RBI30 Jul 2026master-directionPrepared by Complied AI

Reserve Bank of India (Payments Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

RBI/DoS/2026-27/428 DoS.CO.CSITEG.22/31.01.015/2026-27 July 31, 2026 Reserve Bank of India (Payments Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 Table of Contents Chapter I - Preliminary A. Short Title and Commencement B. Applicability C. Definitions Chapter II - Role o…

Source details

Source
Reserve Bank of India
Type
master-direction
Published by source
30 Jul 2026
Coverage area
banking

Document text

Prepared for reading; wording retained from the source.

Verify official record

RBI/DoS/2026-27/428 DoS.CO.CSITEG.22/31.01.015/2026-27 July 31, 2026

Reserve Bank of India (Payments Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

Table of Contents

  • Chapter I - Preliminary
    • A. Short Title and Commencement
    • B. Applicability
    • C. Definitions
  • Chapter II - Role of the Board
    • A. Board Approved Policies
    • B. Board Level Committees
  • Chapter III – Information Technology Governance and Oversight
    • A. IT Governance Framework
    • B. Information Security Policy and Cybersecurity Policy
    • C. IT Strategy Committee of the Board
    • D. Senior Management and IT Steering Committee
    • E. Information Security Committee
    • F. Head of IT Function
    • G. Chief Information Security Officer
    • H. Information Technology Project Management
    • I. IT Architecture
    • J. IT Services Management
  • Chapter IV - IT and Information Security Risk Management
    • A. Periodic Review of IT related Risks
    • B. IT and Information Security Risk Management Framework
    • C. Risk Identification, Assessment, and Documentation
  • Chapter V - Baseline Cybersecurity and Resilience Requirements
    • A. Inventory Management of Information Assets
    • B. Data Leak Prevention Strategy
    • C. Data Migration Controls
    • D. Preventing Execution of Unauthorised Software
    • E. Physical and Environmental Controls
    • F. Capacity Management
    • G. Secure Configuration
    • H. Network Management and Security
    • I. Application Security Life Cycle
    • J. Maintenance, Monitoring, and Analysis of Audit Logs
    • K. Patch, Vulnerability and Change Management
    • L. User Access Control / Management
    • M. Controls on Teleworking
    • N. Authentication Framework for Customers
    • O. Secure Mail and Messaging Systems
    • P. Removable Media
    • Q. Third-Party Arrangements
    • R. Cryptographic Controls
    • S. Straight Through Processing
    • T. Continuous Surveillance
    • U. Advanced Real-time Threat Defence and Management
    • V. Anti-Phishing
    • W. Vulnerability Assessment and Penetration Test
    • X. Red Teaming Exercises
    • Y. Business Continuity and Disaster Recovery
    • Z. Cyber Incident Response and Recovery Management
    • AA. Metrics
    • BB. User / Employee / Management Awareness
    • CC. Customer Education and Awareness
    • DD. Risk based Transaction Monitoring
    • EE. Forensics
  • Chapter VI - Cyber Security Operations Centre
    • A. Governance
    • B. Capabilities
    • C. Staff Capabilities
  • Chapter VII - Information Systems Audit
  • Chapter VIII - Repeal and Other Provisions
    • A. Repeal and Saving
    • B. Application of Other Laws Not barred
    • C. Interpretations

In exercise of the powers conferred Section 27 and Section 35-A of the Banking Regulation Act, 1949, the Reserve Bank of India Act, 1934, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby issues Directions hereinafter specified.

Chapter I - Preliminary

A. Short Title and Commencement

  1. These Directions shall be called the Reserve Bank of India (Payments Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.
  2. These Directions shall come into force with immediate effect.

B. Applicability

  1. These Directions shall be applicable to Payments Banks (hereinafter collectively referred to as 'banks' and individually as a 'bank').

C. Definitions

  1. The following definitions are sourced from FSB Cyber Lexicon unless explicitly mentioned otherwise. In these Directions, unless the context states otherwise, the terms herein shall bear the meanings assigned to them below.

(1) ‘Audit Trail’ - A chronological record that reconstructs and examines the sequence of activities surrounding or leading to a specific operation, procedure, or event in a security-relevant transaction from inception to result. (Source: NIST SP 800-53r5 on Security and Privacy Controls for Information Systems and Organizations) (2) ‘Availability’ - Property of being accessible and usable on demand by an authorised entity. (3) ‘Confidentiality’ - Property that information is neither made available nor disclosed to unauthorised individuals, entities, processes, or systems. (4) ‘Cyber’ - Relating to, within, or through the medium of the interconnected information infrastructure of interactions among persons, processes, data, and information systems. (5) ‘Cyber Event’ - Any observable occurrence in an information system. Cyber events sometimes provide indication that a cyber incident is occurring. (6) ‘Cybersecurity’ - Preservation of confidentiality, integrity, and availability of information and / or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non-repudiation, and reliability can also be involved. (7) ‘Cyber Incident’ - A cyber event that adversely affects the cybersecurity of an information asset whether resulting from malicious activity or not. (Source: Cyber incident definition is adapted from FSB Cyber Lexicon. By the definition, it includes cybersecurity incidents as well as IT incidents.) (8) ‘Cyber Resilience’ - The ability of an organisation to continue to carry out its mission by anticipating and adapting to cyber threats and other relevant changes in the environment and by withstanding, containing, and rapidly recovering from cyber incidents. (9) ‘Cyber-attack’ - Malicious attempt(s) to exploit vulnerabilities through the cyber medium to damage, disrupt, or gain unauthorised access to assets. (10) ‘Cyber Threat’ - A circumstance with the potential to exploit one or more vulnerabilities that adversely affects cybersecurity. (11) ‘Data Dictionary’ - A description of data in business terms, including information about the data. It includes elements like data types, structure details, and security restrictions. (Source: ISACA glossary) (12) ‘De-militarized Zone’ or ‘DMZ’ - A perimeter network segment that is logically between internal and external networks. (Source: NIST SP 800-82 Rev. 2) (13) ‘Distributed Denial of Service (DDoS)’ - A denial of service that is carried out using numerous sources simultaneously. (14) ‘Digital Forensics’ - The process used to acquire, preserve, analyse, and report on evidence using scientific methods that are demonstrably reliable, accurate, and repeatable. (Source: adapted from NIST Cloud Computing Forensic Science Challenges) (15) ‘Framework’ - A framework is a structured set of strategies, policies, procedures, methods, and best practices that guides organisational activities, enables governance, and supports the achievement of defined objectives. (Source: adapted from ISACA glossary and ISO 22340:2024) (16) ‘Honeypot’ - A specially configured server, also known as a decoy server, designed to attract and monitor intruders in a manner so that their actions do not affect production systems. (Source: ISACA glossary) (17) ‘Indicators of Compromise (IOCs)’ - Identifying signs that a cyber incident may have occurred or may be currently occurring. (18) ‘Information Asset’ - Any piece of data, device, or other component of the environment that supports information-related activities. Information Assets include information system, data, hardware, and software. (Source: Information Asset definition is adapted from “Guidance on cyber resilience for financial market infrastructures” publication of Bank for International Settlements and International Organization of Securities Commissions of June 2016) (19) ‘Information Systems (IS)’ - Set of applications, services, information technology assets, or other information-handling components, which includes the operating environment and networks. (20) ‘Integrity’ - Property of accuracy and completeness. (21) ‘Information Technology (IT) Governance’ - The responsibility of executives and the board of directors; consists of the leadership, organisational structures, and processes that ensure that the enterprise’s IT sustains and extends the enterprise's strategies and objectives. (Source: ISACA glossary and COBIT) (22) ‘IT Risk’ - The business risk associated with the use, ownership, operation, involvement, influence, and adoption of IT within an enterprise. (Source: ISACA glossary) (23) ‘Malware’ - Software designed with malicious intent containing features or capabilities that can potentially cause harm directly or indirectly to entities or their information systems. (24) ‘Penetration Testing’ - A test methodology in which assessors typically working under specific constraints, attempt to circumvent or defeat the security features of an information system. (25) ‘Phishing’ - A digital form of social engineering that attempts to acquire private or confidential information by pretending to be a trustworthy entity in an electronic communication. (26) ‘Privileged User’ - A user who, by virtue of function, and / or role, has been allocated powers within an information system, which are significantly greater than those available to the majority of users. (Source: adapted from ISO/IEC 24775-2:2021) (27) ‘Recovery Point Objective’ - The point in time to which data must be recovered after an outage. (Source: NIST glossary) (28) ‘Recovery Time Objective’ - The overall length of time an information system’s components can be in the recovery phase before negatively impacting the organisation’s mission or mission / business processes. (Source: NIST glossary) (29) ‘Red Team’ - A group of people authorised and organised to emulate a potential adversary’s attack or exploitation capabilities against an enterprise’s security posture. The Red Team’s objective is to improve enterprise cybersecurity by demonstrating the impacts of successful attacks and by demonstrating what works for the defenders (i.e., the Blue Team) in an operational environment. (Source: NIST glossary) (30) ‘Red Teaming Exercise’ - An exercise, reflecting real-world conditions, that is conducted as a simulated adversarial attempt by a red team to compromise organisational missions and / or business processes to provide a comprehensive assessment of the security capability of the information system and organisation. (Source: adapted from NIST glossary) (31) ‘Vulnerability’ - A weakness, susceptibility, or flaw of an asset or control that can be exploited by one or more threats. (32) ‘Vulnerability Assessment’ - Systematic examination of an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures and confirm the adequacy of such measures after implementation.

Showing 1,447 of 12,307 words

Research the source law

Find the provision behind this update.

No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.

Browse source laws