Explorer

RBI Issues Comprehensive Directions On IT Governance In Banks, NBFCs

The key focus areas of IT governance will include strategic alignment, risk management, resource management, performance management and business continuity/ disaster recovery management

The RBI on Tuesday came out with a comprehensive guideline related to information technology (IT) governance and controls for banks and NBFCs.

The key focus areas of IT governance will include strategic alignment, risk management, resource management, performance management and business continuity/ disaster recovery management.

In this regard, the RBI has issued the final Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023. The directions will come into force from April 1, 2024, "REs (regulated entities) shall put in place a robust IT Service Management Framework for supporting their information systems and infrastructure to ensure the operational resilience of their entire IT environment," the latest directions said.

REs, it further said, should have a documented data migration policy specifying a systematic process for data migration, ensuring data integrity, completeness and consistency.

"The policy shall, inter alia, contain provisions pertaining to signoffs from business users and application owners at each stage of migration, maintenance of audit trails, etc," the RBI said.

It also said that every IT application which can access or affect critical or sensitive information, should have necessary audit and system logging capability and should provide audit trails.

On cryptographic controls, it said the key length, algorithms, cipher suites and applicable protocols used in transmission channels, processing of data and authentication purpose should be strong.

Also, in order to prevent unauthorised modification of data, REs should ensure that there is no manual intervention or manual modification in data while it is being transferred from one process to another or from one application to another, in respect of critical applications.

According to the directions, the risk management policy of the RE should include IT related risks, including the cyber security related risks, and the risk management committee of the board (RMCB) should periodically review and update the same at least on a yearly basis.

The central bank further said REs should analyse cyber incidents for their severity, impact and root cause. They should take measures, corrective and preventive, to mitigate the adverse impact of incidents on business operations, it added. 

This report has been published as part of an auto-generated syndicated wire feed. Except for the headline, the content has not been modified or edited by ABP LIVE.

Top Headlines

OPINION | GenZ Vs Millennials: Who's Driving Crypto Adoption In India 
OPINION | GenZ Vs Millennials: Who's Driving Crypto Adoption In India 
Can Dalal Street Repeat History? Why June Has Been A Strong Month For Nifty
Nifty Has Ended June Higher In 6 Of The Last 10 Years. Will 2026 Follow Suit?
US-Iran Tensions Drag Share Markets, Sensex 500 Points Down, Nifty Ends Below 23,400
US-Iran Tensions Drag Share Markets, Sensex 500 Points Down, Nifty Ends Below 23,400
Amul’s Rs 600 Crore Bengal Bet: World’s Biggest Curd Factory To Come Up In Howrah
World’s Largest Curd Plant Coming To Kolkata: Why Amul Is Betting Big On Bengal

Videos

CBSE Portal Update: Board Says Website Likely to Resume by 2 PM, Students Told to Wait
Twisha Sharma Case: CBI Reaches Giribala Singh House, Recreates Crime Scene in Ongoing Probe
Twisha Sharma Case: CBI Recreates Crime Scene With Dummy Body at Suspect Giribala Singh’s Home
CBSE Portal Delayed: Students Face Trouble as Website Remains Under Maintenance
Lucknow Tension: Pasi Fort Dispute Escalates as Protesters Confront MP RK Chaudhary

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget