NewsFree365
--°
Markets
1 views

Sebi proposes extending IT, cyber security framework of MIIs to their arms

The Securities and Exchange Board of India (Sebi) aims to enhance regulatory oversight by extending IT and cybersecurity frameworks of Market Infrastructure Institutions (MIIs) to their subsidiaries. Public comments are invited until…

Sebi proposes extending IT, cyber security framework of MIIs to their arms
Markets watchdog Sebi on Friday proposed extending the IT and cyber security framework of Market Infrastructure Institutions (MIIs) -- comprising stock exchanges, depositories, and clearing corporations -- to their subsidiaries to strengthen regulatory oversight.While MIIs are governed by Sebi and operate in compliance with its IT and cybersecurity frameworks, the applicability and regulatory jurisdiction of these framework are not explicitly defined over their subsidiaries.

The move comes even as Sebi highlighted that there could be a case for MIIs to take services of their subsidiaries to carry out certain activities.

These subsidiaries may need to operate in close coordination with the parent MII and might use shared technology infrastructure, applications, market data or other critical IT resources.

"As MIIs continue to diversify their business models through subsidiaries, extending the applicability of the framework would ensure that the regulatory framework remains aligned with the evolving market structure," Sebi said in its consultation paper.Under the proposal, the IT and cyber security framework applicable to the parent MII will also apply to any subsidiary undertaking activity that directly contributes to that MII's domain.

In other words, the subsidiary is carrying out an activity which the MII is supposed to do, handling data that the MII is supposed to handle or sharing infrastructure with MII.

Such subsidiaries will comply with all applicable requirements relating to cyber security, system audits, incident reporting and technology governance.

The IT and cyber security framework applicable to the parent MII will not apply to the subsidiary if the arm does not meet any of these three criteria, Sebi said.

If an MII believes its IT and cyber security framework should not be extended to a subsidiary that only meets the condition of sharing IT infrastructure with the MII, it must follow prescribed steps to seek an exemption.

Such MIIs may seek exemption from Sebi regarding not extending the IT and cyber framework to that subsidiary.

Such proposals must include details of compensatory controls put in place/ proposed to be put in place by MIIs to ensure that the cyber and IT resilience of MIIs is not affected, along with the views of SCOT (Standing Committee on Technology) and the board of the MIIs, the regulator said.

The

Economictimes Verified Source

Syndicated via official news feed

Explore all Markets stories

Syndicated feed content with full publisher credit.

Live Newsroom Broadcast48,500+ Active Readers

Breaking News Sent Directly To Your Phone

Get instant market movers, policy notifications, and verified alerts delivered straight to your WhatsApp and Telegram feeds before algorithms filter them.

Sub-Second Flash Alerts100% Privacy & Zero SpamFree Forever