INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group
In case a Regulated Entity does not report a cyber - security incident to SEBI (despite being aware of the incident) in the prescribed manner, SEBI may take appropriate regulatory action depending on the nature of the incident. Additionally, as per RBI’s Guidance Note, REs should maintain an inventory of incident response and recov - ery, internal and third-party resources to support its response and recovery capabilities. The scope of inci - dent management should capture the life cycle of an incident, typically including, but not limited to: • the classification of an incident’s severity based on predefined criteria (eg, expected time to return to business as usual), enabling proper prioritisa - tion and assignment of resources to respond to an incident; and • the incident response and recovery procedures, including their connection to the RE’s business continuity, disaster recovery and other associated management plans and procedures. Incident response and recovery procedures should be periodically reviewed, tested and updated by the REs. They should also identify and address the root causes of incidents to prevent or minimise serial recurrence. 3.4 Operational Resilience Enforcement There are no specific operation resilience enforcement obligations or provisions for critical ICT service provid - ers under the current cybersecurity regime. 3.5 International Data Transfers The DPDPA allows transfers of personal data outside India to countries or territories that are notified by the central government, subject to compliance with the Act’s data protection principles. The DPDPA estab - lishes a “negative list” approach to cross-border transfers, meaning personal data can be transferred outside India unless the central government specifi - cally restricts such transfers to certain countries or territories through official notification. The DPDPA also requires banks to map their cross- border data flows, maintain audit trails, and conduct regular risk assessments, especially for SDFs. Secure data handling is essential not only for meeting legal
requirements but also preserving business continuity and consumer trust. While the Act does not itself impose operational resil - ience obligations, regulated entities must align data transfer decisions with resilience considerations, particularly in regulated sectors where continuity and access are critical. Further, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the “SPDI Rules”), which are currently in force, permit the trans - fer of sensitive personal data or information to a third-party/individual outside of India, if the recipient ensures the same level of data protection adhered to by the transferor. 3.6 Threat-Led Penetration Testing The CSCRF for Regulated Entities prescribes that Vulnerability Assessment and Penetration Testing (VAPT) must be done to detect vulnerabilities in the IT environment for all critical systems, infrastructure components and other IT systems as defined in the framework. CSCRF specifies a comprehensive scope for VAPT. The scope of the IT environment taken for the VAPT should be made transparent to SEBI and should include all critical assets and infrastructure compo - nents including (not limited to) networking systems, security devices, servers, databases, applications, systems accessible through WAN, LAN as well as with public IPs, websites, etc. Testing Methodology The VAPT should provide in-depth evaluation of the security posture of the system through simulations of actual attacks on its systems and networks. The testing methodology should be adapted from the fol - lowing: • SEBI CSCRF; • NCIIPC; • CERT-In Rules; • The National Institute of Standards and Technology Special Publication 800-115; • Latest ISO27001;
201 CHAMBERS.COM
Powered by FlippingBook