Requirement · RBI-CSF-NBFC-Annex-1-2
RBI-CSF-NBFC Annex 1 §2 · Cyber security — SOC monitoring, vulnerability management, incident reporting (RBI Cyber Security Framework for NBFCs (IT Framework for the NBFC Sector))
Controls (5)
| Control | Name | Domain |
|---|---|---|
| ACC-03 | Privileged access is just-in-time and reviewed | Access Control |
| VUL-01 | Vulnerabilities are scanned and remediated within SLA | Security Operations |
| LOG-01 | Security events are centrally logged and monitored 24x7 | Logging & Monitoring |
| LOG-02 | Audit logs retained 180 days online and 5 years archived, tamper-protected | Logging & Monitoring |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | Third-Party Risk |