×
 

SEBI Proposes Extending Cyber Security Framework Of MIIs To Arms

SEBI proposes wider cyber security coverage for MII arms.

Markets regulator Securities and Exchange Board of India (Sebi) has proposed extending the Information Technology (IT) and cyber security framework applicable to Market Infrastructure Institutions (MIIs) to their subsidiaries. The proposal aims to strengthen regulatory oversight as stock exchanges, depositories and clearing corporations increasingly expand their operations through subsidiary entities.

Sebi noted that while MIIs are directly governed by the regulator and required to comply with its IT and cyber security frameworks, the applicability and regulatory jurisdiction of these requirements over their subsidiaries are not explicitly defined. The regulator said greater clarity is needed, particularly where subsidiaries perform activities connected to the functions of their parent MIIs.

The proposal comes against the possibility of MIIs using their subsidiaries to undertake certain activities, with such entities potentially operating in close coordination with the parent institution. In some cases, subsidiaries may also rely on shared technology infrastructure, applications, market data or other critical IT resources. Sebi said extending the framework would help ensure that regulatory requirements keep pace with the changing structure of market institutions.

Also Read: NSE IPO to Raise ₹22,569 Crore, India's Largest Exchange Opens Books

Under the proposed framework, a subsidiary would be required to follow the IT and cyber security requirements applicable to its parent MII if its activities directly contribute to the MII's domain. This would include situations where the subsidiary carries out an activity that the MII is required to undertake, handles data that the MII is required to manage, or shares IT infrastructure with the MII. Such subsidiaries would be subject to requirements covering cyber security, system audits, incident reporting and technology governance.

However, the framework would not automatically apply to a subsidiary that does not meet any of these three conditions. Sebi has also proposed an exemption mechanism for subsidiaries that only share IT infrastructure with their parent MII. In such cases, the MII would have to approach Sebi with details of compensatory controls implemented or proposed to ensure that the institution's IT and cyber resilience is not compromised. The proposal would also require the views of the MII's Standing Committee on Technology (SCOT) and its board.

Sebi has invited public comments on the proposed changes, with stakeholders allowed to submit their responses until October 2. The consultation is part of the regulator's efforts to address technology and cyber security risks arising from the evolving organisational structures of market infrastructure institutions and ensure appropriate safeguards across entities linked to them.

Also Read: Bitcoin Falls For Four Sessions As $76,000 Support Gains Attention

 
 
 
Gallery Gallery Videos Videos Share on WhatsApp Share