CISO Independence & Authority
-
Reporting Lines: To eliminate conflicts of interest, the Chief Information Security Officer (CISO) is explicitly prohibited from reporting to the Head of IT.
-
Governance Access: The CISO must maintain direct, unimpeded access to the Board and the ITSC, supported by adequate stature, resources, and authority.
-
-
Core Technical Controls
-
Baseline Safeguards: Mandatory implementation across access control (MFA, password protocols, least privilege), patch management, network isolation, robust cryptography, and Data Loss Prevention (DLP).
-
Continuous Monitoring: Operation of a 24×7 Cyber Security Operations Centre (CSOC) equipped with integrated threat intelligence, automated monitoring, detection, and strict escalation protocols.
-
Infrastructure Readiness: Proactive infrastructure upgrades, including full IPv6 readiness, rigorous asset inventory tracking, and formal data classification.
-
Incident Reporting Windows
Banks must report cyber incidents to the RBI via the DAKSH platform within six hours of detection, alongside concurrent proactive notification to CERT-In.
-
Third-Party & Supply Chain Risk
Mandatory pre-onboarding vetting for Application Service Providers (ASPs) and external vendors. Contracts must enforce strict security baselines, explicit audit rights, data protection parameters, incident notification SLAs, source code escrow, and clear exit strategies.
-
Continuous Assurance & Audits
-
Vulnerability Assessments: Conducted every six months.
-
Penetration Testing: Conducted annually for all critical internet-facing systems.
-
Disaster Recovery (DR) Drills: Conducted half-yearly.
Call for Action
Commercial bank leadership, risk officers, and IT strategy committees must immediately audit current governance structures, CISO reporting pathways, and vendor contracts to ensure alignment with these mandatory directives. While the framework applies directly to all commercial banks—including foreign bank branches operating under a "comply or explain" arrangement (excluding Small Finance Banks, Payments Banks, and Local Area Banks)—early gap assessments are critical to meet strict compliance deadlines and avoid regulatory escalation on the DAKSH platform.