{"what_this_is":"The machine-readable twin of the BankPulse page for one RBI rulebook. Same points, same dates, same paragraph references as the page a person reads. RBI's own wording is not reproduced here: each point names the RBI paragraph, the character offset into the text BankPulse read and the sha256 of that text, so the claim can be checked against RBI's own document.","schema_version":1,"release_id":"d653cdb0a5","generated_at":"2026-09-15T00:33:59.117975+00:00","id":"md13643","title":"Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026","document_kind":"Directions","page":"https://bankpulse.ai/rule/md13643","status":"In force","importance":{"code":"MR","label":"MUST READ","weight":"Must read","why":"Binding RBI Directions naming this institution class in the title","layer":"bankpulse_inference"},"applies_to":{"shown":"Commercial banks","class_code":"SCB","from":"the document's own title","layer":"bankpulse_inference"},"dates":{"prid":"md13643","mode":"four_dates_v1","published":{"label":"Published","value":"Jul 31, 2026","stated":true,"why":"The day RBI put this document out."},"effective":{"label":"Starts to apply","value":"","stated":false,"why":"Not stated separately in this document. Read the rule itself before you assume a start date."},"transition":{"label":"Time to get ready","value":"","stated":false,"why":"Cannot be worked out until the day it starts to apply is known."},"deadline":{"label":"Last date to act","value":"","stated":false,"why":"No date to act by was found in this document. Other dates may sit inside single paragraphs."},"sources":{"published":"doc_date in data/highlights/md13643.json","effective":"none held","transition":"none held","deadline":"none held"}},"rbi_source":{"url":"https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13643","document_date":"Jul 31, 2026","read_by_bankpulse":"2026-08-21 16:24:31 UTC","text_sha256":"7d1c7fb2dd87fb598d691460d50e24d8f901cb3ce78b722ba50c935761c9c98e","word_count":12990,"standing_last_checked":"Standing checked on RBI’s Master Directions index, 15 September 2026, 5:58 am IST."},"counts":{"points_shown":132,"points_naming_an_rbi_paragraph":132,"points_stored":132,"actions":0,"amendments":0},"points":[{"n":1,"claim":"md13643-9873c4a0","page_group":"Chapter I. Preliminary","stored_section":"THE CORE IDEA","heading":"Cyber rules for banks","plain_english":"This paper sets the cyber and technology risk rules for commercial banks.","rbi_paragraph":"Para 1","rbi_char_offset":4691,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p1","layer":"bankpulse"},{"n":2,"claim":"md13643-0e747d72","page_group":"Chapter I. Preliminary","stored_section":"KEY DATES","heading":"Start date","plain_english":"These Directions took effect at once.","rbi_paragraph":"Para 2","rbi_char_offset":4871,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"There is no gap here between issue and effect. The Directions come into effect immediately upon issuance. A bank cannot wait for a separate start date, because there is none.","anchor":"https://bankpulse.ai/rule/md13643#p2","layer":"bankpulse"},{"n":3,"claim":"md13643-c06c1ef6","page_group":"Chapter I. Preliminary","stored_section":"WHO IT APPLIES TO","heading":"Who is covered","plain_english":"These Directions apply to every commercial bank.","rbi_paragraph":"Para 3","rbi_char_offset":4941,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p3","layer":"bankpulse"},{"n":1,"claim":"md13643-95d1eb83","page_group":"Chapter II. Role of the Board","stored_section":"KEY DATES","heading":"Board sees them yearly","plain_english":"These plans and policies must go to the Board for review at least once a year.","rbi_paragraph":"Para 8","rbi_char_offset":15215,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p4","layer":"bankpulse"},{"n":2,"claim":"md13643-92469898","page_group":"Chapter II. Role of the Board","stored_section":"WHO SHOULD ACT","heading":"Set up the IT committee","plain_english":"The bank must set up a Board level IT Strategy Committee.","rbi_paragraph":"Para 9","rbi_char_offset":15316,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p5","layer":"bankpulse"},{"n":3,"claim":"md13643-ef6c14da","page_group":"Chapter II. Role of the Board","stored_section":"WHO SHOULD ACT","heading":"Audit committee oversees IS","plain_english":"The audit committee of the Board oversees the audit of information systems.","rbi_paragraph":"Para 10","rbi_char_offset":15533,"weight":"BACKGROUND","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p6","layer":"bankpulse"},{"n":1,"claim":"md13643-663c1eb5","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Seven years of skill","plain_english":"Real IT skill here means at least seven years of running or guiding IT work.","rbi_paragraph":"Para 17(2)","rbi_char_offset":18171,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p7","layer":"bankpulse"},{"n":2,"claim":"md13643-8f2223ba","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"KEY DATES","heading":"Committee meets each quarter","plain_english":"The IT Strategy Committee must meet at least once every three months.","rbi_paragraph":"Para 18","rbi_char_offset":18611,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p8","layer":"bankpulse"},{"n":3,"claim":"md13643-b46e95dd","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"A steering committee too","plain_english":"A steering group of senior staff must also meet at least once every three months.","rbi_paragraph":"Para 21","rbi_char_offset":21030,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p9","layer":"bankpulse"},{"n":4,"claim":"md13643-a65aa6f9","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Keep the two apart","plain_english":"The security officer must not report to the head of IT and gets no business target.","rbi_paragraph":"Para 27","rbi_char_offset":23855,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p10","layer":"bankpulse"},{"n":5,"claim":"md13643-cbd1499b","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"KEY DATES","heading":"Quarterly cyber review","plain_english":"The security officer must place a cyber risk review before the Board every three months.","rbi_paragraph":"Para 28(7)","rbi_char_offset":25476,"weight":"MUST KNOW","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p11","layer":"bankpulse"},{"n":6,"claim":"md13643-d24cbf54","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"No unsupported software","plain_english":"The bank must not run outdated hardware or software that the maker no longer backs.","rbi_paragraph":"Para 37","rbi_char_offset":27956,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p12","layer":"bankpulse"},{"n":7,"claim":"md13643-d4d23143","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"IT risk sits inside","plain_english":"The wider risk policy must also test IT risk from time to time.","rbi_paragraph":"Para 13","rbi_char_offset":16488,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p13","layer":"bankpulse"},{"n":8,"claim":"md13643-97551602","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Have a security policy","plain_english":"The bank must have an information security policy that sets scope, owner and penalty.","rbi_paragraph":"Para 14","rbi_char_offset":16656,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p14","layer":"bankpulse"},{"n":9,"claim":"md13643-0c6faf2a","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"A separate cyber policy","plain_english":"The cyber security policy must be kept apart from the wider IT policy.","rbi_paragraph":"Para 15","rbi_char_offset":16975,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p15","layer":"bankpulse"},{"n":10,"claim":"md13643-bfced4ce","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Three directors at least","plain_english":"The IT Strategy Committee must have at least three directors as members.","rbi_paragraph":"Para 17(1)","rbi_char_offset":17616,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p16","layer":"bankpulse"},{"n":11,"claim":"md13643-bb3d932f","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Chair must be independent","plain_english":"The chair of that committee must be an independent director with real IT skill.","rbi_paragraph":"Para 17(2)","rbi_char_offset":17988,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p17","layer":"bankpulse"},{"n":12,"claim":"md13643-b67dfd4b","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Security committee under it","plain_english":"An information security committee must sit under the IT Strategy Committee.","rbi_paragraph":"Para 23","rbi_char_offset":21747,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p18","layer":"bankpulse"},{"n":13,"claim":"md13643-534923a3","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Risk side heads it","plain_english":"The head of that security committee must come from the risk side of the bank.","rbi_paragraph":"Para 23","rbi_char_offset":22058,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p19","layer":"bankpulse"},{"n":14,"claim":"md13643-f2d348fd","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Name a head of IT","plain_english":"The bank must name a senior officer with real IT skill as head of the IT work.","rbi_paragraph":"Para 24","rbi_char_offset":22699,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p20","layer":"bankpulse"},{"n":15,"claim":"md13643-a6288744","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Head of IT duties","plain_english":"The head of IT must keep projects in line with policy and set up the backup site.","rbi_paragraph":"Para 25","rbi_char_offset":22945,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p21","layer":"bankpulse"},{"n":16,"claim":"md13643-2bfd61be","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Name a security officer","plain_english":"A senior officer, best of general manager rank, must be named security officer.","rbi_paragraph":"Para 27","rbi_char_offset":23721,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p22","layer":"bankpulse"},{"n":17,"claim":"md13643-1b402444","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Staff and budget for security","plain_english":"The security office must be well staffed and its budget set by the threats seen.","rbi_paragraph":"Para 27(3)","rbi_char_offset":24148,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p23","layer":"bankpulse"},{"n":18,"claim":"md13643-d862f85e","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"KEY DATES","heading":"Review architecture yearly","plain_english":"The IT Strategy Committee must review the IT design at least once a year.","rbi_paragraph":"Para 33","rbi_char_offset":26997,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p24","layer":"bankpulse"},{"n":19,"claim":"md13643-acfb681d","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"First line of defence","plain_english":"The head of IT is the first line of defence for IT controls and IT risk.","rbi_paragraph":"Para 26","rbi_char_offset":23331,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p25","layer":"bankpulse"},{"n":20,"claim":"md13643-f678451f","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Always invited","plain_english":"The security officer is a standing invitee to both the IT committees.","rbi_paragraph":"Para 28(3)","rbi_char_offset":25049,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p26","layer":"bankpulse"},{"n":21,"claim":"md13643-9b54bc26","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHO SHOULD ACT","heading":"Reports to the top","plain_english":"The security officer reports to the executive director who looks after risk.","rbi_paragraph":"Para 28(6)","rbi_char_offset":25345,"weight":"BACKGROUND","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p27","layer":"bankpulse"},{"n":22,"claim":"md13643-6d0b23c6","page_group":"Chapter III. Information Technology Governance and Oversight","stored_section":"WHAT CHANGES","heading":"Plan the technology refresh","plain_english":"The bank must plan to replace hardware and software before support runs out.","rbi_paragraph":"Para 38","rbi_char_offset":28167,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p28","layer":"bankpulse"},{"n":1,"claim":"md13643-9eb98002","page_group":"Chapter IV. IT and Information Security Risk Management","stored_section":"KEY DATES","heading":"Risk committee reviews yearly","plain_english":"The risk committee must review and update the risk policy at least once a year.","rbi_paragraph":"Para 39","rbi_char_offset":28512,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p29","layer":"bankpulse"},{"n":2,"claim":"md13643-29284841","page_group":"Chapter IV. IT and Information Security Risk Management","stored_section":"KEY DATES","heading":"Security check each year","plain_english":"The bank must review its security set up and policies at least once a year.","rbi_paragraph":"Para 43","rbi_char_offset":30195,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p30","layer":"bankpulse"},{"n":3,"claim":"md13643-81083d4e","page_group":"Chapter IV. IT and Information Security Risk Management","stored_section":"WHAT CHANGES","heading":"Grade your own risk","plain_english":"The bank must grade its own risk as low, moderate, high or very high.","rbi_paragraph":"Para 45","rbi_char_offset":30747,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p31","layer":"bankpulse"},{"n":1,"claim":"md13643-60157381","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Go beyond the top ten","plain_english":"Application security testing must not stop at the OWASP top 10 list.","rbi_paragraph":"Para 85","rbi_char_offset":41760,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p32","layer":"bankpulse"},{"n":2,"claim":"md13643-53bdfee9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Put the code in escrow","plain_english":"Where the source code cannot be had, the bank must place it in escrow.","rbi_paragraph":"Para 90","rbi_char_offset":43094,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p33","layer":"bankpulse"},{"n":3,"claim":"md13643-077dd865","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"No admin rights","plain_english":"Staff must not hold admin rights on their own desktop or laptop.","rbi_paragraph":"Para 108","rbi_char_offset":48769,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p34","layer":"bankpulse"},{"n":4,"claim":"md13643-9cf6bcb3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Removable media is barred","plain_english":"As a rule, pen drives and like media are barred unless allowed for a set use.","rbi_paragraph":"Para 121","rbi_char_offset":51923,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p35","layer":"bankpulse"},{"n":5,"claim":"md13643-cd1dc5a1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"No manual data changes","plain_english":"Data moving between critical systems must not be changed by hand on the way.","rbi_paragraph":"Para 141","rbi_char_offset":63348,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p36","layer":"bankpulse"},{"n":6,"claim":"md13643-1f6daf64","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Six months, then a year","plain_english":"Critical systems need a scan every six months and an attack test every 12 months.","rbi_paragraph":"Para 151","rbi_char_offset":65773,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"Suppose a scan is run in January and the next in July, six months later. The attack test run in January is next due the following January, 12 months later.","anchor":"https://bankpulse.ai/rule/md13643#p37","layer":"bankpulse"},{"n":7,"claim":"md13643-01b33f88","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Report closure each quarter","plain_english":"The closing of test findings must go to both IT committees every three months.","rbi_paragraph":"Para 161","rbi_char_offset":68986,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p38","layer":"bankpulse"},{"n":8,"claim":"md13643-ec94e41f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Drill every six months","plain_english":"Recovery drills for critical systems must be held at least once every six months.","rbi_paragraph":"Para 165","rbi_char_offset":70024,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p39","layer":"bankpulse"},{"n":9,"claim":"md13643-ad0cad46","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Six hours to report","plain_english":"A cyber incident must be reported on the DAKSH platform within six hours of detection.","rbi_paragraph":"Para 182","rbi_char_offset":73648,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p40","layer":"bankpulse"},{"n":10,"claim":"md13643-d78188f6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Warn customers on passwords","plain_english":"The bank must teach customers never to share a password, a one time code or a PIN.","rbi_paragraph":"Para 207","rbi_char_offset":79932,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p41","layer":"bankpulse"},{"n":11,"claim":"md13643-2c0d9eab","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep an asset list","plain_english":"The bank must keep an up to date list of all its information assets.","rbi_paragraph":"Para 47","rbi_char_offset":31863,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p42","layer":"bankpulse"},{"n":12,"claim":"md13643-a5649021","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep a data dictionary","plain_english":"The bank must keep a data dictionary so that systems share one meaning of data.","rbi_paragraph":"Para 49","rbi_char_offset":32354,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p43","layer":"bankpulse"},{"n":13,"claim":"md13643-a5b37c28","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Stop data leaks","plain_english":"The bank must have a full plan to stop the loss or leak of sensitive data.","rbi_paragraph":"Para 51","rbi_char_offset":32907,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p44","layer":"bankpulse"},{"n":14,"claim":"md13643-4213e5eb","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Wipe a lost device","plain_english":"The bank must be able to lock or wipe a mobile or a laptop from far away.","rbi_paragraph":"Para 54","rbi_char_offset":33840,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p45","layer":"bankpulse"},{"n":15,"claim":"md13643-785596d0","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Data migration policy","plain_english":"The bank must have a data migration policy that keeps data whole and correct.","rbi_paragraph":"Para 55","rbi_char_offset":33983,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p46","layer":"bankpulse"},{"n":16,"claim":"md13643-ba80711a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"List the allowed software","plain_english":"The bank must keep one central list of software that is allowed and not allowed.","rbi_paragraph":"Para 56","rbi_char_offset":34437,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p47","layer":"bankpulse"},{"n":17,"claim":"md13643-8266b0f7","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Control what gets installed","plain_english":"The bank must control what software can be put on its systems and devices.","rbi_paragraph":"Para 57","rbi_char_offset":34640,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p48","layer":"bankpulse"},{"n":18,"claim":"md13643-6366a5cc","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch for new patches","plain_english":"The bank must watch patch notices from makers and CERT-In and apply them fast.","rbi_paragraph":"Para 58","rbi_char_offset":35054,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p49","layer":"bankpulse"},{"n":19,"claim":"md13643-059c4daf","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Guard the data centre","plain_english":"Physical controls must protect the data centre and the backup site from harm.","rbi_paragraph":"Para 60","rbi_char_offset":35991,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p50","layer":"bankpulse"},{"n":20,"claim":"md13643-02b4a4c4","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch heat and water","plain_english":"The bank must watch for breaks in heat, water, smoke, power and access alarms.","rbi_paragraph":"Para 61","rbi_char_offset":36362,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p51","layer":"bankpulse"},{"n":21,"claim":"md13643-f90b638f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep the sites apart","plain_english":"The data centre and the backup site must be far apart in place.","rbi_paragraph":"Para 62","rbi_char_offset":36575,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p52","layer":"bankpulse"},{"n":22,"claim":"md13643-251b468d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Check capacity each year","plain_english":"The bank must check how much IT capacity it needs at least once a year.","rbi_paragraph":"Para 65","rbi_char_offset":37066,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p53","layer":"bankpulse"},{"n":23,"claim":"md13643-83a463a6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Set a security baseline","plain_english":"The bank must set and apply a base security setting for every kind of device.","rbi_paragraph":"Para 66","rbi_char_offset":37424,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p54","layer":"bankpulse"},{"n":24,"claim":"md13643-6d7cd39c","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Review firewalls often","plain_english":"The bank must review firewalls, switches and security kit and their patch levels.","rbi_paragraph":"Para 67","rbi_char_offset":37785,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p55","layer":"bankpulse"},{"n":25,"claim":"md13643-d0a39855","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep a network map","plain_english":"The bank must keep an up to date map of its wired and wireless networks.","rbi_paragraph":"Para 69","rbi_char_offset":38525,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p56","layer":"bankpulse"},{"n":26,"claim":"md13643-1282663c","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"List every allowed device","plain_english":"The bank must keep one central list of the devices allowed on its network.","rbi_paragraph":"Para 70","rbi_char_offset":38702,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p57","layer":"bankpulse"},{"n":27,"claim":"md13643-1c409baa","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Secure the wireless","plain_english":"The bank must secure wireless networks, access points and client systems.","rbi_paragraph":"Para 72","rbi_char_offset":39123,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p58","layer":"bankpulse"},{"n":28,"claim":"md13643-85ee4136","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Block strange devices","plain_english":"The bank must spot devices that are not allowed on the network and block them.","rbi_paragraph":"Para 74","rbi_char_offset":39565,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p59","layer":"bankpulse"},{"n":29,"claim":"md13643-3a79f3c2","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Layer the boundary","plain_english":"Boundary defence must be layered, with firewalls, proxies and intrusion systems.","rbi_paragraph":"Para 77","rbi_char_offset":39983,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p60","layer":"bankpulse"},{"n":30,"claim":"md13643-c927983f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Support IPv6 traffic","plain_english":"Public facing systems of the bank must be able to carry IPv6 traffic.","rbi_paragraph":"Para 78","rbi_char_offset":40386,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p61","layer":"bankpulse"},{"n":31,"claim":"md13643-811125c9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Write secure code","plain_english":"The bank must use secure coding when it builds software on its own or with others.","rbi_paragraph":"Para 80","rbi_char_offset":40594,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p62","layer":"bankpulse"},{"n":32,"claim":"md13643-28a08a15","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep environments apart","plain_english":"The build, test and live systems must be kept apart from each other.","rbi_paragraph":"Para 82","rbi_char_offset":41087,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p63","layer":"bankpulse"},{"n":33,"claim":"md13643-3e102a48","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Vendors must support it","plain_english":"The bank must tie down software support from its vendors by formal agreement.","rbi_paragraph":"Para 89","rbi_char_offset":42847,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p64","layer":"bankpulse"},{"n":34,"claim":"md13643-75e13613","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Get the source code","plain_english":"The bank must get the source code for every critical application from the vendor.","rbi_paragraph":"Para 90","rbi_char_offset":43016,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p65","layer":"bankpulse"},{"n":35,"claim":"md13643-e38c2c3a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Written word from the vendor","plain_english":"The vendor must confirm in writing that the software carries no known flaw or malware.","rbi_paragraph":"Para 92","rbi_char_offset":43580,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p66","layer":"bankpulse"},{"n":36,"claim":"md13643-50424d0b","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Log every critical system","plain_english":"Every system that touches critical or sensitive data must keep an audit trail.","rbi_paragraph":"Para 93","rbi_char_offset":44648,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p67","layer":"bankpulse"},{"n":37,"claim":"md13643-687b2d84","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Trails must stand as proof","plain_english":"Audit trails must be full enough to serve as proof and to settle a dispute.","rbi_paragraph":"Para 95","rbi_char_offset":45136,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p68","layer":"bankpulse"},{"n":38,"claim":"md13643-a77541c3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch the audit trails","plain_english":"The bank must watch audit trails and system logs to find any attack or misuse.","rbi_paragraph":"Para 96","rbi_char_offset":45610,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p69","layer":"bankpulse"},{"n":39,"claim":"md13643-e0af47db","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Find the root cause","plain_english":"The bank must find the root cause of any incident and patch the weak point.","rbi_paragraph":"Para 102","rbi_char_offset":47490,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p70","layer":"bankpulse"},{"n":40,"claim":"md13643-c9dbca45","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch the privileged user","plain_english":"Staff with high system rights must be watched and all their work logged.","rbi_paragraph":"Para 105","rbi_char_offset":48165,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p71","layer":"bankpulse"},{"n":41,"claim":"md13643-bccb0892","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"One place to sign in","plain_english":"Sign in and rights must run from one central system with strong password rules.","rbi_paragraph":"Para 109","rbi_char_offset":48991,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p72","layer":"bankpulse"},{"n":42,"claim":"md13643-8bb7ef82","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Close dormant accounts","plain_english":"The bank must limit failed sign in tries and switch off accounts nobody uses.","rbi_paragraph":"Para 112","rbi_char_offset":49898,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p73","layer":"bankpulse"},{"n":43,"claim":"md13643-589d19fc","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Prove who the customer is","plain_english":"The bank must be able to prove who a customer is on every channel it runs.","rbi_paragraph":"Para 115","rbi_char_offset":50651,"weight":"DO IT","role":"Branch","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p74","layer":"bankpulse"},{"n":44,"claim":"md13643-38f20185","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Secure the mail system","plain_english":"The bank must guard its mail against spoofing, look alike names and bad files.","rbi_paragraph":"Para 117","rbi_char_offset":51071,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p75","layer":"bankpulse"},{"n":45,"claim":"md13643-f4199fd6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Use DMARC on email","plain_english":"The bank must put DMARC in place on its email names to stop spoofing.","rbi_paragraph":"Para 120","rbi_char_offset":51583,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p76","layer":"bankpulse"},{"n":46,"claim":"md13643-45c38255","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Scan media first","plain_english":"Removable media must be scanned for malware before read or write access is given.","rbi_paragraph":"Para 124","rbi_char_offset":52508,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p77","layer":"bankpulse"},{"n":47,"claim":"md13643-f16e6a11","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Assess vendor risk","plain_english":"The bank must assess vendor risk and hold controls that match that risk.","rbi_paragraph":"Para 126","rbi_char_offset":53107,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p78","layer":"bankpulse"},{"n":48,"claim":"md13643-627fa42d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Right to audit the vendor","plain_english":"The vendor agreement must give the bank a right to audit and RBI a right to inspect.","rbi_paragraph":"Para 132","rbi_char_offset":54396,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p79","layer":"bankpulse"},{"n":49,"claim":"md13643-80288cf1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"RBI can see everything","plain_english":"RBI must be able to reach every information resource the bank uses.","rbi_paragraph":"Para 133","rbi_char_offset":54628,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p80","layer":"bankpulse"},{"n":50,"claim":"md13643-af8f6bf5","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Where the data may sit","plain_english":"The bank must follow the law on where systems sit and where data may travel.","rbi_paragraph":"Para 134","rbi_char_offset":54941,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p81","layer":"bankpulse"},{"n":51,"claim":"md13643-45bd3948","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Switch provider must comply","plain_english":"The ATM switch provider must meet the cyber controls the bank writes into the contract.","rbi_paragraph":"Para 136","rbi_char_offset":55403,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p82","layer":"bankpulse"},{"n":52,"claim":"md13643-c080f61a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Change default passwords","plain_english":"Default passwords on network devices and systems must be changed after they go in.","rbi_paragraph":"Para 138(1)","rbi_char_offset":57266,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p83","layer":"bankpulse"},{"n":53,"claim":"md13643-e766da80","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Provider needs its own centre","plain_english":"The ATM switch provider must set up its own cyber security operations centre.","rbi_paragraph":"Para 138(23)","rbi_char_offset":61952,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p84","layer":"bankpulse"},{"n":54,"claim":"md13643-255d255a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Card standards apply","plain_english":"The switch provider must meet the payment card industry data security standard.","rbi_paragraph":"Para 138(24)","rbi_char_offset":62355,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p85","layer":"bankpulse"},{"n":55,"claim":"md13643-e1e01400","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Use strong encryption","plain_english":"Key length, methods and protocols used to send and hold data must be strong.","rbi_paragraph":"Para 140","rbi_char_offset":62804,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p86","layer":"bankpulse"},{"n":56,"claim":"md13643-130f6356","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Run a security centre","plain_english":"The bank must set up a cyber security operations centre for a constant watch.","rbi_paragraph":"Para 143","rbi_char_offset":63861,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p87","layer":"bankpulse"},{"n":57,"claim":"md13643-a78b4662","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Whitelist internet sites","plain_english":"The bank must whitelist the internet sites and systems that staff may reach.","rbi_paragraph":"Para 146","rbi_char_offset":64814,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p88","layer":"bankpulse"},{"n":58,"claim":"md13643-76c141e6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Buy anti phishing help","plain_english":"The bank must buy a service that takes down fake sites and rogue apps.","rbi_paragraph":"Para 148","rbi_char_offset":65125,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p89","layer":"bankpulse"},{"n":59,"claim":"md13643-effed654","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Scan and attack tests","plain_english":"The bank must run scans and attack tests on all critical and internet facing systems.","rbi_paragraph":"Para 149","rbi_char_offset":65351,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p90","layer":"bankpulse"},{"n":60,"claim":"md13643-598ddf75","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Independent testers only","plain_english":"Scans and attack tests must be run by trained and independent security experts.","rbi_paragraph":"Para 155","rbi_char_offset":67021,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p91","layer":"bankpulse"},{"n":61,"claim":"md13643-17174880","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Follow the ISO standard","plain_english":"The continuity and recovery policy must follow best practice such as ISO 22301.","rbi_paragraph":"Para 163","rbi_char_offset":69426,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p92","layer":"bankpulse"},{"n":62,"claim":"md13643-fdfba237","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Run on the backup site","plain_english":"A recovery test must run the backup site as the main site for a full working day.","rbi_paragraph":"Para 167","rbi_char_offset":70425,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p93","layer":"bankpulse"},{"n":63,"claim":"md13643-fd42c647","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Test your backups","plain_english":"The bank must back data up and restore it now and then to prove it works.","rbi_paragraph":"Para 169","rbi_char_offset":70785,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p94","layer":"bankpulse"},{"n":64,"claim":"md13643-c120ed54","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Near zero data loss","plain_english":"The bank must aim for the least recovery time and near zero data loss.","rbi_paragraph":"Para 171","rbi_char_offset":71200,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p95","layer":"bankpulse"},{"n":65,"claim":"md13643-e6f9d9b3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Both sites must match","plain_english":"The settings and security patches at the main and backup sites must be the same.","rbi_paragraph":"Para 173","rbi_char_offset":71567,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p96","layer":"bankpulse"},{"n":66,"claim":"md13643-425e3cc7","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Have a response policy","plain_english":"The bank must have a written policy on how it answers and recovers from an incident.","rbi_paragraph":"Para 175","rbi_char_offset":71994,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p97","layer":"bankpulse"},{"n":67,"claim":"md13643-52689ea1","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Train the incident staff","plain_english":"Staff who handle cyber incidents must be given special training.","rbi_paragraph":"Para 176","rbi_char_offset":72663,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p98","layer":"bankpulse"},{"n":68,"claim":"md13643-198edfe9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Plan for ransomware","plain_english":"The bank must write down how it answers ransomware, data wiping and denial of service.","rbi_paragraph":"Para 179","rbi_char_offset":73125,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p99","layer":"bankpulse"},{"n":69,"claim":"md13643-accb6333","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Shut the attack in","plain_english":"The bank must hold an attack in by shielding or cutting off the hit systems.","rbi_paragraph":"Para 180","rbi_char_offset":73247,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p100","layer":"bankpulse"},{"n":70,"claim":"md13643-b903fe0d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Tell CERT-In as well","plain_english":"The bank must also tell CERT-In about a cyber incident without being asked.","rbi_paragraph":"Para 182","rbi_char_offset":73830,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p101","layer":"bankpulse"},{"n":71,"claim":"md13643-1d6045b6","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Share threat news","plain_english":"The bank must set up ways to gather and share threat news at home and abroad.","rbi_paragraph":"Para 186","rbi_char_offset":74684,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p102","layer":"bankpulse"},{"n":72,"claim":"md13643-262902ef","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Join the cyber drills","plain_english":"The bank must take part in cyber drills run by CERT-In and IDRBT.","rbi_paragraph":"Para 188","rbi_char_offset":75112,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p103","layer":"bankpulse"},{"n":73,"claim":"md13643-f5404564","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Write a crisis plan","plain_english":"The bank must write a cyber crisis management plan under the Board approved framework.","rbi_paragraph":"Para 192","rbi_char_offset":76026,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p104","layer":"bankpulse"},{"n":74,"claim":"md13643-06d168bf","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Four steps in a crisis","plain_english":"The crisis plan must cover four steps: detection, containment, response and recovery.","rbi_paragraph":"Para 193","rbi_char_offset":76162,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p105","layer":"bankpulse"},{"n":75,"claim":"md13643-b5bcf87f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Measure with real numbers","plain_english":"The bank must build measures such as patch delay, malware cover and training reach.","rbi_paragraph":"Para 194","rbi_char_offset":77057,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p106","layer":"bankpulse"},{"n":76,"claim":"md13643-b71482d9","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Teach the staff","plain_english":"The bank must set out safe use rules for staff, vendors and partners.","rbi_paragraph":"Para 199","rbi_char_offset":78364,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p107","layer":"bankpulse"},{"n":77,"claim":"md13643-1a8dea84","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Train every new recruit","plain_english":"Cyber awareness training is a must for all new recruits.","rbi_paragraph":"Para 203","rbi_char_offset":79131,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p108","layer":"bankpulse"},{"n":78,"claim":"md13643-37de37af","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"KEY DATES","heading":"Board training each year","plain_english":"The Board and senior staff must be trained on IT and cyber risk once a year.","rbi_paragraph":"Para 204","rbi_char_offset":79487,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p109","layer":"bankpulse"},{"n":79,"claim":"md13643-0002385f","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHO SHOULD ACT","heading":"Take down fake sites","plain_english":"The bank must ask customers to report phishing mail and then act on it.","rbi_paragraph":"Para 206","rbi_char_offset":79780,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p110","layer":"bankpulse"},{"n":80,"claim":"md13643-61a9e358","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Watch risky transactions","plain_english":"The bank must watch transactions on a risk basis across every channel it runs.","rbi_paragraph":"Para 209","rbi_char_offset":80299,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p111","layer":"bankpulse"},{"n":81,"claim":"md13643-7ad9a84d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Alert on large payments","plain_english":"The bank must alert the customer about payments above a value the customer sets.","rbi_paragraph":"Para 210","rbi_char_offset":80457,"weight":"DO IT","role":"Branch","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p112","layer":"bankpulse"},{"n":82,"claim":"md13643-6e70e47e","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Keep forensics on standby","plain_english":"The bank must keep network forensic and denial of service help on standby.","rbi_paragraph":"Para 211","rbi_char_offset":80651,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p113","layer":"bankpulse"},{"n":83,"claim":"md13643-42e2db7a","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"THE CORE IDEA","heading":"The data stays yours","plain_english":"The bank owns the duty to keep customer data safe, even at a vendor site.","rbi_paragraph":"Para 53","rbi_char_offset":33346,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p114","layer":"bankpulse"},{"n":84,"claim":"md13643-67129961","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"THE CORE IDEA","heading":"Access on business need","plain_english":"Access to information assets is allowed only where there is a real business need.","rbi_paragraph":"Para 104","rbi_char_offset":48058,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p115","layer":"bankpulse"},{"n":85,"claim":"md13643-9775b1c2","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Two factor for privilege","plain_english":"A second factor is needed to sign in for privileged users of critical systems.","rbi_paragraph":"Para 110","rbi_char_offset":49382,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p116","layer":"bankpulse"},{"n":86,"claim":"md13643-a535fe5c","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Rules for remote work","plain_english":"Remote work needs safe systems, a second sign in factor and a list of remote devices.","rbi_paragraph":"Para 114","rbi_char_offset":50062,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p117","layer":"bankpulse"},{"n":87,"claim":"md13643-da5a785d","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Bank is the identity source","plain_english":"The bank stands as the identity source when a customer reaches a partner system.","rbi_paragraph":"Para 116","rbi_char_offset":50862,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p118","layer":"bankpulse"},{"n":88,"claim":"md13643-775c2fa3","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"THE CORE IDEA","heading":"The bank stays answerable","plain_english":"The bank stays answerable for security risk in work it has given out.","rbi_paragraph":"Para 127","rbi_char_offset":53622,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p119","layer":"bankpulse"},{"n":89,"claim":"md13643-3167a119","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Check vendor staff","plain_english":"Background checks and secrecy agreements are needed for all vendor staff.","rbi_paragraph":"Para 135","rbi_char_offset":55224,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p120","layer":"bankpulse"},{"n":90,"claim":"md13643-9e799264","page_group":"Chapter V. Baseline Cybersecurity and Resilience Requirements","stored_section":"WHAT CHANGES","heading":"Red team exercises","plain_english":"The bank may run red team drills that copy how a real attacker works.","rbi_paragraph":"Para 162","rbi_char_offset":69139,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p121","layer":"bankpulse"},{"n":1,"claim":"md13643-d60b7631","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHAT CHANGES","heading":"Framework for the centre","plain_english":"The bank must have a framework to set up and run its security operations centre.","rbi_paragraph":"Para 212","rbi_char_offset":80865,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p122","layer":"bankpulse"},{"n":2,"claim":"md13643-0bdbdd06","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHO SHOULD ACT","heading":"What the centre must do","plain_english":"The centre must watch, study and escalate incidents and work with outside agencies.","rbi_paragraph":"Para 217","rbi_char_offset":82805,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p123","layer":"bankpulse"},{"n":3,"claim":"md13643-ce5cad0b","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHO SHOULD ACT","heading":"Watch round the clock","plain_english":"The bank must work out the staff it needs to watch systems 24x7.","rbi_paragraph":"Para 223","rbi_char_offset":86076,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p124","layer":"bankpulse"},{"n":4,"claim":"md13643-be14ef6e","page_group":"Chapter VI. Cyber Security Operations Centre","stored_section":"WHO SHOULD ACT","heading":"Level three analysts","plain_english":"Level three analysts need deep packet study, forensic skill and malware knowledge.","rbi_paragraph":"Para 221(3)","rbi_char_offset":85575,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p125","layer":"bankpulse"},{"n":1,"claim":"md13643-ab4d7822","page_group":"Chapter VII. Information Systems Audit","stored_section":"WHAT CHANGES","heading":"Have an IS audit policy","plain_english":"The bank must have an information systems audit policy.","rbi_paragraph":"Para 225","rbi_char_offset":86741,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p126","layer":"bankpulse"},{"n":2,"claim":"md13643-ce9657e0","page_group":"Chapter VII. Information Systems Audit","stored_section":"KEY DATES","heading":"Audit policy reviewed yearly","plain_english":"The audit committee must approve that policy and review it at least once a year.","rbi_paragraph":"Para 225","rbi_char_offset":86929,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p127","layer":"bankpulse"},{"n":3,"claim":"md13643-aa02ff51","page_group":"Chapter VII. Information Systems Audit","stored_section":"WHO SHOULD ACT","heading":"Separate IS audit function","plain_english":"The bank must have a separate information systems audit function with the right skill.","rbi_paragraph":"Para 227","rbi_char_offset":87181,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p128","layer":"bankpulse"},{"n":4,"claim":"md13643-ef5d403d","page_group":"Chapter VII. Information Systems Audit","stored_section":"WHAT CHANGES","heading":"Plan audits by risk","plain_english":"Audit planning must follow a risk based approach.","rbi_paragraph":"Para 228","rbi_char_offset":87606,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p129","layer":"bankpulse"},{"n":1,"claim":"md13643-d2980a9c","page_group":"Chapter VIII. Repeal and Other Provisions","stored_section":"WHAT IT REPLACES","heading":"Old cyber rules go","plain_english":"These Directions repeal the earlier cyber framework and IT governance instructions.","rbi_paragraph":"Para 230","rbi_char_offset":87952,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13643#p130","layer":"bankpulse"},{"n":2,"claim":"md13643-ed77acc3","page_group":"Chapter VIII. Repeal and Other Provisions","stored_section":"WHAT IT REPLACES","heading":"Other laws still apply","plain_english":"These Directions add to other laws and rules and do not replace them.","rbi_paragraph":"Para 232","rbi_char_offset":89438,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"A bank follows these Directions and thinks the matter is closed. It is not. Any other laws, rules, regulations or directions in force still apply on top. Where another one asks for more, the bank does the more.","anchor":"https://bankpulse.ai/rule/md13643#p131","layer":"bankpulse"},{"n":3,"claim":"md13643-a449e126","page_group":"Chapter VIII. Repeal and Other Provisions","stored_section":"THE CORE IDEA","heading":"RBI has the last word","plain_english":"RBI may issue clarifications, and its reading of these Directions is final.","rbi_paragraph":"Para 233","rbi_char_offset":89886,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"Two banks read the same clause differently. Neither reading settles it. RBI may issue clarifications, and its interpretation of any provision is final and binding on all concerned entities.","anchor":"https://bankpulse.ai/rule/md13643#p132","layer":"bankpulse"}],"actions":[],"amendments":[],"layers":{"rbi_source":"Facts taken from RBI's own document.","bankpulse":"BankPulse's plain-English summary of RBI's document.","bankpulse_inference":"BankPulse's own inference, not stated by RBI."},"rbi_wording_not_included":"By design. BankPulse never republishes RBI's exact sentences. Use rbi_paragraph with rbi_source.url to read RBI's own words.","terms":"BankPulse's plain-English summaries are BankPulse's own work. The underlying regulation is the Reserve Bank of India's. Always check the RBI document named in rbi_source before acting."}