HomeNewsBusinessMarketsSEBI asks exchanges to conduct cyber audit twice a year

SEBI asks exchanges to conduct cyber audit twice a year

In addition to the cyber audits, the exchanges are also required to carry out periodic vulnerability assessment and penetration testing (VAPT).

May 20, 2022 / 18:23 IST
Story continues below Advertisement

Stock exchanges and all other market infrastructure institutions (MIIs) would be required to conduct cyber audits twice within a fiscal year, as per a circular issued by the Securities and Exchange Board of India (SEBI) on May 20.

The MIIs "are mandated to conduct comprehensive cyber audit at least two times in a financial year", the circular stated.

Story continues below Advertisement

Along with the cyber audit reports,  all MIIs are directed to submit a declaration from the managing director or chief executive officer "certifying compliance by the MII with all SEBI circulars and advisories related to cyber security issued from time to time", the market regulator added.

In addition to the cyber audits, the bourses are also required to carry out periodic vulnerability assessment and penetration testing (VAPT), which includes an inspection of all critical assets and infrastructure components like servers, networking systems, security devices, load balancers and other IT systems, SEBI said.