FAQ on Cybersecurity and Cyber Resilience Framework (CSCRF)
Key Highlights
Last date not announced- Total Vacancies
- See notification
- Last Date to Apply
- Not announced
- Application Fee
- ₹22 (Gen)
- Age Limit
- See notification
- Qualification
- See notification
- Pay Scale
- Small- size REs Self- certification REs 1. Amount of collateral/ assets with Clearing Corporations (CCs) N.A. More than Rs. 1000 Crores More than Rs. 10 Crores and less than Rs. 1000 Crores Rs. 10 Crores and below 6.2. Further, in case trading member/ RE is engaged in Clientele as well as Proprietary Trading, such brokers sha
Important Links
Links open on the official portal (sebi.gov.in).
Important Dates
- Notification date
Dates are as stated in the official notification. Extensions are published by the recruiting authority — verify on the official website before the closing date.
Post-Wise Vacancy Details
| Post Name | Vacancies |
|---|---|
| Outsourcing of activities by Stock Exchanges and Clearing Corporations | — |
| Outsourcing by Depositories | — |
| Guidelines on Outsourcing of Activities by Intermediaries | — |
Swipe the table sideways to see every column.
Application Fee
- General / UR
- ₹22
feeds, commercial providers, and industry peers to analyse threat intelligence relevant to their specific operational environment. Page 22 of 23 DC-DR Drills 68. Are scenario-based cybersecurity drills mandated in CSCRF same as Red/Blue teaming, or do they serve a different purpose? Answer: Please refer CSCRF 'Governance: Risk Management: standard 3' with their corresponding guidelines. While both Scenario-based Cybersecurity drills and Red/ blue teaming are integral to REs' security posture, they serve different purposes. Scenario-based cybersecurity drills assess REs' incident response and…
Fees are paid on the official application portal. Payment gateway charges may apply.
Selection Process
- 1Norms'. Page 12 of 23 Cyber Capability Index (CCI)
- 2CSCRF mandates MIIs and Qualified REs to develop automated tool and suitable dashboards for submitting automated compliance. What is the significance for this requirement? Answer: CSCRF has mentioned that MIIs and Qualified REs shall build an automated tool and suitable dashboard (preferably integrated with log aggregator) for submitting compliance. Automated dashboard integrated with log…
- 3How does the Cyber Capability Index (CCI) assessment to be conducted by MIIs and Qualified REs? Answer: MIIs shall conduct third-party assessment of their cyber resilience using CCI on a half-yearly basis. Qualified REs shall do self-assessment of their cyber resilience using CCI on a yearly basis. Please refer Standard 4 of 'Governance: Oversight (GV.OV)', corresponding guidelines, and…
- 4How do decimal values handled in CCI score or SOC efficacy? How should REs calculate score if an undefined value is obtained during calculation? Answer: Score can be taken in decimal value up to two decimal places. Further, if an undefined value is obtained during any calculation, then the maximum or minimum (depending on parameter and corresponding formula) marks of that particular category…
- 5In parameter 14 of CCI (Table 27), the formula is (Number of individuals' screened/total number of individuals having access to organization's information and information systems) ×100. Here, suppose if both the parameters are zero (0), then zero marks shall be awarded for this parameter.
- 6In parameter 2 of CCI (Table 27), the formula is (Number of vulnerabilities mitigated/ Number of vulnerabilities identified)×100. Here, suppose if both the parameters are zero (0), then
Notification Details
Frequently Asked Questions (FAQs) on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI REs and Framework for Adoption of Cloud Services by SEBI REs
1. Securities and Exchange Board of India (SEBI) has issued 'Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)' vide circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024. The key objective of CSCRF is to address evolving cyber threats, to align with the industry standards, to encourage efficient audits, and to ensure compliance by SEBI REs.
2. In light of the queries and suggestions received and consultation held with REs, Frequently Asked Questions (FAQs) have been prepared on CSCRF and Framework for Adoption of Cloud Services by SEBI REs.
3. The objective of the FAQs is to provide better clarity on several concepts related to CSCRF. For ease of reference, these FAQs are categorised into subjects under following heads: 3.1. Governance and CISO related guidelines 3.2. Thresholds for REs' categorization 3.3. Asset Inventory and Classification of Critical/ Non-critical systems 3.4. VAPT and Patch Management 3.5. Cyber Audit and Timelines 3.6. Cyber Capability Index (CCI) 3.7. Software Bill of Materials (SBOM) 3.8. Outsourcing related guidelines 3.9. Cloud Service Providers (CSPs) and Hosted Services 3.10. COTS product testing 3.11. Log Management, Data Security, and other Protect guidelines
3.12. ISO 27001 certification 3.13. Security Operations Centre (SOC) and Market-SOC (M-SOC) 3.14. Threat Intelligence 3.15. DC-DR Drills 3.16. Response and Recovery 3.17. Classification and Handling of Cybersecurity Incidents
4. These FAQs are in the nature of providing guidance on the Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs), and any explanation/ clarification provided herein should neither be regarded as an interpretation of CSCRF nor be treated as a binding opinion/ decision of the Securities and Exchange Board of India. Different facts or conditions may entail different interpretations. For full particulars of the CSCRF governing cybersecurity and cyber resilience, please refer to actual text of the Acts/ Regulations/ Circulars appearing under the legal framework section on the SEBI website.
This is an extract. Download the official notification PDF for the complete text.
Frequently Asked Questions
What is the application fee for FAQ on Cybersecurity and Cyber Resilience Framework (CSCRF)?+
The application fee is ₹22 for general candidates. Fees are paid on the official application portal.