{"what_this_is":"The machine-readable twin of the BankPulse page for one RBI rulebook. Same points, same dates, same paragraph references as the page a person reads. RBI's own wording is not reproduced here: each point names the RBI paragraph, the character offset into the text BankPulse read and the sha256 of that text, so the claim can be checked against RBI's own document.","schema_version":1,"release_id":"d653cdb0a5","generated_at":"2026-09-15T00:33:59.117975+00:00","id":"md13625","title":"Reserve Bank of India (Payments Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026","document_kind":"Directions","page":"https://bankpulse.ai/rule/md13625","status":"In force","importance":{"code":"MR","label":"MUST READ","weight":"Must read","why":"Binding RBI Directions naming this institution class in the title","layer":"bankpulse_inference"},"applies_to":{"shown":"Payments banks","class_code":"PB","from":"the document's own title","layer":"bankpulse_inference"},"dates":{"prid":"md13625","mode":"four_dates_v1","published":{"label":"Published","value":"Jul 31, 2026","stated":true,"why":"The day RBI put this document out."},"effective":{"label":"Starts to apply","value":"","stated":false,"why":"Not stated separately in this document. Read the rule itself before you assume a start date."},"transition":{"label":"Time to get ready","value":"","stated":false,"why":"Cannot be worked out until the day it starts to apply is known."},"deadline":{"label":"Last date to act","value":"","stated":false,"why":"No date to act by was found in this document. Other dates may sit inside single paragraphs."},"sources":{"published":"doc_date in data/highlights/md13625.json","effective":"none held","transition":"none held","deadline":"none held"}},"rbi_source":{"url":"https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13625","document_date":"Jul 31, 2026","read_by_bankpulse":"2026-08-21 16:25:01 UTC","text_sha256":"cd8124bc64b43298d85c8f475adb61f22c2b3530ea0f1648356017f384777d8c","word_count":12591,"standing_last_checked":"Standing checked on RBI’s Master Directions index, 15 September 2026, 5:58 am IST."},"counts":{"points_shown":130,"points_naming_an_rbi_paragraph":130,"points_stored":130,"actions":0,"amendments":0},"points":[{"n":1,"claim":"md13625-e1a4f741","page_group":"Chapter I. Preliminary","stored_section":"THE CORE IDEA","heading":"Cyber rules, payments banks","plain_english":"This paper sets the cyber and technology risk rules for payments banks.","rbi_paragraph":"Para 1","rbi_char_offset":4685,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p1","layer":"bankpulse"},{"n":2,"claim":"md13625-1840df20","page_group":"Chapter I. Preliminary","stored_section":"KEY DATES","heading":"Start date","plain_english":"These Directions took effect at once.","rbi_paragraph":"Para 2","rbi_char_offset":4863,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p2","layer":"bankpulse"},{"n":3,"claim":"md13625-afed2258","page_group":"Chapter I. Preliminary","stored_section":"WHO IT APPLIES TO","heading":"Who is covered","plain_english":"These Directions apply to every payments bank.","rbi_paragraph":"Para 3","rbi_char_offset":4928,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p3","layer":"bankpulse"},{"n":1,"claim":"md13625-95d1eb83","page_group":"Chapter II. Role of the Board","stored_section":"KEY DATES","heading":"Board sees them yearly","plain_english":"These plans and policies must go to the Board for review at least once a year.","rbi_paragraph":"Para 7","rbi_char_offset":13115,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p4","layer":"bankpulse"},{"n":2,"claim":"md13625-92469898","page_group":"Chapter II. Role of the Board","stored_section":"WHO SHOULD ACT","heading":"Set up the IT committee","plain_english":"The bank must set up a Board level IT Strategy Committee.","rbi_paragraph":"Para 8","rbi_char_offset":13216,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p5","layer":"bankpulse"},{"n":3,"claim":"md13625-ef6c14da","page_group":"Chapter II. Role of the Board","stored_section":"WHO SHOULD ACT","heading":"Audit committee oversees IS","plain_english":"The audit committee of the Board oversees the audit of information systems.","rbi_paragraph":"Para 9","rbi_char_offset":13437,"weight":"BACKGROUND","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p6","layer":"bankpulse"},{"n":1,"claim":"md13625-663c1eb5","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Seven years of skill","plain_english":"Real IT skill here means at least seven years of running or guiding IT work.","rbi_paragraph":"Para 16(2)","rbi_char_offset":15789,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p7","layer":"bankpulse"},{"n":2,"claim":"md13625-8f2223ba","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"KEY DATES","heading":"Committee meets each quarter","plain_english":"The IT Strategy Committee must meet at least once every three months.","rbi_paragraph":"Para 17","rbi_char_offset":16232,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p8","layer":"bankpulse"},{"n":3,"claim":"md13625-b46e95dd","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"A steering committee too","plain_english":"A steering group of senior staff must also meet at least once every three months.","rbi_paragraph":"Para 20","rbi_char_offset":18656,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p9","layer":"bankpulse"},{"n":4,"claim":"md13625-a65aa6f9","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Keep the two apart","plain_english":"The security officer must not report to the head of IT and gets no business target.","rbi_paragraph":"Para 26","rbi_char_offset":21481,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p10","layer":"bankpulse"},{"n":5,"claim":"md13625-cbd1499b","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"KEY DATES","heading":"Quarterly cyber review","plain_english":"The security officer must place a cyber risk review before the Board every three months.","rbi_paragraph":"Para 27(7)","rbi_char_offset":23102,"weight":"MUST KNOW","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p11","layer":"bankpulse"},{"n":6,"claim":"md13625-d24cbf54","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"No unsupported software","plain_english":"The bank must not run outdated hardware or software that the maker no longer backs.","rbi_paragraph":"Para 36","rbi_char_offset":25569,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p12","layer":"bankpulse"},{"n":7,"claim":"md13625-d4d23143","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"IT risk sits inside","plain_english":"The wider risk policy must also test IT risk from time to time.","rbi_paragraph":"Para 12","rbi_char_offset":14392,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p13","layer":"bankpulse"},{"n":8,"claim":"md13625-97551602","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Have a security policy","plain_english":"The bank must have an information security policy that sets scope, owner and penalty.","rbi_paragraph":"Para 13","rbi_char_offset":14560,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p14","layer":"bankpulse"},{"n":9,"claim":"md13625-0c6faf2a","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"A separate cyber policy","plain_english":"The cyber security policy must be kept apart from the wider IT policy.","rbi_paragraph":"Para 14","rbi_char_offset":14879,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p15","layer":"bankpulse"},{"n":10,"claim":"md13625-4b270014","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Three directors at least","plain_english":"The IT Strategy Committee must have at least three directors as members.","rbi_paragraph":"Para 16(1)","rbi_char_offset":15519,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p16","layer":"bankpulse"},{"n":11,"claim":"md13625-f541883c","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Chair must be independent","plain_english":"The chair of that committee must be an independent director with real IT skill.","rbi_paragraph":"Para 16(2)","rbi_char_offset":15606,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p17","layer":"bankpulse"},{"n":12,"claim":"md13625-b67dfd4b","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Security committee under it","plain_english":"An information security committee must sit under the IT Strategy Committee.","rbi_paragraph":"Para 22","rbi_char_offset":19373,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p18","layer":"bankpulse"},{"n":13,"claim":"md13625-534923a3","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Risk side heads it","plain_english":"The head of that security committee must come from the risk side of the bank.","rbi_paragraph":"Para 22","rbi_char_offset":19682,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p19","layer":"bankpulse"},{"n":14,"claim":"md13625-f2d348fd","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Name a head of IT","plain_english":"The bank must name a senior officer with real IT skill as head of the IT work.","rbi_paragraph":"Para 23","rbi_char_offset":20323,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p20","layer":"bankpulse"},{"n":15,"claim":"md13625-a6288744","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Head of IT duties","plain_english":"The head of IT must keep projects in line with policy and set up the backup site.","rbi_paragraph":"Para 24","rbi_char_offset":20569,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p21","layer":"bankpulse"},{"n":16,"claim":"md13625-2bfd61be","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Name a security officer","plain_english":"A senior officer, best of general manager rank, must be named security officer.","rbi_paragraph":"Para 26","rbi_char_offset":21347,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p22","layer":"bankpulse"},{"n":17,"claim":"md13625-1b402444","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Staff and budget for security","plain_english":"The security office must be well staffed and its budget set by the threats seen.","rbi_paragraph":"Para 26(3)","rbi_char_offset":21774,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p23","layer":"bankpulse"},{"n":18,"claim":"md13625-d862f85e","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"KEY DATES","heading":"Review architecture yearly","plain_english":"The IT Strategy Committee must review the IT design at least once a year.","rbi_paragraph":"Para 32","rbi_char_offset":24610,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p24","layer":"bankpulse"},{"n":19,"claim":"md13625-f678451f","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Always invited","plain_english":"The security officer is a standing invitee to both the IT committees.","rbi_paragraph":"Para 27(3)","rbi_char_offset":22675,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p25","layer":"bankpulse"},{"n":20,"claim":"md13625-9b54bc26","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Reports to the top","plain_english":"The security officer reports to the executive director who looks after risk.","rbi_paragraph":"Para 27(6)","rbi_char_offset":22971,"weight":"BACKGROUND","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p26","layer":"bankpulse"},{"n":21,"claim":"md13625-6d0b23c6","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Plan the technology refresh","plain_english":"The bank must plan to replace hardware and software before support runs out.","rbi_paragraph":"Para 37","rbi_char_offset":25780,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p27","layer":"bankpulse"},{"n":1,"claim":"md13625-9eb98002","page_group":"Chapter IV. IT and Information Security Risk Management","stored_section":"KEY DATES","heading":"Risk committee reviews yearly","plain_english":"The risk committee must review and update the risk policy at least once a year.","rbi_paragraph":"Para 38","rbi_char_offset":26125,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p28","layer":"bankpulse"},{"n":2,"claim":"md13625-29284841","page_group":"Chapter IV. IT and Information Security Risk Management","stored_section":"KEY DATES","heading":"Security check each year","plain_english":"The bank must review its security set up and policies at least once a year.","rbi_paragraph":"Para 42","rbi_char_offset":27808,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p29","layer":"bankpulse"},{"n":3,"claim":"md13625-81083d4e","page_group":"Chapter IV. IT and Information Security Risk Management","stored_section":"WHAT CHANGES","heading":"Grade your own risk","plain_english":"The bank must grade its own risk as low, moderate, high or very high.","rbi_paragraph":"Para 44","rbi_char_offset":28360,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p30","layer":"bankpulse"},{"n":1,"claim":"md13625-60157381","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Go beyond the top ten","plain_english":"Application security testing must not stop at the OWASP top 10 list.","rbi_paragraph":"Para 84","rbi_char_offset":39330,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p31","layer":"bankpulse"},{"n":2,"claim":"md13625-53bdfee9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Put the code in escrow","plain_english":"Where the source code cannot be had, the bank must place it in escrow.","rbi_paragraph":"Para 89","rbi_char_offset":40664,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p32","layer":"bankpulse"},{"n":3,"claim":"md13625-077dd865","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"No admin rights","plain_english":"Staff must not hold admin rights on their own desktop or laptop.","rbi_paragraph":"Para 107","rbi_char_offset":46338,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p33","layer":"bankpulse"},{"n":4,"claim":"md13625-9cf6bcb3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Removable media is barred","plain_english":"As a rule, pen drives and like media are barred unless allowed for a set use.","rbi_paragraph":"Para 120","rbi_char_offset":49495,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p34","layer":"bankpulse"},{"n":5,"claim":"md13625-cd1dc5a1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"No manual data changes","plain_english":"Data moving between critical systems must not be changed by hand on the way.","rbi_paragraph":"Para 140","rbi_char_offset":60909,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p35","layer":"bankpulse"},{"n":6,"claim":"md13625-1f6daf64","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Six months, then a year","plain_english":"Critical systems need a scan every six months and an attack test every 12 months.","rbi_paragraph":"Para 150","rbi_char_offset":63334,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"Suppose a scan is run in January and the next in July, six months later. The attack test run in January is next due the following January, 12 months later.","anchor":"https://bankpulse.ai/rule/md13625#p36","layer":"bankpulse"},{"n":7,"claim":"md13625-01b33f88","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Report closure each quarter","plain_english":"The closing of test findings must go to both IT committees every three months.","rbi_paragraph":"Para 160","rbi_char_offset":66548,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p37","layer":"bankpulse"},{"n":8,"claim":"md13625-ec94e41f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Drill every six months","plain_english":"Recovery drills for critical systems must be held at least once every six months.","rbi_paragraph":"Para 164","rbi_char_offset":67586,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p38","layer":"bankpulse"},{"n":9,"claim":"md13625-ad0cad46","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Six hours to report","plain_english":"A cyber incident must be reported on the DAKSH platform within six hours of detection.","rbi_paragraph":"Para 181","rbi_char_offset":71210,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p39","layer":"bankpulse"},{"n":10,"claim":"md13625-d78188f6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Warn customers on passwords","plain_english":"The bank must teach customers never to share a password, a one time code or a PIN.","rbi_paragraph":"Para 206","rbi_char_offset":77494,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p40","layer":"bankpulse"},{"n":11,"claim":"md13625-2c0d9eab","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep an asset list","plain_english":"The bank must keep an up to date list of all its information assets.","rbi_paragraph":"Para 46","rbi_char_offset":29460,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p41","layer":"bankpulse"},{"n":12,"claim":"md13625-a5649021","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep a data dictionary","plain_english":"The bank must keep a data dictionary so that systems share one meaning of data.","rbi_paragraph":"Para 48","rbi_char_offset":29951,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p42","layer":"bankpulse"},{"n":13,"claim":"md13625-a5b37c28","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Stop data leaks","plain_english":"The bank must have a full plan to stop the loss or leak of sensitive data.","rbi_paragraph":"Para 50","rbi_char_offset":30504,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p43","layer":"bankpulse"},{"n":14,"claim":"md13625-4213e5eb","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Wipe a lost device","plain_english":"The bank must be able to lock or wipe a mobile or a laptop from far away.","rbi_paragraph":"Para 53","rbi_char_offset":31437,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p44","layer":"bankpulse"},{"n":15,"claim":"md13625-785596d0","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Data migration policy","plain_english":"The bank must have a data migration policy that keeps data whole and correct.","rbi_paragraph":"Para 54","rbi_char_offset":31580,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p45","layer":"bankpulse"},{"n":16,"claim":"md13625-ba80711a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"List the allowed software","plain_english":"The bank must keep one central list of software that is allowed and not allowed.","rbi_paragraph":"Para 55","rbi_char_offset":32034,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p46","layer":"bankpulse"},{"n":17,"claim":"md13625-8266b0f7","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Control what gets installed","plain_english":"The bank must control what software can be put on its systems and devices.","rbi_paragraph":"Para 56","rbi_char_offset":32237,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p47","layer":"bankpulse"},{"n":18,"claim":"md13625-6366a5cc","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch for new patches","plain_english":"The bank must watch patch notices from makers and CERT-In and apply them fast.","rbi_paragraph":"Para 57","rbi_char_offset":32651,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p48","layer":"bankpulse"},{"n":19,"claim":"md13625-059c4daf","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Guard the data centre","plain_english":"Physical controls must protect the data centre and the backup site from harm.","rbi_paragraph":"Para 59","rbi_char_offset":33588,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p49","layer":"bankpulse"},{"n":20,"claim":"md13625-02b4a4c4","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch heat and water","plain_english":"The bank must watch for breaks in heat, water, smoke, power and access alarms.","rbi_paragraph":"Para 60","rbi_char_offset":33959,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p50","layer":"bankpulse"},{"n":21,"claim":"md13625-f90b638f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep the sites apart","plain_english":"The data centre and the backup site must be far apart in place.","rbi_paragraph":"Para 61","rbi_char_offset":34172,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p51","layer":"bankpulse"},{"n":22,"claim":"md13625-251b468d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Check capacity each year","plain_english":"The bank must check how much IT capacity it needs at least once a year.","rbi_paragraph":"Para 64","rbi_char_offset":34663,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p52","layer":"bankpulse"},{"n":23,"claim":"md13625-83a463a6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Set a security baseline","plain_english":"The bank must set and apply a base security setting for every kind of device.","rbi_paragraph":"Para 65","rbi_char_offset":35021,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p53","layer":"bankpulse"},{"n":24,"claim":"md13625-6d7cd39c","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Review firewalls often","plain_english":"The bank must review firewalls, switches and security kit and their patch levels.","rbi_paragraph":"Para 66","rbi_char_offset":35382,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p54","layer":"bankpulse"},{"n":25,"claim":"md13625-d0a39855","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep a network map","plain_english":"The bank must keep an up to date map of its wired and wireless networks.","rbi_paragraph":"Para 68","rbi_char_offset":36123,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p55","layer":"bankpulse"},{"n":26,"claim":"md13625-1282663c","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"List every allowed device","plain_english":"The bank must keep one central list of the devices allowed on its network.","rbi_paragraph":"Para 69","rbi_char_offset":36300,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p56","layer":"bankpulse"},{"n":27,"claim":"md13625-1c409baa","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Secure the wireless","plain_english":"The bank must secure wireless networks, access points and client systems.","rbi_paragraph":"Para 71","rbi_char_offset":36721,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p57","layer":"bankpulse"},{"n":28,"claim":"md13625-85ee4136","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Block strange devices","plain_english":"The bank must spot devices that are not allowed on the network and block them.","rbi_paragraph":"Para 73","rbi_char_offset":37160,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p58","layer":"bankpulse"},{"n":29,"claim":"md13625-3a79f3c2","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Layer the boundary","plain_english":"Boundary defence must be layered, with firewalls, proxies and intrusion systems.","rbi_paragraph":"Para 76","rbi_char_offset":37578,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p59","layer":"bankpulse"},{"n":30,"claim":"md13625-c927983f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Support IPv6 traffic","plain_english":"Public facing systems of the bank must be able to carry IPv6 traffic.","rbi_paragraph":"Para 77","rbi_char_offset":37956,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p60","layer":"bankpulse"},{"n":31,"claim":"md13625-811125c9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Write secure code","plain_english":"The bank must use secure coding when it builds software on its own or with others.","rbi_paragraph":"Para 79","rbi_char_offset":38164,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p61","layer":"bankpulse"},{"n":32,"claim":"md13625-28a08a15","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep environments apart","plain_english":"The build, test and live systems must be kept apart from each other.","rbi_paragraph":"Para 81","rbi_char_offset":38657,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p62","layer":"bankpulse"},{"n":33,"claim":"md13625-3e102a48","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Vendors must support it","plain_english":"The bank must tie down software support from its vendors by formal agreement.","rbi_paragraph":"Para 88","rbi_char_offset":40417,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p63","layer":"bankpulse"},{"n":34,"claim":"md13625-75e13613","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Get the source code","plain_english":"The bank must get the source code for every critical application from the vendor.","rbi_paragraph":"Para 89","rbi_char_offset":40586,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p64","layer":"bankpulse"},{"n":35,"claim":"md13625-e38c2c3a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Written word from the vendor","plain_english":"The vendor must confirm in writing that the software carries no known flaw or malware.","rbi_paragraph":"Para 91","rbi_char_offset":41150,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p65","layer":"bankpulse"},{"n":36,"claim":"md13625-50424d0b","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Log every critical system","plain_english":"Every system that touches critical or sensitive data must keep an audit trail.","rbi_paragraph":"Para 92","rbi_char_offset":42218,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p66","layer":"bankpulse"},{"n":37,"claim":"md13625-687b2d84","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Trails must stand as proof","plain_english":"Audit trails must be full enough to serve as proof and to settle a dispute.","rbi_paragraph":"Para 94","rbi_char_offset":42706,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p67","layer":"bankpulse"},{"n":38,"claim":"md13625-a77541c3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch the audit trails","plain_english":"The bank must watch audit trails and system logs to find any attack or misuse.","rbi_paragraph":"Para 95","rbi_char_offset":43180,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p68","layer":"bankpulse"},{"n":39,"claim":"md13625-e0af47db","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Find the root cause","plain_english":"The bank must find the root cause of any incident and patch the weak point.","rbi_paragraph":"Para 101","rbi_char_offset":45059,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p69","layer":"bankpulse"},{"n":40,"claim":"md13625-c9dbca45","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch the privileged user","plain_english":"Staff with high system rights must be watched and all their work logged.","rbi_paragraph":"Para 104","rbi_char_offset":45734,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p70","layer":"bankpulse"},{"n":41,"claim":"md13625-bccb0892","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"One place to sign in","plain_english":"Sign in and rights must run from one central system with strong password rules.","rbi_paragraph":"Para 108","rbi_char_offset":46560,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p71","layer":"bankpulse"},{"n":42,"claim":"md13625-8bb7ef82","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Close dormant accounts","plain_english":"The bank must limit failed sign in tries and switch off accounts nobody uses.","rbi_paragraph":"Para 111","rbi_char_offset":47467,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p72","layer":"bankpulse"},{"n":43,"claim":"md13625-589d19fc","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Prove who the customer is","plain_english":"The bank must be able to prove who a customer is on every channel it runs.","rbi_paragraph":"Para 114","rbi_char_offset":48220,"weight":"DO IT","role":"Branch","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p73","layer":"bankpulse"},{"n":44,"claim":"md13625-38f20185","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Secure the mail system","plain_english":"The bank must guard its mail against spoofing, look alike names and bad files.","rbi_paragraph":"Para 116","rbi_char_offset":48640,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p74","layer":"bankpulse"},{"n":45,"claim":"md13625-f4199fd6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Use DMARC on email","plain_english":"The bank must put DMARC in place on its email names to stop spoofing.","rbi_paragraph":"Para 119","rbi_char_offset":49152,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p75","layer":"bankpulse"},{"n":46,"claim":"md13625-45c38255","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Scan media first","plain_english":"Removable media must be scanned for malware before read or write access is given.","rbi_paragraph":"Para 123","rbi_char_offset":50080,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p76","layer":"bankpulse"},{"n":47,"claim":"md13625-c604768b","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Right to audit the vendor","plain_english":"The vendor agreement must give the bank a right to audit and RBI a right to inspect.","rbi_paragraph":"Para 131","rbi_char_offset":51967,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p77","layer":"bankpulse"},{"n":48,"claim":"md13625-80288cf1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"RBI can see everything","plain_english":"RBI must be able to reach every information resource the bank uses.","rbi_paragraph":"Para 132","rbi_char_offset":52198,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p78","layer":"bankpulse"},{"n":49,"claim":"md13625-af8f6bf5","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Where the data may sit","plain_english":"The bank must follow the law on where systems sit and where data may travel.","rbi_paragraph":"Para 133","rbi_char_offset":52511,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p79","layer":"bankpulse"},{"n":50,"claim":"md13625-15dc1619","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Switch provider must comply","plain_english":"The ATM switch provider must meet the cyber controls the bank writes into the contract.","rbi_paragraph":"Para 135","rbi_char_offset":52973,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p80","layer":"bankpulse"},{"n":51,"claim":"md13625-c080f61a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Change default passwords","plain_english":"Default passwords on network devices and systems must be changed after they go in.","rbi_paragraph":"Para 137(1)","rbi_char_offset":54829,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p81","layer":"bankpulse"},{"n":52,"claim":"md13625-e766da80","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Provider needs its own centre","plain_english":"The ATM switch provider must set up its own cyber security operations centre.","rbi_paragraph":"Para 137(23)","rbi_char_offset":59510,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p82","layer":"bankpulse"},{"n":53,"claim":"md13625-255d255a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Card standards apply","plain_english":"The switch provider must meet the payment card industry data security standard.","rbi_paragraph":"Para 137(24)","rbi_char_offset":59913,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p83","layer":"bankpulse"},{"n":54,"claim":"md13625-e1e01400","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Use strong encryption","plain_english":"Key length, methods and protocols used to send and hold data must be strong.","rbi_paragraph":"Para 139","rbi_char_offset":60365,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p84","layer":"bankpulse"},{"n":55,"claim":"md13625-130f6356","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Run a security centre","plain_english":"The bank must set up a cyber security operations centre for a constant watch.","rbi_paragraph":"Para 142","rbi_char_offset":61422,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p85","layer":"bankpulse"},{"n":56,"claim":"md13625-a78b4662","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Whitelist internet sites","plain_english":"The bank must whitelist the internet sites and systems that staff may reach.","rbi_paragraph":"Para 145","rbi_char_offset":62376,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p86","layer":"bankpulse"},{"n":57,"claim":"md13625-76c141e6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Buy anti phishing help","plain_english":"The bank must buy a service that takes down fake sites and rogue apps.","rbi_paragraph":"Para 147","rbi_char_offset":62687,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p87","layer":"bankpulse"},{"n":58,"claim":"md13625-effed654","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Scan and attack tests","plain_english":"The bank must run scans and attack tests on all critical and internet facing systems.","rbi_paragraph":"Para 148","rbi_char_offset":62913,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p88","layer":"bankpulse"},{"n":59,"claim":"md13625-598ddf75","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Independent testers only","plain_english":"Scans and attack tests must be run by trained and independent security experts.","rbi_paragraph":"Para 154","rbi_char_offset":64582,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p89","layer":"bankpulse"},{"n":60,"claim":"md13625-17174880","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Follow the ISO standard","plain_english":"The continuity and recovery policy must follow best practice such as ISO 22301.","rbi_paragraph":"Para 162","rbi_char_offset":66988,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p90","layer":"bankpulse"},{"n":61,"claim":"md13625-fdfba237","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Run on the backup site","plain_english":"A recovery test must run the backup site as the main site for a full working day.","rbi_paragraph":"Para 166","rbi_char_offset":67987,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p91","layer":"bankpulse"},{"n":62,"claim":"md13625-fd42c647","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Test your backups","plain_english":"The bank must back data up and restore it now and then to prove it works.","rbi_paragraph":"Para 168","rbi_char_offset":68347,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p92","layer":"bankpulse"},{"n":63,"claim":"md13625-c120ed54","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Near zero data loss","plain_english":"The bank must aim for the least recovery time and near zero data loss.","rbi_paragraph":"Para 170","rbi_char_offset":68762,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p93","layer":"bankpulse"},{"n":64,"claim":"md13625-e6f9d9b3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Both sites must match","plain_english":"The settings and security patches at the main and backup sites must be the same.","rbi_paragraph":"Para 172","rbi_char_offset":69129,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p94","layer":"bankpulse"},{"n":65,"claim":"md13625-425e3cc7","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Have a response policy","plain_english":"The bank must have a written policy on how it answers and recovers from an incident.","rbi_paragraph":"Para 174","rbi_char_offset":69556,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p95","layer":"bankpulse"},{"n":66,"claim":"md13625-52689ea1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Train the incident staff","plain_english":"Staff who handle cyber incidents must be given special training.","rbi_paragraph":"Para 175","rbi_char_offset":70225,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p96","layer":"bankpulse"},{"n":67,"claim":"md13625-198edfe9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Plan for ransomware","plain_english":"The bank must write down how it answers ransomware, data wiping and denial of service.","rbi_paragraph":"Para 178","rbi_char_offset":70687,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p97","layer":"bankpulse"},{"n":68,"claim":"md13625-accb6333","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Shut the attack in","plain_english":"The bank must hold an attack in by shielding or cutting off the hit systems.","rbi_paragraph":"Para 179","rbi_char_offset":70809,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p98","layer":"bankpulse"},{"n":69,"claim":"md13625-b903fe0d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Tell CERT-In as well","plain_english":"The bank must also tell CERT-In about a cyber incident without being asked.","rbi_paragraph":"Para 181","rbi_char_offset":71392,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p99","layer":"bankpulse"},{"n":70,"claim":"md13625-1d6045b6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Share threat news","plain_english":"The bank must set up ways to gather and share threat news at home and abroad.","rbi_paragraph":"Para 185","rbi_char_offset":72246,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p100","layer":"bankpulse"},{"n":71,"claim":"md13625-262902ef","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Join the cyber drills","plain_english":"The bank must take part in cyber drills run by CERT-In and IDRBT.","rbi_paragraph":"Para 187","rbi_char_offset":72674,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p101","layer":"bankpulse"},{"n":72,"claim":"md13625-f5404564","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Write a crisis plan","plain_english":"The bank must write a cyber crisis management plan under the Board approved framework.","rbi_paragraph":"Para 191","rbi_char_offset":73588,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p102","layer":"bankpulse"},{"n":73,"claim":"md13625-06d168bf","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Four steps in a crisis","plain_english":"The crisis plan must cover four steps: detection, containment, response and recovery.","rbi_paragraph":"Para 192","rbi_char_offset":73724,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p103","layer":"bankpulse"},{"n":74,"claim":"md13625-b5bcf87f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Measure with real numbers","plain_english":"The bank must build measures such as patch delay, malware cover and training reach.","rbi_paragraph":"Para 193","rbi_char_offset":74619,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p104","layer":"bankpulse"},{"n":75,"claim":"md13625-b71482d9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Teach the staff","plain_english":"The bank must set out safe use rules for staff, vendors and partners.","rbi_paragraph":"Para 198","rbi_char_offset":75926,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p105","layer":"bankpulse"},{"n":76,"claim":"md13625-1a8dea84","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Train every new recruit","plain_english":"Cyber awareness training is a must for all new recruits.","rbi_paragraph":"Para 202","rbi_char_offset":76693,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p106","layer":"bankpulse"},{"n":77,"claim":"md13625-37de37af","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Board training each year","plain_english":"The Board and senior staff must be trained on IT and cyber risk once a year.","rbi_paragraph":"Para 203","rbi_char_offset":77049,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p107","layer":"bankpulse"},{"n":78,"claim":"md13625-0002385f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Take down fake sites","plain_english":"The bank must ask customers to report phishing mail and then act on it.","rbi_paragraph":"Para 205","rbi_char_offset":77342,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p108","layer":"bankpulse"},{"n":79,"claim":"md13625-61a9e358","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch risky transactions","plain_english":"The bank must watch transactions on a risk basis across every channel it runs.","rbi_paragraph":"Para 208","rbi_char_offset":77861,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p109","layer":"bankpulse"},{"n":80,"claim":"md13625-7ad9a84d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Alert on large payments","plain_english":"The bank must alert the customer about payments above a value the customer sets.","rbi_paragraph":"Para 209","rbi_char_offset":78019,"weight":"DO IT","role":"Branch","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p110","layer":"bankpulse"},{"n":81,"claim":"md13625-6e70e47e","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep forensics on standby","plain_english":"The bank must keep network forensic and denial of service help on standby.","rbi_paragraph":"Para 210","rbi_char_offset":78213,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p111","layer":"bankpulse"},{"n":82,"claim":"md13625-42e2db7a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"THE CORE IDEA","heading":"The data stays yours","plain_english":"The bank owns the duty to keep customer data safe, even at a vendor site.","rbi_paragraph":"Para 52","rbi_char_offset":30943,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p112","layer":"bankpulse"},{"n":83,"claim":"md13625-67129961","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"THE CORE IDEA","heading":"Access on business need","plain_english":"Access to information assets is allowed only where there is a real business need.","rbi_paragraph":"Para 103","rbi_char_offset":45627,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p113","layer":"bankpulse"},{"n":84,"claim":"md13625-9775b1c2","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Two factor for privilege","plain_english":"A second factor is needed to sign in for privileged users of critical systems.","rbi_paragraph":"Para 109","rbi_char_offset":46951,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p114","layer":"bankpulse"},{"n":85,"claim":"md13625-a535fe5c","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Rules for remote work","plain_english":"Remote work needs safe systems, a second sign in factor and a list of remote devices.","rbi_paragraph":"Para 113","rbi_char_offset":47631,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p115","layer":"bankpulse"},{"n":86,"claim":"md13625-da5a785d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Bank is the identity source","plain_english":"The bank stands as the identity source when a customer reaches a partner system.","rbi_paragraph":"Para 115","rbi_char_offset":48431,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p116","layer":"bankpulse"},{"n":87,"claim":"md13625-775c2fa3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"THE CORE IDEA","heading":"The bank stays answerable","plain_english":"The bank stays answerable for security risk in work it has given out.","rbi_paragraph":"Para 126","rbi_char_offset":51193,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p117","layer":"bankpulse"},{"n":88,"claim":"md13625-3167a119","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Check vendor staff","plain_english":"Background checks and secrecy agreements are needed for all vendor staff.","rbi_paragraph":"Para 134","rbi_char_offset":52794,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p118","layer":"bankpulse"},{"n":89,"claim":"md13625-9e799264","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Red team exercises","plain_english":"The bank may run red team drills that copy how a real attacker works.","rbi_paragraph":"Para 161","rbi_char_offset":66701,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p119","layer":"bankpulse"},{"n":1,"claim":"md13625-d60b7631","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHAT CHANGES","heading":"Framework for the centre","plain_english":"The bank must have a framework to set up and run its security operations centre.","rbi_paragraph":"Para 211","rbi_char_offset":78427,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p120","layer":"bankpulse"},{"n":2,"claim":"md13625-0bdbdd06","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHO SHOULD ACT","heading":"What the centre must do","plain_english":"The centre must watch, study and escalate incidents and work with outside agencies.","rbi_paragraph":"Para 216","rbi_char_offset":80366,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p121","layer":"bankpulse"},{"n":3,"claim":"md13625-ce5cad0b","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHO SHOULD ACT","heading":"Watch round the clock","plain_english":"The bank must work out the staff it needs to watch systems 24x7.","rbi_paragraph":"Para 222","rbi_char_offset":83636,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p122","layer":"bankpulse"},{"n":4,"claim":"md13625-be14ef6e","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHO SHOULD ACT","heading":"Level three analysts","plain_english":"Level three analysts need deep packet study, forensic skill and malware knowledge.","rbi_paragraph":"Para 220(3)","rbi_char_offset":83135,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p123","layer":"bankpulse"},{"n":1,"claim":"md13625-ab4d7822","page_group":"Chapter VII. Information Systems Audit","stored_section":"WHAT CHANGES","heading":"Have an IS audit policy","plain_english":"The bank must have an information systems audit policy.","rbi_paragraph":"Para 224","rbi_char_offset":84270,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p124","layer":"bankpulse"},{"n":2,"claim":"md13625-ce9657e0","page_group":"Chapter VII. Information Systems Audit","stored_section":"KEY DATES","heading":"Audit policy reviewed yearly","plain_english":"The audit committee must approve that policy and review it at least once a year.","rbi_paragraph":"Para 224","rbi_char_offset":84454,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p125","layer":"bankpulse"},{"n":3,"claim":"md13625-aa02ff51","page_group":"Chapter VII. Information Systems Audit","stored_section":"WHO SHOULD ACT","heading":"Separate IS audit function","plain_english":"The bank must have a separate information systems audit function with the right skill.","rbi_paragraph":"Para 226","rbi_char_offset":84706,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p126","layer":"bankpulse"},{"n":4,"claim":"md13625-ef5d403d","page_group":"Chapter VII. Information Systems Audit","stored_section":"WHAT CHANGES","heading":"Plan audits by risk","plain_english":"Audit planning must follow a risk based approach.","rbi_paragraph":"Para 227","rbi_char_offset":85131,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p127","layer":"bankpulse"},{"n":1,"claim":"md13625-11b3ef5f","page_group":"Chapter VIII. Repeal and Other Provisions","stored_section":"WHAT IT REPLACES","heading":"Old cyber rules go","plain_english":"These Directions repeal the earlier cyber framework and IT governance instructions.","rbi_paragraph":"Para 229","rbi_char_offset":85477,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13625#p128","layer":"bankpulse"},{"n":2,"claim":"md13625-ed77acc3","page_group":"Chapter VIII. Repeal and Other Provisions","stored_section":"WHAT IT REPLACES","heading":"Other laws still apply","plain_english":"These Directions add to other laws and rules and do not replace them.","rbi_paragraph":"Para 231","rbi_char_offset":86961,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"A bank follows these Directions and thinks the matter is closed. It is not. Any other laws, rules, regulations or directions in force still apply on top. Where another one asks for more, the bank does the more.","anchor":"https://bankpulse.ai/rule/md13625#p129","layer":"bankpulse"},{"n":3,"claim":"md13625-a449e126","page_group":"Chapter VIII. Repeal and Other Provisions","stored_section":"THE CORE IDEA","heading":"RBI has the last word","plain_english":"RBI may issue clarifications, and its reading of these Directions is final.","rbi_paragraph":"Para 232","rbi_char_offset":87409,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"Two banks read the same clause differently. Neither reading settles it. RBI may issue clarifications, and its interpretation of any provision is final and binding on all concerned entities.","anchor":"https://bankpulse.ai/rule/md13625#p130","layer":"bankpulse"}],"actions":[],"amendments":[],"layers":{"rbi_source":"Facts taken from RBI's own document.","bankpulse":"BankPulse's plain-English summary of RBI's document.","bankpulse_inference":"BankPulse's own inference, not stated by RBI."},"rbi_wording_not_included":"By design. BankPulse never republishes RBI's exact sentences. Use rbi_paragraph with rbi_source.url to read RBI's own words.","terms":"BankPulse's plain-English summaries are BankPulse's own work. The underlying regulation is the Reserve Bank of India's. Always check the RBI document named in rbi_source before acting."}