๐Ÿฆ RBI CYBER SECURITY FRAMEWORK โ€” RBI/2015-16/418 ๐Ÿ“‹ 24 BASELINE REQUIREMENTS โ€” 106 CONTROLS MAPPED ๐Ÿ›ก๏ธ BOARD-APPROVED CYBER SECURITY POLICY MANDATORY โฑ๏ธ CYBER INCIDENTS REPORTABLE TO RBI IN 2โ€“6 HOURS โš–๏ธ MONETARY PENALTIES UNDER BANKING REGULATION ACT ๐Ÿ›๏ธ SOC & CYBER CRISIS MANAGEMENT PLAN REQUIRED ๐Ÿ”ฅ 40% EARLY BIRD DISCOUNT ๐ŸŽ 30-DAY FREE TRIAL ๐Ÿฆ RBI CYBER SECURITY FRAMEWORK โ€” RBI/2015-16/418 ๐Ÿ“‹ 24 BASELINE REQUIREMENTS โ€” 106 CONTROLS MAPPED ๐Ÿ›ก๏ธ BOARD-APPROVED CYBER SECURITY POLICY MANDATORY โฑ๏ธ CYBER INCIDENTS REPORTABLE TO RBI IN 2โ€“6 HOURS โš–๏ธ MONETARY PENALTIES UNDER BANKING REGULATION ACT ๐Ÿ›๏ธ SOC & CYBER CRISIS MANAGEMENT PLAN REQUIRED ๐Ÿ”ฅ 40% EARLY BIRD DISCOUNT ๐ŸŽ 30-DAY FREE TRIAL
๐Ÿฆ RBI Cyber Security Framework in Banks โ€” Annex 1 Baseline

Prove RBI Cyber
Security
Compliance.

RBI circular RBI/2015-16/418 mandates a Board-approved cyber security policy and a baseline of 24 requirements for every bank. Our platform codifies all 24 requirements and 106 controls into role-based workflows โ€” making your posture measurable, auditable and defensible before a supervisory assessment.

โœ… 24 Baseline Requirements
โœ… 106 Controls
โœ… 3 Role Panels
โœ… Audit Ready
RBI Compliance Snapshot
24
Baseline RequirementsAnnex 1 of RBI/2015-16/418
106
Mapped ControlsPre-loaded across all requirements
2โ€“6h
Incident ReportingWindow to report to RBI / CERT-In
6
Control DomainsGrouping the 24 baseline requirements
โš ๏ธ WHY NON-COMPLIANCE MATTERS

The Real Cost of
Falling Short of the RBI Framework

Unlike a flat fine schedule, RBI consequences are supervisory and regulatory. Gaps in your baseline controls surface during RBI inspections, IT examinations and incident reviews โ€” and carry real financial, legal and reputational weight.

โš–๏ธ
Sec 46 / 47A
BANKING REGULATION ACT PENALTIES

RBI can impose monetary penalties on banks for contravention of its directions, including the Cyber Security Framework. Penalties are accompanied by public disclosure โ€” a direct reputational hit with customers and the market.

โฑ๏ธ
2โ€“6 Hours
MANDATORY INCIDENT REPORTING

Banks must report unusual cyber-security incidents to the RBI within two to six hours (Annex 3 template), and to CERT-In / NCIIP / IB-CART. Late or incomplete reporting compounds supervisory concern during follow-up.

๐Ÿ›๏ธ
Board Liability
OVERSIGHT & ACCOUNTABILITY

The framework places cyber-security squarely with the Board and its IT Sub-Committee. A Board-approved policy, gap assessment and SOC are required โ€” leadership is accountable for material control gaps during examination.

24
Baseline Requirements
106
Controls Mapped
6
Control Domains
3
Role Panels
๐Ÿ›ก๏ธ THE SOLUTION

RBI Compliance
Made Measurable

Spreadsheets cannot produce the structured, auditable evidence an RBI examination demands. The Cognisec RBI Cyber Security Engine codifies all 24 Annex-1 requirements and 106 controls into role-based workflows mapped to your bank's assets.

๐Ÿ—‚๏ธ

Asset Inventory & Classification

Build your inventory of business IT assets and classify by criticality, aligned to Requirement 1 of Annex 1. Coverage is computed per asset, not as a vague composite score.

๐Ÿ”

Risk Assessment & Residual Risk

Compliance Owners assess inherent and residual risk per asset. Identify gaps against the baseline and prioritise remediation under IT Sub-Committee oversight.

๐Ÿ”„

Control Submission & Validation

Owners submit control evidence; the CISO reviews, validates and approves. Every action is logged โ€” exactly the audit trail RBI inspections expect.

๐Ÿ“Š

Coverage Dashboards & Board Reporting

Live coverage = approved pairs รท required pairs (active assets ร— 24 requirements). Board Members see compliance posture, audit findings and submissions in one view.

Annex 1 โ€” 24 Requirements, 6 Domains
๐Ÿ—‚๏ธ
Asset & Configuration
Inventory, secure config, environmental, unauthorised software
๐ŸŒ
Network & Boundary Defence
Network security, real-time threat defence, anti-phishing
๐Ÿ”‘
Access & Authentication
User access, customer authentication, secure mail, removable media
๐Ÿ›ก๏ธ
Application & Vulnerability Mgmt
ASLC, patch/change management, VA/PT & red team
๐Ÿ“Š
Monitoring, Logging & Forensics
Audit logs, DLP, transaction monitoring, forensics
๐Ÿ›๏ธ
Governance, Response & Awareness
Vendor risk, incident response, metrics, staff & customer awareness
๐Ÿ—๏ธ THREE ROLE PANELS

Built for Every RBI Stakeholder

One platform, three dedicated panels โ€” CISO, Compliance Owner and Board Member. Each role sees exactly what the framework expects of them.

Panel 1

๐Ÿ›๏ธ CISO

The central owner of the bank's cyber-security programme. The CISO builds the policy, manages users, reviews Compliance Owner submissions, validates controls and reports the gap assessment to the Board โ€” as named in the circular.

  • Build and version the Cyber Security Policy
  • Review & validate Compliance Owner submissions
  • Full 24-requirement / 106-control coverage view
  • Residual risk oversight across all assets
  • Manage Compliance Owner accounts
  • Gap assessment reporting to the Board
Panel 2

๐Ÿ—‚๏ธ Compliance Owner

Responsible for day-to-day implementation. Compliance Owners build the asset inventory, assess risk per asset, implement controls across the 24 requirements, and submit evidence to the CISO for validation.

  • Asset inventory & bulk asset upload
  • Risk assessment per asset & requirement
  • Report & submit controls for review
  • Track rejected controls & remediation
  • Per-asset compliance view
  • Evidence upload aligned to Annex 1
Panel 3

๐Ÿ‘” Board Member

Read and oversight access for the Board and IT Sub-Committee. Approve the cyber-security policy, review audit findings and reports, and view compliance posture and risk โ€” the Board accountability the framework demands.

  • Approve the Board-level Cyber Security Policy
  • View audit findings & audit reports
  • Review control submissions
  • Compliance posture & risk dashboards
  • Oversight without operational edit rights
  • Evidence for supervisory assessment
๐Ÿ“œ FRAMEWORK IN FORCE

The RBI Framework Is Mandatory

Issued on 2 June 2016 and reinforced by subsequent RBI directions, the Cyber Security Framework applies to every scheduled commercial bank. The baseline is the floor โ€” not the ceiling โ€” for examination.

24
Requirements
106
Controls
3
Annexes

Circular RBI/2015-16/418 โ€” Department of Banking Supervision

๐Ÿ”ฅ EARLY BIRD OFFER

First 5 Subscribers
Get 40% OFF โ€” Forever

Lock in your discounted rate permanently. Price never increases for early subscribers.

โœ“
โœ“
3
4
5
3 spots left
Claim My 40% Discount โ†’
๐Ÿš€ GET STARTED TODAY

Stop Worrying About RBI Inspections.
Start Being Compliant.

30-day free trial. All features. All 3 panels. 24 requirements, 106 controls ready.

Start Free 30-Day Trial Learn About the Framework First

๐Ÿฆ No charge during trial ยท Cancel anytime ยท Early bird pricing locked for first 5 subscribers

๐Ÿค Looking for Channel Partners Across India

We are actively seeking partners โ€” IT vendors, audit firms and compliance consultants serving co-operative banks, regional and scheduled commercial banks โ€” to represent the Cognisec RBI Cyber Security Engine. If you work in banking technology or cyber-compliance, let's talk.

๐Ÿ’ฌ WhatsApp to Discuss Partnership ๐Ÿ“ง Email Us
๐Ÿ’ฌ Chat on WhatsApp for any enquiry
WhatsApp Us