We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Banks

RBI Cyber Security Framework for Banks

RBI’s cyber security framework applies to every scheduled commercial bank, with expectations scaling to the bank’s size and digital footprint. The audit is annual, the reporting obligations are continuous, and supervisory attention has moved firmly from policy documents to whether controls demonstrably operate.

What RBI Cyber Security Framework requires of banks

  • A board-approved cyber security policy distinct from the general IT policy, with named accountability rather than a committee in the abstract.
  • A Security Operations Centre with evidence of alert triage, escalation and closure — coverage on paper is the most common finding.
  • Incident reporting to RBI within the prescribed window, and separately to CERT-In within six hours of detection. Conflating the two clocks is a recurring error.
  • Annual VAPT of internet-facing and critical internal systems, with retest evidence proving closure rather than a list of open findings.
  • Cyber crisis management plan that has actually been exercised, with a dated record of the exercise.

Evidence assessors actually ask for

Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.

  • Board minutes showing the cyber security policy was reviewed and decisions taken
  • SOC alert samples worked end to end — detection, triage, escalation, closure
  • VAPT report plus the retest confirming remediation
  • A dated restoration test against your stated RTO, not a backup success log
  • Access review records showing what was reviewed, by whom, and what was removed

Where banks usually come unstuck

  • Treating the six-hour CERT-In clock as starting at confirmation rather than detection.
  • Presenting a SOC dashboard when the auditor asked to watch a live alert being worked.
  • An untested crisis plan — a plan that has never been exercised is a document, not a capability.

Related

RBI PSS auditBanking sectorVAPT servicesCERT-In directions
Scope this engagement →What it costs
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Ready to discuss your RBI Cyber Security Framework requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →