Markets regulator Sebi on Thursday clarified that the cybersecurity and cyber resilience framework (CSCRF) applies only to systems used exclusively for its regulated activities. Shared infrastructure will also be audited if not already covered by the RBI or another regulator. Further, if regulated entities (REs) comply with RBI (or other regulator) cybersecurity rules that are equivalent to Sebi's, such compliance will be accepted by the markets watchdog. In its circular, Sebi also elaborated on the definition of critical systems, stating that it includes all systems that affect core operations, store or transmit regulatory data, client-facing applications, internet-facing systems, and other systems on the same network.REs have been asked to adopt zero-trust principles such as network segm
A lot of disclosures made by companies to stock exchanges "probably leaves a lot for imagination", a Sebi official said on Thursday. At a conference in the national capital, Rajesh Dangeti, Chief General Manager of Corporation Finance Department (CFD) at the Securities and Exchange Board of India (Sebi), also emphasised the need to ensure that information is not only given out by companies frequently but also fairly and in a manner which is easily understood by the investors. He also wondered whether there is a scope for reducing the time frame for certain disclosures that are currently made on a quarterly basis. Under Sebi norms, listed entities are required to make various disclosures in a timely manner in order to ensure the interests of shareholders, especially minority shareholders, a