RBI Cybersecurity Framework for Banks
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Data Protection
Per RBI Cyber Framework: data protection. Requirements include (a) data classification + handling + (b) encryption at rest + in transit + (c) data loss prevention + (d) customer data security per PMLA + DPDPA + (e) cross-border data transfer compliance + (f) maintain documented data protection.
- RBI Cyber evidence for RBIBANK-4
- 6-hour incident reporting + concurrent audit + Board approval partial
Governance
Per RBI Cybersecurity Framework for Banks: governance. Requirements include (a) maintain Board-Approved Cybersecurity Policy aligned to RBI master direction + (b) maintain Cyber Crisis Management Plan including detection + response + recovery + (c) maintain Inventory of Information Assets + classification + (d) implement governance structure including CISO + Chief Risk Officer + (e) report to Board + senior management + (f) cooperate with RBI inspections.
- RBI Cyber evidence for RBIBANK-1
- 6-hour incident reporting + concurrent audit + Board approval partial
Identity Access
Per RBI Cyber Framework: identity + access. Requirements include (a) Identity and Access Management + (b) Multi-Factor Authentication for sensitive systems + (c) Privileged Access Management (PAM) + (d) periodic access review + recertification + (e) maintain audit + (f) align with RBI MITM/phishing-resistant authentication.
- RBI Cyber evidence for RBIBANK-3
- 6-hour incident reporting + concurrent audit + Board approval partial
Incident Response
Per RBI Cyber Framework + CERT-In Directions: incident response. Requirements include (a) incident response capability + (b) report cyber incidents to RBI within 6 hours per RBI Master Direction + (c) report to CERT-In within 6 hours per CERT-In Directions 2022 + (d) maintain incident log + (e) tabletop exercises + (f) integrate with broader IR.
- RBI Cyber evidence for RBIBANK-6
- 6-hour incident reporting + concurrent audit + Board approval partial
Technical Controls
Per RBI Cyber Framework: technical controls. Requirements include (a) Network Security and Segmentation + (b) Secure Configuration and Hardening + (c) Application Security including web + mobile + API + (d) Endpoint protection + EDR + (e) integrate with broader InfoSec baseline + (f) maintain testing + monitoring.
- RBI Cyber evidence for RBIBANK-2
- 6-hour incident reporting + concurrent audit + Board approval partial
Third-Party Risk
Per RBI Cyber Framework + Cloud Guidelines + Outsourcing Master Direction: third-party. Requirements include (a) third-party risk management + (b) cloud computing per RBI guidelines + (c) outsourcing contracts + concurrent audit + (d) ongoing monitoring + (e) right to audit + (f) cooperate with RBI inspections of third parties.
- RBI Cyber evidence for RBIBANK-7
- 6-hour incident reporting + concurrent audit + Board approval partial
Training and Awareness
Per RBI Cyber Framework: training. Requirements include (a) staff training role-based + (b) Board + senior management training + (c) customer education campaigns + (d) phishing simulations + (e) maintain training records + (f) measure effectiveness.
- RBI Cyber evidence for RBIBANK-8
- 6-hour incident reporting + concurrent audit + Board approval partial
Vulnerability and Threat
Per RBI Cyber Framework: vulnerability + threat. Requirements include (a) vulnerability assessment + penetration testing + bug bounty + (b) patching aligned to risk + (c) threat intelligence + IOC integration + (d) SOC + SIEM + (e) maintain documented programme.
- RBI Cyber evidence for RBIBANK-5
- 6-hour incident reporting + concurrent audit + Board approval partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.