{"what_this_is":"The machine-readable twin of the BankPulse page for one RBI rulebook. Same points, same dates, same paragraph references as the page a person reads. RBI's own wording is not reproduced here: each point names the RBI paragraph, the character offset into the text BankPulse read and the sha256 of that text, so the claim can be checked against RBI's own document.","schema_version":1,"release_id":"d653cdb0a5","generated_at":"2026-09-15T00:33:59.117975+00:00","id":"md13597","title":"Reserve Bank of India (All India Financial Institutions – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026","document_kind":"Directions","page":"https://bankpulse.ai/rule/md13597","status":"In force","importance":{"code":"MR","label":"MUST READ","weight":"Must read","why":"Binding RBI Directions naming this institution class in the title","layer":"bankpulse_inference"},"applies_to":{"shown":"All India financial institutions","class_code":"AIFI","from":"the document's own title","layer":"bankpulse_inference"},"dates":{"prid":"md13597","mode":"four_dates_v1","published":{"label":"Published","value":"Jul 31, 2026","stated":true,"why":"The day RBI put this document out."},"effective":{"label":"Starts to apply","value":"","stated":false,"why":"Not stated separately in this document. Read the rule itself before you assume a start date."},"transition":{"label":"Time to get ready","value":"","stated":false,"why":"Cannot be worked out until the day it starts to apply is known."},"deadline":{"label":"Last date to act","value":"","stated":false,"why":"No date to act by was found in this document. Other dates may sit inside single paragraphs."},"sources":{"published":"doc_date in data/highlights/md13597.json","effective":"none held","transition":"none held","deadline":"none held"}},"rbi_source":{"url":"https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13597","document_date":"Jul 31, 2026","read_by_bankpulse":"2026-08-21 16:25:46 UTC","text_sha256":"b851b5d3e837f0c7b47bcc5e414f29dacd46e9fbd019cd179d9d505afddf696e","word_count":11515,"standing_last_checked":"Standing checked on RBI’s Master Directions index, 15 September 2026, 5:58 am IST."},"counts":{"points_shown":124,"points_naming_an_rbi_paragraph":124,"points_stored":124,"actions":0,"amendments":0},"points":[{"n":1,"claim":"md13597-509f7072","page_group":"Chapter I. Preliminary","stored_section":"THE CORE IDEA","heading":"Cyber and technology rules","plain_english":"This paper sets the cyber and technology risk rules for all India financial institutions.","rbi_paragraph":"Para 1","rbi_char_offset":4703,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p1","layer":"bankpulse"},{"n":2,"claim":"md13597-1840df20","page_group":"Chapter I. Preliminary","stored_section":"KEY DATES","heading":"Start date","plain_english":"These Directions took effect at once.","rbi_paragraph":"Para 2","rbi_char_offset":4899,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p2","layer":"bankpulse"},{"n":3,"claim":"md13597-37d98736","page_group":"Chapter I. Preliminary","stored_section":"WHO IT APPLIES TO","heading":"Who is covered","plain_english":"These Directions apply to every all India financial institution.","rbi_paragraph":"Para 3","rbi_char_offset":4964,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":["agriculture-loan"],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p3","layer":"bankpulse"},{"n":1,"claim":"md13597-95d1eb83","page_group":"Chapter II. Role of the Board","stored_section":"KEY DATES","heading":"Board sees them yearly","plain_english":"These plans and policies must go to the Board for review at least once a year.","rbi_paragraph":"Para 7","rbi_char_offset":13449,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p4","layer":"bankpulse"},{"n":2,"claim":"md13597-92469898","page_group":"Chapter II. Role of the Board","stored_section":"WHO SHOULD ACT","heading":"Set up the IT committee","plain_english":"The all India financial institution must set up a Board level IT Strategy Committee.","rbi_paragraph":"Para 8","rbi_char_offset":13550,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p5","layer":"bankpulse"},{"n":3,"claim":"md13597-393ab01f","page_group":"Chapter II. Role of the Board","stored_section":"WHO SHOULD ACT","heading":"Audit committee oversees IS","plain_english":"The audit committee of the Board oversees the audit of information systems.","rbi_paragraph":"Para 9","rbi_char_offset":13771,"weight":"BACKGROUND","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p6","layer":"bankpulse"},{"n":1,"claim":"md13597-663c1eb5","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Seven years of skill","plain_english":"Real IT skill here means at least seven years of running or guiding IT work.","rbi_paragraph":"Para 16(2)","rbi_char_offset":16124,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p7","layer":"bankpulse"},{"n":2,"claim":"md13597-8f2223ba","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"KEY DATES","heading":"Committee meets each quarter","plain_english":"The IT Strategy Committee must meet at least once every three months.","rbi_paragraph":"Para 17","rbi_char_offset":16564,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p8","layer":"bankpulse"},{"n":3,"claim":"md13597-b46e95dd","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"A steering committee too","plain_english":"A steering group of senior staff must also meet at least once every three months.","rbi_paragraph":"Para 20","rbi_char_offset":18988,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p9","layer":"bankpulse"},{"n":4,"claim":"md13597-a65aa6f9","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Keep the two apart","plain_english":"The security officer must not report to the head of IT and gets no business target.","rbi_paragraph":"Para 26","rbi_char_offset":21814,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p10","layer":"bankpulse"},{"n":5,"claim":"md13597-9bcf3fbf","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"KEY DATES","heading":"Quarterly cyber review","plain_english":"The security officer must place a cyber risk review before the Board every three months.","rbi_paragraph":"Para 27(7)","rbi_char_offset":23437,"weight":"MUST KNOW","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p11","layer":"bankpulse"},{"n":6,"claim":"md13597-d24cbf54","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"No unsupported software","plain_english":"The all India financial institution must not run outdated hardware or software that the maker no longer backs.","rbi_paragraph":"Para 36","rbi_char_offset":25904,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p12","layer":"bankpulse"},{"n":7,"claim":"md13597-d4d23143","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"IT risk sits inside","plain_english":"The wider risk policy must also test IT risk from time to time.","rbi_paragraph":"Para 12","rbi_char_offset":14726,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p13","layer":"bankpulse"},{"n":8,"claim":"md13597-97551602","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Have a security policy","plain_english":"The all India financial institution must have an information security policy that sets scope, owner and penalty.","rbi_paragraph":"Para 13","rbi_char_offset":14894,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p14","layer":"bankpulse"},{"n":9,"claim":"md13597-0c6faf2a","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"A separate cyber policy","plain_english":"The cyber security policy must be kept apart from the wider IT policy.","rbi_paragraph":"Para 14","rbi_char_offset":15213,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p15","layer":"bankpulse"},{"n":10,"claim":"md13597-4b270014","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Three directors at least","plain_english":"The IT Strategy Committee must have at least three directors as members.","rbi_paragraph":"Para 16(1)","rbi_char_offset":15854,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p16","layer":"bankpulse"},{"n":11,"claim":"md13597-bb3d932f","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Chair must be independent","plain_english":"The chair of that committee must be an independent director with real IT skill.","rbi_paragraph":"Para 16(2)","rbi_char_offset":15941,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p17","layer":"bankpulse"},{"n":12,"claim":"md13597-b67dfd4b","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Security committee under it","plain_english":"An information security committee must sit under the IT Strategy Committee.","rbi_paragraph":"Para 22","rbi_char_offset":19705,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p18","layer":"bankpulse"},{"n":13,"claim":"md13597-534923a3","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Risk side heads it","plain_english":"The head of that security committee must come from the risk side of the all India financial institution.","rbi_paragraph":"Para 22","rbi_char_offset":20015,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p19","layer":"bankpulse"},{"n":14,"claim":"md13597-93ec89c4","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Name a head of IT","plain_english":"The all India financial institution must name a senior officer with real IT skill as head of the IT work.","rbi_paragraph":"Para 23","rbi_char_offset":20656,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p20","layer":"bankpulse"},{"n":15,"claim":"md13597-06fe66bf","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Head of IT duties","plain_english":"The head of IT must keep projects in line with policy and set up the backup site.","rbi_paragraph":"Para 24","rbi_char_offset":20902,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p21","layer":"bankpulse"},{"n":16,"claim":"md13597-2bfd61be","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Name a security officer","plain_english":"A senior officer, best of general manager rank, must be named security officer.","rbi_paragraph":"Para 26","rbi_char_offset":21680,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p22","layer":"bankpulse"},{"n":17,"claim":"md13597-1b402444","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Staff and budget for security","plain_english":"The security office must be well staffed and its budget set by the threats seen.","rbi_paragraph":"Para 26(3)","rbi_char_offset":22107,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p23","layer":"bankpulse"},{"n":18,"claim":"md13597-f237f916","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"KEY DATES","heading":"Review architecture yearly","plain_english":"The IT Strategy Committee must review the IT design at least once a year.","rbi_paragraph":"Para 32","rbi_char_offset":24945,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p24","layer":"bankpulse"},{"n":19,"claim":"md13597-f678451f","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Always invited","plain_english":"The security officer is a standing invitee to both the IT committees.","rbi_paragraph":"Para 27(3)","rbi_char_offset":23010,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p25","layer":"bankpulse"},{"n":20,"claim":"md13597-9b54bc26","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Reports to the top","plain_english":"The security officer reports to the executive director who looks after risk.","rbi_paragraph":"Para 27(6)","rbi_char_offset":23306,"weight":"BACKGROUND","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p26","layer":"bankpulse"},{"n":21,"claim":"md13597-6d0b23c6","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Plan the technology refresh","plain_english":"The all India financial institution must plan to replace hardware and software before support runs out.","rbi_paragraph":"Para 37","rbi_char_offset":26115,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p27","layer":"bankpulse"},{"n":1,"claim":"md13597-9eb98002","page_group":"Chapter IV. IT and Information Security Risk Management","stored_section":"KEY DATES","heading":"Risk committee reviews yearly","plain_english":"The risk committee must review and update the risk policy at least once a year.","rbi_paragraph":"Para 38","rbi_char_offset":26460,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p28","layer":"bankpulse"},{"n":2,"claim":"md13597-29284841","page_group":"Chapter IV. IT and Information Security Risk Management","stored_section":"KEY DATES","heading":"Security check each year","plain_english":"The all India financial institution must review its security set up and policies at least once a year.","rbi_paragraph":"Para 42","rbi_char_offset":28143,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p29","layer":"bankpulse"},{"n":3,"claim":"md13597-81083d4e","page_group":"Chapter IV. IT and Information Security Risk Management","stored_section":"WHAT CHANGES","heading":"Grade your own risk","plain_english":"The all India financial institution must grade its own risk as low, moderate, high or very high.","rbi_paragraph":"Para 44","rbi_char_offset":28695,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p30","layer":"bankpulse"},{"n":1,"claim":"md13597-60157381","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Go beyond the top ten","plain_english":"Application security testing must not stop at the OWASP top 10 list.","rbi_paragraph":"Para 84","rbi_char_offset":39699,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p31","layer":"bankpulse"},{"n":2,"claim":"md13597-b57ca1d6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Put the code in escrow","plain_english":"Where the source code cannot be had, the all India financial institution must place it in escrow.","rbi_paragraph":"Para 89","rbi_char_offset":41033,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p32","layer":"bankpulse"},{"n":3,"claim":"md13597-077dd865","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"No admin rights","plain_english":"Staff must not hold admin rights on their own desktop or laptop.","rbi_paragraph":"Para 107","rbi_char_offset":46707,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p33","layer":"bankpulse"},{"n":4,"claim":"md13597-aaa77bc7","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Removable media is barred","plain_english":"As a rule, pen drives and like media are barred unless allowed for a set use.","rbi_paragraph":"Para 120","rbi_char_offset":49865,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p34","layer":"bankpulse"},{"n":5,"claim":"md13597-cd1dc5a1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"No manual data changes","plain_english":"Data moving between critical systems must not be changed by hand on the way.","rbi_paragraph":"Para 136","rbi_char_offset":53875,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p35","layer":"bankpulse"},{"n":6,"claim":"md13597-1f6daf64","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Six months, then a year","plain_english":"Critical systems need a scan every six months and an attack test every 12 months.","rbi_paragraph":"Para 146","rbi_char_offset":56336,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"Suppose a scan is run in January and the next in July, six months later. The attack test run in January is next due the following January, 12 months later.","anchor":"https://bankpulse.ai/rule/md13597#p36","layer":"bankpulse"},{"n":7,"claim":"md13597-01b33f88","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Report closure each quarter","plain_english":"The closing of test findings must go to both IT committees every three months.","rbi_paragraph":"Para 156","rbi_char_offset":59550,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p37","layer":"bankpulse"},{"n":8,"claim":"md13597-15a89718","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Drill every six months","plain_english":"Recovery drills for critical systems must be held at least once every six months.","rbi_paragraph":"Para 160","rbi_char_offset":60597,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p38","layer":"bankpulse"},{"n":9,"claim":"md13597-ad0cad46","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Six hours to report","plain_english":"A cyber incident must be reported on the DAKSH platform within six hours of detection.","rbi_paragraph":"Para 177","rbi_char_offset":64222,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p39","layer":"bankpulse"},{"n":10,"claim":"md13597-d78188f6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Warn customers on passwords","plain_english":"The all India financial institution must teach customers never to share a password, a one time code or a PIN.","rbi_paragraph":"Para 202","rbi_char_offset":70511,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p40","layer":"bankpulse"},{"n":11,"claim":"md13597-aa95a6a5","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep an asset list","plain_english":"The all India financial institution must keep an up to date list of all its information assets.","rbi_paragraph":"Para 46","rbi_char_offset":29791,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p41","layer":"bankpulse"},{"n":12,"claim":"md13597-a5649021","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep a data dictionary","plain_english":"The all India financial institution must keep a data dictionary so that systems share one meaning of data.","rbi_paragraph":"Para 48","rbi_char_offset":30311,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p42","layer":"bankpulse"},{"n":13,"claim":"md13597-a5b37c28","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Stop data leaks","plain_english":"The all India financial institution must have a full plan to stop the loss or leak of sensitive data.","rbi_paragraph":"Para 50","rbi_char_offset":30864,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p43","layer":"bankpulse"},{"n":14,"claim":"md13597-4213e5eb","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Wipe a lost device","plain_english":"The all India financial institution must be able to lock or wipe a mobile or a laptop from far away.","rbi_paragraph":"Para 53","rbi_char_offset":31797,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p44","layer":"bankpulse"},{"n":15,"claim":"md13597-785596d0","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Data migration policy","plain_english":"The all India financial institution must have a data migration policy that keeps data whole and correct.","rbi_paragraph":"Para 54","rbi_char_offset":31940,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p45","layer":"bankpulse"},{"n":16,"claim":"md13597-ba80711a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"List the allowed software","plain_english":"The all India financial institution must keep one central list of software that is allowed and not allowed.","rbi_paragraph":"Para 55","rbi_char_offset":32394,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p46","layer":"bankpulse"},{"n":17,"claim":"md13597-8266b0f7","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Control what gets installed","plain_english":"The all India financial institution must control what software can be put on its systems and devices.","rbi_paragraph":"Para 56","rbi_char_offset":32598,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p47","layer":"bankpulse"},{"n":18,"claim":"md13597-5a8bdfe1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch for new patches","plain_english":"The all India financial institution must watch patch notices from makers and CERT-In and apply them fast.","rbi_paragraph":"Para 57","rbi_char_offset":33012,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p48","layer":"bankpulse"},{"n":19,"claim":"md13597-059c4daf","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Guard the data centre","plain_english":"Physical controls must protect the data centre and the backup site from harm.","rbi_paragraph":"Para 59","rbi_char_offset":33949,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p49","layer":"bankpulse"},{"n":20,"claim":"md13597-02b4a4c4","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch heat and water","plain_english":"The all India financial institution must watch for breaks in heat, water, smoke, power and access alarms.","rbi_paragraph":"Para 60","rbi_char_offset":34320,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p50","layer":"bankpulse"},{"n":21,"claim":"md13597-f90b638f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep the sites apart","plain_english":"The data centre and the backup site must be far apart in place.","rbi_paragraph":"Para 61","rbi_char_offset":34533,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p51","layer":"bankpulse"},{"n":22,"claim":"md13597-251b468d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Check capacity each year","plain_english":"The all India financial institution must check how much IT capacity it needs at least once a year.","rbi_paragraph":"Para 64","rbi_char_offset":35024,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p52","layer":"bankpulse"},{"n":23,"claim":"md13597-83a463a6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Set a security baseline","plain_english":"The all India financial institution must set and apply a base security setting for every kind of device.","rbi_paragraph":"Para 65","rbi_char_offset":35382,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p53","layer":"bankpulse"},{"n":24,"claim":"md13597-81983d11","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Review firewalls often","plain_english":"The all India financial institution must review firewalls, switches and security kit and their patch levels.","rbi_paragraph":"Para 66","rbi_char_offset":35743,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p54","layer":"bankpulse"},{"n":25,"claim":"md13597-d0a39855","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep a network map","plain_english":"The all India financial institution must keep an up to date map of its wired and wireless networks.","rbi_paragraph":"Para 68","rbi_char_offset":36488,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p55","layer":"bankpulse"},{"n":26,"claim":"md13597-9b4cf08a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"List every allowed device","plain_english":"The all India financial institution must keep one central list of the devices allowed on its network.","rbi_paragraph":"Para 69","rbi_char_offset":36665,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p56","layer":"bankpulse"},{"n":27,"claim":"md13597-1c409baa","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Secure the wireless","plain_english":"The all India financial institution must secure wireless networks, access points and client systems.","rbi_paragraph":"Para 71","rbi_char_offset":37090,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p57","layer":"bankpulse"},{"n":28,"claim":"md13597-ceb272d9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Block strange devices","plain_english":"The all India financial institution must spot devices that are not allowed on the network and block them.","rbi_paragraph":"Para 73","rbi_char_offset":37529,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p58","layer":"bankpulse"},{"n":29,"claim":"md13597-3a79f3c2","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Layer the boundary","plain_english":"Boundary defence must be layered, with firewalls, proxies and intrusion systems.","rbi_paragraph":"Para 76","rbi_char_offset":37947,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p59","layer":"bankpulse"},{"n":30,"claim":"md13597-c927983f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Support IPv6 traffic","plain_english":"Public facing systems of the all India financial institution must be able to carry IPv6 traffic.","rbi_paragraph":"Para 77","rbi_char_offset":38325,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p60","layer":"bankpulse"},{"n":31,"claim":"md13597-811125c9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Write secure code","plain_english":"The all India financial institution must use secure coding when it builds software on its own or with others.","rbi_paragraph":"Para 79","rbi_char_offset":38533,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p61","layer":"bankpulse"},{"n":32,"claim":"md13597-28a08a15","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep environments apart","plain_english":"The build, test and live systems must be kept apart from each other.","rbi_paragraph":"Para 81","rbi_char_offset":39026,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p62","layer":"bankpulse"},{"n":33,"claim":"md13597-3e102a48","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Vendors must support it","plain_english":"The all India financial institution must tie down software support from its vendors by formal agreement.","rbi_paragraph":"Para 88","rbi_char_offset":40786,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p63","layer":"bankpulse"},{"n":34,"claim":"md13597-75e13613","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Get the source code","plain_english":"The all India financial institution must get the source code for every critical application from the vendor.","rbi_paragraph":"Para 89","rbi_char_offset":40955,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p64","layer":"bankpulse"},{"n":35,"claim":"md13597-e38c2c3a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Written word from the vendor","plain_english":"The vendor must confirm in writing that the software carries no known flaw or malware.","rbi_paragraph":"Para 91","rbi_char_offset":41519,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p65","layer":"bankpulse"},{"n":36,"claim":"md13597-50424d0b","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Log every critical system","plain_english":"Every system that touches critical or sensitive data must keep an audit trail.","rbi_paragraph":"Para 92","rbi_char_offset":42587,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p66","layer":"bankpulse"},{"n":37,"claim":"md13597-687b2d84","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Trails must stand as proof","plain_english":"Audit trails must be full enough to serve as proof and to settle a dispute.","rbi_paragraph":"Para 94","rbi_char_offset":43075,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p67","layer":"bankpulse"},{"n":38,"claim":"md13597-a77541c3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch the audit trails","plain_english":"The all India financial institution must watch audit trails and system logs to find any attack or misuse.","rbi_paragraph":"Para 95","rbi_char_offset":43549,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p68","layer":"bankpulse"},{"n":39,"claim":"md13597-e0af47db","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Find the root cause","plain_english":"The all India financial institution must find the root cause of any incident and patch the weak point.","rbi_paragraph":"Para 101","rbi_char_offset":45428,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p69","layer":"bankpulse"},{"n":40,"claim":"md13597-c9dbca45","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch the privileged user","plain_english":"Staff with high system rights must be watched and all their work logged.","rbi_paragraph":"Para 104","rbi_char_offset":46103,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p70","layer":"bankpulse"},{"n":41,"claim":"md13597-bccb0892","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"One place to sign in","plain_english":"Sign in and rights must run from one central system with strong password rules.","rbi_paragraph":"Para 108","rbi_char_offset":46929,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p71","layer":"bankpulse"},{"n":42,"claim":"md13597-8bb7ef82","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Close dormant accounts","plain_english":"The all India financial institution must limit failed sign in tries and switch off accounts nobody uses.","rbi_paragraph":"Para 111","rbi_char_offset":47837,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p72","layer":"bankpulse"},{"n":43,"claim":"md13597-7aa0b02a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Prove who the customer is","plain_english":"The all India financial institution must be able to prove who a customer is on every channel it runs.","rbi_paragraph":"Para 114","rbi_char_offset":48590,"weight":"DO IT","role":"Branch","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p73","layer":"bankpulse"},{"n":44,"claim":"md13597-38f20185","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Secure the mail system","plain_english":"The all India financial institution must guard its mail against spoofing, look alike names and bad files.","rbi_paragraph":"Para 116","rbi_char_offset":49010,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p74","layer":"bankpulse"},{"n":45,"claim":"md13597-f4199fd6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Use DMARC on email","plain_english":"The all India financial institution must put DMARC in place on its email names to stop spoofing.","rbi_paragraph":"Para 119","rbi_char_offset":49522,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p75","layer":"bankpulse"},{"n":46,"claim":"md13597-45c38255","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Scan media first","plain_english":"Removable media must be scanned for malware before read or write access is given.","rbi_paragraph":"Para 123","rbi_char_offset":50447,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p76","layer":"bankpulse"},{"n":47,"claim":"md13597-62dd442f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Right to audit the vendor","plain_english":"The vendor agreement must give the all India financial institution a right to audit and RBI a right to inspect.","rbi_paragraph":"Para 131","rbi_char_offset":52334,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p77","layer":"bankpulse"},{"n":48,"claim":"md13597-80288cf1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"RBI can see everything","plain_english":"RBI must be able to reach every information resource the all India financial institution uses.","rbi_paragraph":"Para 132","rbi_char_offset":52567,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p78","layer":"bankpulse"},{"n":49,"claim":"md13597-af8f6bf5","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Where the data may sit","plain_english":"The all India financial institution must follow the law on where systems sit and where data may travel.","rbi_paragraph":"Para 133","rbi_char_offset":52884,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p79","layer":"bankpulse"},{"n":50,"claim":"md13597-e1e01400","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Use strong encryption","plain_english":"Key length, methods and protocols used to send and hold data must be strong.","rbi_paragraph":"Para 135","rbi_char_offset":53331,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p80","layer":"bankpulse"},{"n":51,"claim":"md13597-a78b4662","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Whitelist internet sites","plain_english":"The all India financial institution must whitelist the internet sites and systems that staff may reach.","rbi_paragraph":"Para 141","rbi_char_offset":55377,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p81","layer":"bankpulse"},{"n":52,"claim":"md13597-d78e520e","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Buy anti phishing help","plain_english":"The all India financial institution must buy a service that takes down fake sites and rogue apps.","rbi_paragraph":"Para 143","rbi_char_offset":55688,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p82","layer":"bankpulse"},{"n":53,"claim":"md13597-effed654","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Scan and attack tests","plain_english":"The all India financial institution must run scans and attack tests on all critical and internet facing systems.","rbi_paragraph":"Para 144","rbi_char_offset":55914,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p83","layer":"bankpulse"},{"n":54,"claim":"md13597-598ddf75","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Independent testers only","plain_english":"Scans and attack tests must be run by trained and independent security experts.","rbi_paragraph":"Para 150","rbi_char_offset":57584,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p84","layer":"bankpulse"},{"n":55,"claim":"md13597-17174880","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Follow the ISO standard","plain_english":"The continuity and recovery policy must follow best practice such as ISO 22301.","rbi_paragraph":"Para 158","rbi_char_offset":59999,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p85","layer":"bankpulse"},{"n":56,"claim":"md13597-fdfba237","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Run on the backup site","plain_english":"A recovery test must run the backup site as the main site for a full working day.","rbi_paragraph":"Para 162","rbi_char_offset":60998,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p86","layer":"bankpulse"},{"n":57,"claim":"md13597-fd42c647","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Test your backups","plain_english":"The all India financial institution must back data up and restore it now and then to prove it works.","rbi_paragraph":"Para 164","rbi_char_offset":61358,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p87","layer":"bankpulse"},{"n":58,"claim":"md13597-fee3492e","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Near zero data loss","plain_english":"The all India financial institution must aim for the least recovery time and near zero data loss.","rbi_paragraph":"Para 166","rbi_char_offset":61773,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p88","layer":"bankpulse"},{"n":59,"claim":"md13597-e6f9d9b3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Both sites must match","plain_english":"The settings and security patches at the main and backup sites must be the same.","rbi_paragraph":"Para 168","rbi_char_offset":62140,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p89","layer":"bankpulse"},{"n":60,"claim":"md13597-425e3cc7","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Have a response policy","plain_english":"The all India financial institution must have a written policy on how it answers and recovers from an incident.","rbi_paragraph":"Para 170","rbi_char_offset":62567,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p90","layer":"bankpulse"},{"n":61,"claim":"md13597-52689ea1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Train the incident staff","plain_english":"Staff who handle cyber incidents must be given special training.","rbi_paragraph":"Para 171","rbi_char_offset":63236,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p91","layer":"bankpulse"},{"n":62,"claim":"md13597-198edfe9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Plan for ransomware","plain_english":"The all India financial institution must write down how it answers ransomware, data wiping and denial of service.","rbi_paragraph":"Para 174","rbi_char_offset":63699,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p92","layer":"bankpulse"},{"n":63,"claim":"md13597-accb6333","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Shut the attack in","plain_english":"The all India financial institution must hold an attack in by shielding or cutting off the hit systems.","rbi_paragraph":"Para 175","rbi_char_offset":63821,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p93","layer":"bankpulse"},{"n":64,"claim":"md13597-b903fe0d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Tell CERT-In as well","plain_english":"The all India financial institution must also tell CERT-In about a cyber incident without being asked.","rbi_paragraph":"Para 177","rbi_char_offset":64404,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p94","layer":"bankpulse"},{"n":65,"claim":"md13597-1d6045b6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Share threat news","plain_english":"The all India financial institution must set up ways to gather and share threat news at home and abroad.","rbi_paragraph":"Para 181","rbi_char_offset":65258,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p95","layer":"bankpulse"},{"n":66,"claim":"md13597-262902ef","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Join the cyber drills","plain_english":"The all India financial institution must take part in cyber drills run by CERT-In and IDRBT.","rbi_paragraph":"Para 183","rbi_char_offset":65686,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p96","layer":"bankpulse"},{"n":67,"claim":"md13597-f5404564","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Write a crisis plan","plain_english":"The all India financial institution must write a cyber crisis management plan under the Board approved framework.","rbi_paragraph":"Para 187","rbi_char_offset":66607,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p97","layer":"bankpulse"},{"n":68,"claim":"md13597-06d168bf","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Four steps in a crisis","plain_english":"The crisis plan must cover four steps: detection, containment, response and recovery.","rbi_paragraph":"Para 188","rbi_char_offset":66743,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p98","layer":"bankpulse"},{"n":69,"claim":"md13597-b5bcf87f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Measure with real numbers","plain_english":"The all India financial institution must build measures such as patch delay, malware cover and training reach.","rbi_paragraph":"Para 189","rbi_char_offset":67638,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p99","layer":"bankpulse"},{"n":70,"claim":"md13597-19c2bfce","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Teach the staff","plain_english":"The all India financial institution must set out safe use rules for staff, vendors and partners.","rbi_paragraph":"Para 194","rbi_char_offset":68944,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p100","layer":"bankpulse"},{"n":71,"claim":"md13597-1a8dea84","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Train every new recruit","plain_english":"Cyber awareness training is a must for all new recruits.","rbi_paragraph":"Para 198","rbi_char_offset":69710,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p101","layer":"bankpulse"},{"n":72,"claim":"md13597-37de37af","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Board training each year","plain_english":"The Board and senior staff must be trained on IT and cyber risk once a year.","rbi_paragraph":"Para 199","rbi_char_offset":70066,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p102","layer":"bankpulse"},{"n":73,"claim":"md13597-fb6010fa","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Take down fake sites","plain_english":"The all India financial institution must ask customers to report phishing mail and then act on it.","rbi_paragraph":"Para 201","rbi_char_offset":70359,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p103","layer":"bankpulse"},{"n":74,"claim":"md13597-61a9e358","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch risky transactions","plain_english":"The all India financial institution must watch transactions on a risk basis across every channel it runs.","rbi_paragraph":"Para 204","rbi_char_offset":70879,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p104","layer":"bankpulse"},{"n":75,"claim":"md13597-6e70e47e","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep forensics on standby","plain_english":"The all India financial institution must keep network forensic and denial of service help on standby.","rbi_paragraph":"Para 205","rbi_char_offset":71051,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p105","layer":"bankpulse"},{"n":76,"claim":"md13597-42e2db7a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"THE CORE IDEA","heading":"The data stays yours","plain_english":"The all India financial institution owns the duty to keep customer data safe, even at a vendor site.","rbi_paragraph":"Para 52","rbi_char_offset":31303,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p106","layer":"bankpulse"},{"n":77,"claim":"md13597-67129961","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"THE CORE IDEA","heading":"Access on business need","plain_english":"Access to information assets is allowed only where there is a real business need.","rbi_paragraph":"Para 103","rbi_char_offset":45996,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p107","layer":"bankpulse"},{"n":78,"claim":"md13597-9775b1c2","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Two factor for privilege","plain_english":"A second factor is needed to sign in for privileged users of critical systems.","rbi_paragraph":"Para 109","rbi_char_offset":47320,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p108","layer":"bankpulse"},{"n":79,"claim":"md13597-0696ff00","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Rules for remote work","plain_english":"Remote work needs safe systems, a second sign in factor and a list of remote devices.","rbi_paragraph":"Para 113","rbi_char_offset":48001,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p109","layer":"bankpulse"},{"n":80,"claim":"md13597-da5a785d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Bank is the identity source","plain_english":"The all India financial institution stands as the identity source when a customer reaches a partner system.","rbi_paragraph":"Para 115","rbi_char_offset":48801,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p110","layer":"bankpulse"},{"n":81,"claim":"md13597-775c2fa3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"THE CORE IDEA","heading":"The bank stays answerable","plain_english":"The all India financial institution stays answerable for security risk in work it has given out.","rbi_paragraph":"Para 126","rbi_char_offset":51559,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p111","layer":"bankpulse"},{"n":82,"claim":"md13597-3167a119","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Check vendor staff","plain_english":"Background checks and secrecy agreements are needed for all vendor staff.","rbi_paragraph":"Para 134","rbi_char_offset":53167,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p112","layer":"bankpulse"},{"n":83,"claim":"md13597-9e799264","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Red team exercises","plain_english":"The all India financial institution may run red team drills that copy how a real attacker works.","rbi_paragraph":"Para 157","rbi_char_offset":59703,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p113","layer":"bankpulse"},{"n":1,"claim":"md13597-d60b7631","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHAT CHANGES","heading":"Framework for the centre","plain_english":"The all India financial institution must have a framework to set up and run its security operations centre.","rbi_paragraph":"Para 206","rbi_char_offset":71265,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p114","layer":"bankpulse"},{"n":2,"claim":"md13597-0bdbdd06","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHO SHOULD ACT","heading":"What the centre must do","plain_english":"The centre must watch, study and escalate incidents and work with outside agencies.","rbi_paragraph":"Para 211","rbi_char_offset":73248,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p115","layer":"bankpulse"},{"n":3,"claim":"md13597-ce5cad0b","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHO SHOULD ACT","heading":"Watch round the clock","plain_english":"The all India financial institution must work out the staff it needs to watch systems 24x7.","rbi_paragraph":"Para 217","rbi_char_offset":76518,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p116","layer":"bankpulse"},{"n":4,"claim":"md13597-be14ef6e","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHO SHOULD ACT","heading":"Level three analysts","plain_english":"Level three analysts need deep packet study, forensic skill and malware knowledge.","rbi_paragraph":"Para 215(3)","rbi_char_offset":76017,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p117","layer":"bankpulse"},{"n":1,"claim":"md13597-ab4d7822","page_group":"Chapter VII. Information Systems Audit","stored_section":"WHAT CHANGES","heading":"Have an IS audit policy","plain_english":"The all India financial institution must have an information systems audit policy.","rbi_paragraph":"Para 219","rbi_char_offset":77152,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p118","layer":"bankpulse"},{"n":2,"claim":"md13597-ce9657e0","page_group":"Chapter VII. Information Systems Audit","stored_section":"KEY DATES","heading":"Audit policy reviewed yearly","plain_english":"The audit committee must approve that policy and review it at least once a year.","rbi_paragraph":"Para 219","rbi_char_offset":77336,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p119","layer":"bankpulse"},{"n":3,"claim":"md13597-aa02ff51","page_group":"Chapter VII. Information Systems Audit","stored_section":"WHO SHOULD ACT","heading":"Separate IS audit function","plain_english":"The all India financial institution must have a separate information systems audit function with the right skill.","rbi_paragraph":"Para 221","rbi_char_offset":77588,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p120","layer":"bankpulse"},{"n":4,"claim":"md13597-ef5d403d","page_group":"Chapter VII. Information Systems Audit","stored_section":"WHAT CHANGES","heading":"Plan audits by risk","plain_english":"Audit planning must follow a risk based approach.","rbi_paragraph":"Para 222","rbi_char_offset":78013,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p121","layer":"bankpulse"},{"n":1,"claim":"md13597-87d2d742","page_group":"Chapter VIII. Repeal and Other Provisions","stored_section":"WHAT IT REPLACES","heading":"Old cyber rules go","plain_english":"These Directions repeal the earlier cyber framework and IT governance instructions.","rbi_paragraph":"Para 224","rbi_char_offset":78359,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13597#p122","layer":"bankpulse"},{"n":2,"claim":"md13597-ed77acc3","page_group":"Chapter VIII. Repeal and Other Provisions","stored_section":"WHAT IT REPLACES","heading":"Other laws still apply","plain_english":"These Directions add to other laws and rules and do not replace them.","rbi_paragraph":"Para 226","rbi_char_offset":79861,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"A bank follows these Directions and thinks the matter is closed. It is not. Any other laws, rules, regulations or directions in force still apply on top. Where another one asks for more, the bank does the more.","anchor":"https://bankpulse.ai/rule/md13597#p123","layer":"bankpulse"},{"n":3,"claim":"md13597-a449e126","page_group":"Chapter VIII. Repeal and Other Provisions","stored_section":"THE CORE IDEA","heading":"RBI has the last word","plain_english":"RBI may issue clarifications, and its reading of these Directions is final.","rbi_paragraph":"Para 227","rbi_char_offset":80309,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"Two banks read the same clause differently. Neither reading settles it. RBI may issue clarifications, and its interpretation of any provision is final and binding on all concerned entities.","anchor":"https://bankpulse.ai/rule/md13597#p124","layer":"bankpulse"}],"actions":[],"amendments":[],"layers":{"rbi_source":"Facts taken from RBI's own document.","bankpulse":"BankPulse's plain-English summary of RBI's document.","bankpulse_inference":"BankPulse's own inference, not stated by RBI."},"rbi_wording_not_included":"By design. BankPulse never republishes RBI's exact sentences. Use rbi_paragraph with rbi_source.url to read RBI's own words.","terms":"BankPulse's plain-English summaries are BankPulse's own work. The underlying regulation is the Reserve Bank of India's. Always check the RBI document named in rbi_source before acting."}