India’s Securities and Exchange Board of India is seeking comments on a cybersecurity framework for subsidiaries of market infrastructure institutions, Law.asia reported. A consultation is not a final rule, but it signals where security and compliance expectations may be heading for organizations that support market infrastructure.

Institutions that may be in scope can use the consultation period to compare current controls with the proposed direction. Useful preparation includes mapping critical services and dependencies, reviewing third-party access, confirming incident escalation paths and testing the quality of evidence available for audits and regulatory reporting.

Cybersecurity frameworks are most effective when operational teams can translate them into owned controls. That means assigning accountable owners, establishing measurable review cycles and ensuring incident response plans are exercised rather than filed away. Organizations should consult the official SEBI materials for the authoritative scope, deadlines and eventual requirements.

Source: Law.asia

By Allan