PFRDA circular PFRDA/2024/14/ICS/01 · 08 Jan 2024
Official title
Information and Cyber Security Policy Guidelines - 2024 For Intermediaries / Regulated Entities
Summary
Check the official recordThe Pension Fund Regulatory and Development Authority (PFRDA) has issued comprehensive Information and Cyber Security Policy Guidelines for 2024 to strengthen the IT infrastructure and data protection of its regulated entities and intermediaries. These guidelines establish a structured framework for governance, risk identification, protection, detection, response, and recovery from cyber threats. Regulated entities are required to formulate a Board-approved policy, conduct regular security audits, and implement specific technical controls, including vulnerability assessments and penetration testing. Entities are classified into two categories, with Category II entities permitted to follow their principal regulator's guidelines if they certify compliance and adhere to PFRDA's incident reporting requirements. All entities must report specific cyber incidents to CERT-In and PFRDA within six hours of detection.
What you must do
Key dates
Who is affected
Thresholds
Exceptions
परिपत्र
परिपत्र संख्या: पीएफआरडीए/2024/14/आईसीएस/01
01 अगस्त, 2024
सेवा में,
पीएफआरडीए के सभी मध्यवर्ती / विनियमित संस्थाएं
महोदया / महोदय,
सूचना और साइबर सुरक्षा नीति दिशानिर्देश - 2024 पर मध्यवर्ती / विनियमित संस्थाओं के लिए परिपत्र
प्रौद्योगिकी में लगातार हो रहे संवर्धन और उभरते हुए खतरों के बीच, साइबर सुरक्षा उपायों के माध्यम से आईटी अवसंरचना और डेटा की सुरक्षा भी बहुत महत्वपूर्ण है। यह उम्मीद की जा रही है कि विनियमित संस्थाओं ने साइबर सुरक्षा मामलों पर रोक लगाने के लिए अतीत में उपाय किए होंगे, लेकिन अभिदाताओं के हितों की रक्षा करने और विकसित हो रहे स्थापत्य की सुरक्षा और उसकी सत्यनिष्ठा सुनिश्चित करने के लिए, प्राधिकरण द्वारा सूचना और साइबर सुरक्षा नीति दिशानिर्देश - 2024 को अनुलग्नक में प्रदान किया गया है। ये दिशानिर्देश, विनियमित संस्थाओं के लिए साइबर खतरों को प्रभावी ढंग से प्रबंधित करने, महत्वपूर्ण आस्तियों की रक्षा करने और डिजिटल युग में विश्वास और भरोसा बनाए रखने के लिए एक रोडमैप के रूप में काम करेंगे। ये दिशानिर्देश विनियमित संस्थाओं के लिए एक व्यापक मानदंड के रूप में भी कार्य करेंगे ताकि वे अपनी सूचना और संचार प्रौद्योगिकी (आईसीटी) अवसंरचना को साइबर खतरों से बचाने के लिए आवश्यक नियंत्रणों और प्रक्रियाओं को समझ सकें और उन्हें कार्यान्वित कर सकें।
यह परिपत्र, पेंशन निधि विनियामक और विकास प्राधिकरण अधिनियम की धारा 14 के अंतर्गत प्रदत्त शक्तियों का प्रयोग करते हुए जारी किया गया है।
ये दिशानिर्देश 01 अगस्त, 2024 से लागू होंगे।
(हस्ताक्षर) सचिन जोनेजा महाप्रबंधक सूचना और साइबर सुरक्षा विभाग
PENSION FUND REGULATORY AND DEVELOPMENT AUTHORITY
CIRCULAR
Circular No.: PFRDA/2024/14/ICS/01
01.08.2024
To
All Intermediaries / Regulated Entities of PFRDA
Madam/Sir,
Circular on Information & Cybersecurity Policy Guidelines- 2024 for Intermediaries/Regulated entities
With the rapid technological advancements and emerging threats, protection of IT infrastructure and data through cybersecurity measures is of considerable importance. While the regulated entities are expected to have taken measures in the past to prevent the cyber security issues, in order to protect the interest of the subscribers and ensure safety and integrity of the evolving architecture the Authority hereby lays down Information & Cybersecurity Policy guidelines - 2024 as per Annexure. These guidelines will serve as a roadmap for Regulated Entities to effectively manage cyber risks, protect critical assets and maintain trust and confidence in the digital age. The guidelines shall also act as a broad standard for the Regulated Entities to understand and implement essential controls and procedures to protect their Information & Communication Technology (ICT) infrastructure from cyber threats.
This circular is issued in exercise of powers conferred under section 14 of the Pension Fund Regulatory and Development Authority Act.
These guidelines shall come into effect from 01st August, 2024.
(Signature) Sachin Joneja General Manager Information & Cyber Security Department
ANNEXURE
PENSION FUND REGULATORY AND DEVELOPMENT AUTHORITY
Information and Cyber Security Policy Guidelines - 2024 For Intermediaries / Regulated Entities
Table of Contents
1. Introduction and scope
In today's interconnected digital landscape, the financial services sector stands as a prime target for cyber threats due to the vast amounts of sensitive data it handles, including personal and financial information. Cyber-attacks are increasing in frequency, sophistication and impact, with perpetrators continually refining their efforts to compromise systems, networks and information world-wide. A key driver of this trend is the increasing usage of technology by the financial services sector to improve customer service and operational efficiency.
The following emerging trends in technology and their extensive use in almost all spheres of financial services is creating opportunities and threats in the form of Cybersecurity risk to the business:
Objective and Purpose:
In the NPS architecture there is significant element of data storage, transmission and recordkeeping with Central Recordkeeping Agencies (CRA’s), PFMs, POPs, Custodian and Trustee bank and the safety and security of which is of primary concern to the regulator in order to ensure systemic protection. The continued safety and security of the systems, data and privacy of the information is of utmost importance to the regulator in light of the protection of subscriber’s interest.