Requirement · RBI-CSF-NBFC-Annex-1-2

RBI-CSF-NBFC Annex 1 §2 · Cyber security — SOC monitoring, vulnerability management, incident reporting (RBI Cyber Security Framework for NBFCs (IT Framework for the NBFC Sector))

Controls (5)

ControlNameDomain
ACC-03Privileged access is just-in-time and reviewedAccess Control
VUL-01Vulnerabilities are scanned and remediated within SLASecurity Operations
LOG-01Security events are centrally logged and monitored 24x7Logging & Monitoring
LOG-02Audit logs retained 180 days online and 5 years archived, tamper-protectedLogging & Monitoring
VEN-03Supplier security incidents are assessed for impact and trackedThird-Party Risk