Entered in Prismet
Effective 1 Apr 2027
Effective 1 Apr 2027
Obligation changes
4
from RBI update
Material
2
require control change
Policies affected
3
revision required
Controls affected
6
3 with a gap
Actions open
3
3 owners
Population
—
No data available
What this change affects
Pulses follow recorded relationships from the event to the people who must act.
Obligation changes
| Obligation | Change | Requirement | Materiality |
|---|---|---|---|
| Audit-log retention and tamper protection | Changed | 180 days online, 5 years archived | Material |
| Payment API security and credential hygiene | Clarified | Rotate credentials on provider incidents | Material |
| Regulatory change impact assessment | New | Assess and record impact within 30 days | Moderate |
| Third-party incident reporting | Clarified | Notify RBI / CERT-In within 6 hours | Moderate |
Affected controls
| Control | Statement | Systems | Position |
|---|---|---|---|
| PAY-01 | Payment APIs secured with mTLS, signing and customer 2FA | PayGate Payment Gateway · Meridian Customer Portal | Operating · key rotation in progress |
| LOG-01 | Security events are centrally logged and monitored 24x7 | Amazon Web Services (ap-south-1) · Meridian Customer Portal | Operating |
| LOG-02 | Audit logs retained 180 days online and 5 years archived | Amazon Web Services (ap-south-1) · SAP S/4HANA | AI-drafted · pending approval (T-014) |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | PayGate Payment Gateway | Exception · F-RBI-03 |
| ACC-03 | Privileged access is just-in-time and reviewed | Amazon Web Services (ap-south-1) · Microsoft Entra ID | Remediation in progress · F-ITGC-02 |
| VUL-01 | Vulnerabilities are scanned and remediated within SLA | Amazon Web Services (ap-south-1) · GitHub Enterprise Cloud | Evidence pending (T-019) |
Actions and owners
| Action | Owner | Due | Status | Validation |
|---|---|---|---|---|
| T-017 Impact assessment: RBI circular on cyber resilience & digital payment security | Sanjay Kulkarni | 29 Oct 2026 | In Progress | Pending |
| T-014 Review and approve AI-drafted control LOG-02 (log retention) | Meera Joshi | 11 Oct 2026 | Open | Not planned |
| T-019 Connect AWS Inspector delegated admin account for VUL-01 evidence | Rahul Nair | 13 Oct 2026 | Open | Pending |
Review population
○ No data available
Policies
| Policy | Title | Status |
|---|---|---|
| pol-itgov | IT Governance Policy (RBI-aligned) | Revision required |
| pol-payments | Payments Security Policy | Revision required |
| pol-logging | Logging & Security Monitoring Standard | Revision required |