RBI Cybersecurity Framework
The RBI Cybersecurity Framework establishes mandatory cybersecurity requirements for banks and financial institutions in India. Here is what it covers and how to operationalize compliance.
RBI Cybersecurity Framework Overview
The Reserve Bank of India (RBI) Cybersecurity Framework was introduced in 2016 and updated through subsequent circulars. It establishes mandatory cybersecurity requirements for scheduled commercial banks, payment system operators, NBFCs, and other RBI-regulated entities.
The framework is risk-based and tiered. Banks are categorized into Tier 1 through Tier 4 based on size, complexity, and digital footprint. Higher tiers face more rigorous requirements. The categorization determines the controls applicable to each institution.
The framework consolidates RBI guidance across multiple cybersecurity areas: governance, infrastructure security, application security, network security, customer security, third-party risk, incident response, and business continuity. Compliance is monitored through RBI inspections and self-assessment reporting.
While targeted at financial institutions, the framework's risk-based approach and control set provide useful reference for any India-operating organization handling sensitive financial data. Pair with the CERT-In incident reporting requirements for comprehensive Indian regulatory coverage.
Governance Requirements
The framework places strong emphasis on governance:
- Board-approved cyber security policy: Comprehensive policy covering all aspects of cyber security, reviewed annually
- Cyber Security Operations Centre (CSOC): 24/7 monitoring capability appropriate to the bank's tier
- Cyber Crisis Management Plan (CCMP): Documented response procedures for major cyber incidents
- Designated cyber security officer: Senior individual with defined responsibilities and reporting line to senior management
- IT Strategy Committee at board level: Provides strategic direction and oversight
- Information Security Committee at executive level: Operational oversight of security program
The governance structure must demonstrate sustained leadership attention to cybersecurity. Board minutes should reflect regular discussion of cyber risk, threat landscape, and program maturity.
For non-banking entities, similar governance structures (named CISO, board-level oversight, documented policy) align with most cybersecurity frameworks and are good practice regardless of regulatory mandate.
Major Control Areas
The framework specifies controls across several domains:
- Infrastructure security: Network segmentation, firewalls, IDS/IPS, vulnerability management, patch management, change management
- Application security: Secure SDLC, code review, application security testing, web application firewalls
- Endpoint security: Anti-malware, endpoint detection and response, mobile device management, BYOD controls
- Identity and access management: MFA for privileged access, role-based access control, segregation of duties, privileged access management
- Customer security: Customer authentication, transaction monitoring, fraud detection, customer awareness
- Third-party security: Vendor risk assessment, contract security clauses, ongoing monitoring of third-party access
- Incident response: Detection, containment, eradication, recovery, post-incident review
- Business continuity: BCP/DRP testing, alternate site operations, recovery time and point objectives
Controls scale with bank tier. Tier 1 banks face the most rigorous expectations across all areas. Lower-tier banks have proportional but still substantial requirements.
Reporting Requirements
Banks have specific reporting obligations to RBI:
- Cyber security incident reports: Significant incidents must be reported to RBI typically within 2-6 hours of detection, depending on severity
- Self-assessment reports: Annual self-assessment of cyber security maturity submitted to RBI
- Phishing and fraud reports: Customer-impacting fraud incidents reported with specific timelines
- System audits: Independent system audits with results submitted to board and RBI on request
- Significant change reports: Major system changes that affect cyber security posture
The reporting timelines often interact with CERT-In's 6-hour rule and DPDPA breach notification. Banks operating digital channels typically face the most stringent timelines and must satisfy multiple regulators in parallel for the same incident.
Build the regulatory reporting matrix into your incident response runbook. For each incident category, identify all applicable regulators, timelines, and reporting formats.
Implementation Priorities
For banks implementing or maturing the RBI Cybersecurity Framework:
- Tier classification: Confirm your tier with RBI and identify specific requirements applicable to your tier
- Gap assessment: Compare current controls against framework requirements, prioritize gaps by risk
- CSOC establishment: Build or contract 24/7 monitoring capability appropriate to tier
- Cyber Crisis Management Plan: Document, train, and exercise the CCMP. Tabletop exercises at least annually.
- Incident response capability: Build operational IR with defined roles, runbooks, and external partners (forensics, legal, PR)
- Vendor risk program: Comprehensive third-party risk assessment with ongoing monitoring of high-risk vendors
- Customer security: Strong authentication, transaction monitoring, customer awareness campaigns
- Continuous improvement: Regular vulnerability assessments, penetration testing, and red team exercises
The framework is not a one-time compliance project. Cyber threat landscape evolves continuously. Banks must demonstrate ongoing program maturity through evidence of operations, exercises, and improvements.
Frequently Asked Questions
Related Articles
CERT-In 6-Hour Incident Reporting
CERT-In requires Indian organizations to report cyber incidents within 6 hours. Here is what counts as reportable, how to file, and how to operationalize the timeline.
India DPDPA 2023 Compliance Guide
India's DPDPA 2023 is the country's first comprehensive personal data protection law. Here is what data fiduciaries must do to comply, including consent, notice, and breach handling.
AI Governance Policy Template
An AI governance policy is the foundational document for any AI program. Here is a template covering scope, principles, lifecycle controls, and accountability.