[Image omitted. See the official document.]
CIRCULAR
IFSCA-CSD0MSC/13/2025-DCS
March 10, 2025
To,
All Regulated Entities in the International Financial Services Centres (IFSCs)
Dear Madam/Sir,
Subject: Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs
- As the IFSC continues to evolve as a global financial hub, the sophistication of cyber threats targeting financial entities is also expected to grow. In such an international jurisdiction, where institutions cater to a diverse global client base, maintaining robust cyber security becomes fundamental. The ability of financial entities to protect their IT systems from being compromised by threat actors—whether through fraudulent financial transactions, breach of sensitive data, or the disruption of critical IT infrastructure—directly impacts the trust placed in the jurisdiction.
Consequently, cyber security is not just a necessity but a foundational pillar for ensuring the stability, resilience, and credibility of the financial services offered within the GIFT IFSC. These Guidelines on cyber security and cyber resilience intend to lay down International Financial Services Centres Authority (IFSCA)’s broad expectations from its Regulated Entities (“REs”). For the purpose of these Guidelines, REs shall include any entity which is licensed, recognised, registered or authorised by IFSCA. The implementation of these Guidelines shall be undertaken in accordance with the principle of proportionality, after taking into due consideration:
- a. the scale and complexity of operations,
- b. the nature of the activity the entity is engaged in,
- c. its interconnectedness with the financial ecosystem and
- d. the corresponding cyber risks the entity is exposed to.
- The key components of the Guidelines are categorized into:
- I. Governance
- II. Cyber security and cyber resilience framework
- III. Third party risk management
- IV. Communication & awareness
- V. Audit
I. Governance
- The REs shall have adequate governance mechanisms, with a clear set of roles and responsibilities to manage cyber risk. The set of stakeholders involved in the governance of an RE’s cyber risk management mechanism shall collectively be referred to as the “Oversight Body” of the RE and may include one or more of the following:
- i. Governing Board, or
- ii. Senior management personnel which include the Managing Director (MD), Chief Executive Officer (CEO), Chief Information Security Officer (CISO), Chief Technology Officer (CTO), Principal officer, Compliance officer or
- iii. Committee(s) involving/ designated by any of the above for the purpose of technology or cyber risk management of the RE
-
The REs shall ensure that their Governing Board and the senior management possesses sufficient expertise and knowledge to effectively understand and manage cyber risk. The Governing Board and senior management shall set the tone at the highest levels and cultivate a strong culture of cyber risk management and awareness at all levels of staff within the entity.
-
The REs shall appoint a CISO or alternatively, designate a senior employee/ management personnel to
- a. assess, identify and reduce cyber security risks,
- b. respond to incidents, establish appropriate standards and controls, and
- c. direct the establishment and implementation of processes and procedures as approved by the Oversight Body of the RE
- The CISO or senior employee/ management personnel so designated shall henceforth be referred to as the “Designated Officer”.
II. Cyber Security and Cyber Resilience framework
- The REs shall formulate the Cyber Security and Cyber Resilience Framework to maintain the Confidentiality, Integrity and Availability of their IT assets. The said framework, inter alia, shall:
- i. aim to maintain and promote the RE’s ability to anticipate, withstand, contain, and recover from cyber-attacks.
- ii. take an integrated and comprehensive view of the potential cyber threats, including third party risks that the RE faces.
- iii. define the RE’s cyber risk appetite and cyber resilience objectives.
- iv. outline the RE’s people, process and technology requirements for managing cyber risks.
- v. establish the roles and responsibilities of the Oversight Body, the Designated Officer, the employees and other stakeholders, including clear communication lines to be adhered to, during a cyber incident.
- vi. be reviewed and updated periodically to ensure that the framework stays relevant.
-
The Oversight Body shall ensure that the aforementioned framework is in accordance with the RE’s overall risk management framework.
-
The REs shall formulate an Information Security (IS) Policy as part of their cyber security and cyber resilience framework with the following basic principles.
-
a) Identification and Classification of IT Assets
- i. The REs shall maintain a detailed inventory of IT assets, including both logical (data, software) and physical (hardware) components, including system configurations, their interconnections with internal and external systems, with distinct and clear identification of the assets.
- ii. The REs shall carry out a risk assessment of those assets and classify the assets based on their business criticality, sensitivity of data they hold, and potential impact on other systems if compromised.
- iii. The REs shall identify and classify their business functions and supporting processes based on their criticality to overall operations and potential impact on performance. This classification shall guide the prioritization of security measures across protective, detective, response, and recovery efforts, focusing on mitigating risks associated with the most critical functions and processes.
-
b) Protection
The REs shall implement appropriate security controls, aligned with international best practices and cyber security and cyber resilience standards like NIST, ISO 27000, etc, to minimize the likelihood and impact of cyber-attacks on critical business functions, IT assets, and data. These controls must be proportional to the RE’s threat landscape and risk appetite. These controls shall be selected after taking into account the potential threat of compromise of technology, people and processes.
This may, inter alia, include measures pertaining to hardening of devices, network security, data security, patch management, disposal of systems and any other policies that aid in protection of the RE’s IT assets.
-
c) Access Control
- i. The REs shall manage access rights to IT assets and their supporting systems on a ‘need-to-know’ basis, following the principle of ‘least privilege’ (i.e., prevent unjustified access to a large set of data) and principle of ‘segregation of duties’ (i.e., to prevent the allocation of combinations of access rights that may be used to circumvent controls).
- ii. The REs shall enforce authentication methods that are sufficiently robust to adequately and effectively ensure that access control policies and procedures are complied with.
-
d) Physical Security
The Confidentiality, Integrity and Availability of information can be impaired through physical access and damage or destruction to physical components. The REs need to ensure adequate physical security of their IT assets, using measures such as secure location of critical data, restricted access to data centers, server rooms etc.
-
e) Vulnerability Assessment and Penetration Testing (VAPT)
The REs shall conduct Vulnerability Assessment and Penetration Testing (VAPT) to detect vulnerabilities in the IT environment for all critical systems, infrastructure components and other IT systems. The VAPT shall be conducted at least once a year.
-
f) Recovery
The REs shall have recovery policies and procedures to maximise their ability to provide services on an ongoing basis and to limit losses in the event of severe business disruption.
-
g) Incident Management
The IS Policy of the REs shall clearly define the term “cyber incident”. The REs shall develop and implement processes for preventing, detecting, analysing and responding to cyber incidents. REs shall also establish mechanisms to fulfil the disclosure and reporting requirements, as specified by IFSCA, during and after a cyber incident.
-
h) Audit trail
The REs shall ensure that audit trail exists for IT assets, such that it:
- a. satisfies the entity’s business continuity and recovery needs,
- b. satisfies the entity’s regulatory and legal obligations,
- c. facilitates audit and serves as forensic evidence when required, and
- d. assists in dispute resolution.