On August 20, 2024, the Securities Exchange Board of India (SEBI) introduced the Cyber Security and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) under section 11(1) of the SEBI Act. This framework sets forth standards and guidelines designed to enhance cyber resilience and ensure robust cyber security across SEBI-regulated entities (REs). DSCI commends SEBI for incorporating stakeholder feedback to create a framework that balances business needs with cyber security and resilience goals.
This document serves as a primer, outlining the key features and changes in the final version compared to the draft. It also summarizes the framework outlining the key features and takeaways of the CSCRF.