Indian stock markets given ten day deadline to file infosec report, secure board signoff
- Reference: 1653461588
- News link: https://www.theregister.co.uk/2022/05/25/sebi_modified_mii_infosec_rules/
- Source link:
This time the source of the edict is the Securities and Exchange Board of India, which on May 20 [1]published a modified version of the "Cyber Security and Cyber Resilience framework" that applies to market infrastructure institutions (MIIs) – or stock exchanges, clearing corporations and depositories – that it published in 2015.
Among the modifications, equipment rated "critical" and therefore subject to regular security review and testing has been expanded to any internet-facing application, and any system that stores personally identifiable information. Anything that interacts with other critical systems for operations or maintenance is now also classified as critical.
[2]
MII boards must sign off on lists of critical systems.
[3]
[4]
Stock exchanges and other entities mentioned above have also been told to "maintain up-to-date inventory of … hardware and systems, software and information assets (internal and external), details of … network resources, connections to … network and data flows."
The update also orders increased frequency of security audits, and requires they be undertaken only by organizations approved by the Indian Computer Emergency Response Team.
[5]
And the sting in the tail?
"All MIIs are directed to communicate the status of the implementation of the provisions of this circular to SEBI within 10 days from the date of this circular."
[6]Infosys board asks boss Salil Parekh to stay another 5 years
[7]Indian government accuses Uber of jacking up prices for loyal customers
[8]India seizes $725 million of Xiaomi's cash
Just how one gets a board up to speed to sign off on a list of critical infrastructure ten days after the issuance of a circular is anyone's guess. The Register imagines many boards will push back – their duty of care precludes rushing to judgement. Especially because the modified rules were published on Friday, May 20, meaning the ten-day deadline spans two weekends.
The modified rules will likely be most unwelcome at MIIs, as they and all other Indian IT shops are already facing a 60-day deadline to adopt new rules that require [9]reporting of many infosec incidents within six hours of detection , log file retention, and collection of records of customer activities. Those rules have met with [10]considerable opposition . India's government [11]slightly reduced the reporting requirements, but the list of information Indian organizsations are required to collect is still long – and the 60-day deadline to be ready for the new reporting requirements was not extended. ®
Get our [12]Tech Resources
[1] https://www.sebi.gov.in/legal/circulars/may-2022/modification-in-cyber-security-and-cyber-resilience-framework-of-stock-exchanges-clearing-corporations-and-depositories_59085.html
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yo3@QxxYCtDUlruYq6pF2gAAAEs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yo3@QxxYCtDUlruYq6pF2gAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yo3@QxxYCtDUlruYq6pF2gAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yo3@QxxYCtDUlruYq6pF2gAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/05/23/infosys_ceo_stays/
[7] https://www.theregister.com/2022/05/11/indian_government_ridesharing_regulation_crackdown/
[8] https://www.theregister.com/2022/05/03/india_seizes_xiaomo_cash/
[9] https://www.theregister.com/2022/04/29/cert_in_directive/
[10] https://www.theregister.com/2022/05/10/india_infosec_rules_criticised/
[11] https://www.theregister.com/2022/05/20/cert_in_rules_faq/
[12] https://whitepapers.theregister.com/
Shirley...?
Surely any organization that takes security seriously will have already done most of the donkey work already and the only rushed aspect will be to convene the board and put the relevant information in front of them for them to approve.
Won't they??
Re: Shirley...?
There is a world of difference between securing a network and documenting it, and another world of difference between documenting it and writing a government-mandated report.
I take it you haven't written any government reports. I have written a few (unfortunately), and it is not something I enjoy doing in the slightest.
Re: Shirley...?
If you don't document what you do then it might as well be considered not done. How many of us have ended up in world of pain because stuff was being done, but not documented, so it either needed checking or, and often easier, doing again just to confirm that it had been done.
I agree about government reporting (I've done it but in UK and US, not India), but if the article is correct then that's not what's needed.
"All MIIs are directed to communicate the status of the implementation of the provisions of this circular to SEBI within 10 days from the date of this circular."
If they've taken any of this seriously since 2015 (when the original requirements were published) then they only have to say that, in line with their current Cyber Security and Cyber Resilience Framework Policies and Procedures they are auditing their estate in light of the new requirements and will update the P&Ps and relevant audit/test/HR/reporting/risk/etc. plans to include the new requirements. Then they attach their plan and schedule to finish these updates and an outline/draft plan with assumptions (they haven't finished the audit yet) to meet the new framework requirements.
For a large company this is still a fair bit of work but if they take cyber security and resilience seriously and make it part of their everyday work they ought to be able to produce something that will demonstrate they are on top of it. Of course, if they've done fuck all since 2015 then they can still report on this. The report will be a lot of management speak for "we've done fuck all" and the plan and schedule might be a bit vague and run out a few years, but they could still meet the letter of the "communicate the status....".
Indian IT
What could possibly go wrong.
And if it doesn't happen in 10 days ?
What if the companies simply don't respond in the allotted time span ?
Is there any hint of a fine anywhere ?
On the other hand, they could respond with a basic report and mention "See Appendix . . ." for all precisions, the appendices being sent 30 days later.
This whole attitude smacks of useless pressure from administrative busybodies who grant themselves a lot more importance than they have.
Businesses don't want to be hacked. Most of them do want to be secure, and a fair proportion of them actually put money on the table for that. The thought behind this new rule may be commendable, but granting a 90-day delay (given that businesses are already on a 60-day delay for something else) wouldn't kill the donkey.
Criticality?
" Among the modifications, equipment rated "critical" and therefore subject to regular security review and testing has been expanded to any internet-facing application, and any system that stores personally identifiable information. Anything that interacts with other critical systems for operations or maintenance is now also classified as critical. "
Was the businesswise relatively unimportant server on which some bod ('for convenience') at Equifax saved a clear test list of the access credentials for numerous other functionally important servers 'critical'?
Making blanket rules based on lists is a sure fire way to miss the elephants in the office, as such rules always either have insufficient coverage or they get so complicated and detailed that they can't be maintained (or indeed in some cases even implemented). Also, as is commonly the case for PCI DSS, such rules can result in everything not on the list being left wide open because attention is focused primarily on 'compliance' with the rules.
What's really needed for adequate security is constant attention to and monitoring of the actualities of each individual organisation's infrastructure in the context of its purposes and risks. That requires knowledgeable, dedicated personnel - and that requires sufficient resourcing. As ISO/IEC 27001 states, top management are responsible for information security, at least insofar as they must provide the authority and finance for the job to be done properly.
Leaving security to the IT department to manage out of its local budget is a sure path to failure, as is following the letter of externally generated rules at the expense of keeping in touch with what's actually happening.
Can the Indian government respond in any meaningful way to its citizens in 10 days?