Markets regulator Securities and Change Board of India (Sebi) on Monday determined to introduce an IT Resilience Index (ITRI) to evaluate the functioning and resilience of data know-how programs of market infrastructure establishments (MIIs), together with inventory exchanges, depositories and clearing companies.
The transfer is aimed toward strengthening oversight of the resilience of IT programs and figuring out rising weaknesses at an early stage, in order that well timed corrective measures will be taken.
Below the framework, the ITRI can be computed utilizing a uniform set of 9 parameters, every carrying a selected weightage to make sure comparability throughout MIIs, Sebi mentioned in its round.
Availability and safety will carry the very best weightage of 20 per cent every, adopted by integrity, governance, reliability and monitoring, enterprise continuity, and modularity and suppleness at 10 per cent every.
Scalability and different elements, together with incident dealing with, will account for the remaining 5 per cent every.
MIIs have already carried out the beta model of the ITRI framework and can operationalise the framework, together with the EWS and real-time monitoring of service supply, by February 28, 2027.
The primary ITRI computation underneath the framework will cowl the half-year ended March 31, 2027.
MIIs will compute the index on a half-yearly foundation inside 60 days of the top of every half-year and submit a comparative evaluation of two consecutive half-years, together with corrective actions taken or proposed, to their Standing Committee on Expertise (SCOT) and governing boards.
Sebi mentioned the computation of ITRI can be system-driven to make sure that the method stays goal, non-discretionary and foolproof.
In case any parameter can’t be computed routinely and requires guide intervention, the MII will undertake guide information retrieval solely after discussing the exception with its SCOT.
The framework is designed as a self-operating mannequin underneath which MIIs will periodically compute the ITRI and supply their governing boards with an evaluation of the general well being of IT programs and areas requiring enchancment.
Sebi mentioned MIIs already repeatedly monitor the efficiency of processes and purposes, in addition to utilisation of system assets on the part stage, to allow early detection of doable efficiency points and system slowness.
Below the framework, MIIs will even construct programs offering steady visibility into service supply to market contributors. These programs will embody consolidated dashboards for monitoring system and utility efficiency, service supply and any deviations or anomalies.
MIIs will additional formulate SOPs to watch system availability and continuity of service supply to market contributors and flag any disruption or deviation.
The framework has been formulated to strengthen efficiency monitoring, guarantee well timed service supply to market contributors, establish rising weaknesses in IT programs at an early stage and facilitate well timed corrective motion, Sebi mentioned.
In a separate round, Sebi mentioned it has aligned its Incident Reporting Portal with the “Format for Incident Reporting Change (FIRE)” framework developed by the Monetary Stability Board (FSB) as a way to streamline the reporting of cyber incidents.
FIRE permits structured incident reporting by defining widespread data fields, standardised definitions, and constant classification of incident attributes, selling harmonisation throughout sectors or jurisdictions.
“The portal will facilitate reporting of incidents in phases to mirror the incident life cycle from preliminary reporting to intermediate updates and closing closure, whereas acknowledging that sure data will not be accessible on the time of preliminary reporting,” Sebi mentioned.
Sebi requested regulated entities (REs) to report cyber incidents by the Cyber Incident Reporting Portal of Sebi, which will be accessed by logging into https:iportal.sebi.gov.in.
