RBI's cybersecurity framework for regulated financial entities, covering board-approved policy, incident reporting, and resilience testing obligations.
Who needs RBI
Banks, NBFCs, payment system operators, and other entities regulated by the Reserve Bank of India that are required to maintain a board-approved cybersecurity policy and report cyber incidents within RBI's mandated timelines.
Frequently asked
What is RBI?
Reserve Bank of India Cybersecurity Framework is a India compliance framework. RBI's cybersecurity framework for regulated financial entities, covering board-approved policy, incident reporting, and resilience testing obligations.
How does Threat ResQ Technologies help with RBI?
Threat ResQ maps your existing controls against RBI requirements, closes identified gaps, and supports the certification or attestation process end to end via getTRAC's continuous evidence collection.
How quickly must we report a cyber incident to RBI?
RBI mandates reporting of unusual cybersecurity incidents within a few hours of detection, depending on the entity type and incident category — significantly tighter than most global breach-notification windows.
Does RBI's framework overlap with ISO 27001 or PCI DSS?
Yes — many technical controls overlap, so we map RBI-specific requirements, like the board-approved policy and resilience testing obligations, onto whatever ISO 27001 or PCI DSS work you've already done rather than starting from zero.