Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023)
Requires a senior-level executive — preferably in the rank of a General Manager or equivalent — to be designated as CISO, with no direct reporting line to the Head of IT and no business targets, appointed for a reasonable minimum term with an adequately staffed CISO's office. The CISO reports to the Executive Director overseeing risk and places a cyber-risk review before the Board, the Risk Management Committee or the IT Strategy Committee at least quarterly. Applies to commercial banks (including small finance banks, payments banks and foreign banks), NBFCs in the Top, Upper and Middle layers, credit information companies and the All India Financial Institutions.
IS Audit – RBI →