Cloud Security in Banks: IIBF IT Security Exam Guide

ITSEC By Ashish Jain · IIBF STORE Editorial · 27 August 2026 · Updated 11 Oct 2026 · 12 min read · 46 views
Cloud Security in Banks: IIBF IT Security Exam Guide

Cloud security in banks is not a technology problem your vendor solves for you — it is an accountability problem the Reserve Bank has placed squarely on the bank's own board. When a bank moves its core lending platform, its data lake or even its HR system to a public cloud, the operational work shifts to the service provider, but the regulatory responsibility does not move an inch.

That single idea — you can outsource the activity, never the accountability — is the sentence IIBF examiners build questions around. This guide walks through the governing framework, the shared responsibility model, contractual controls, technical safeguards and exit planning, in the order an answer script should present them.

☁️ What Cloud Security in Banks Actually Covers

Cloud adoption in Indian banking is no longer limited to test environments. Banks run analytics workloads, customer onboarding journeys, chatbot stacks, disaster-recovery sites and increasingly whole digital-lending platforms on infrastructure they do not own. Security therefore has to be re-framed: instead of guarding a perimeter you control, you are governing a service relationship plus a configuration you control remotely.

Three deployment models appear in the syllabus. A public cloud is multi-tenant infrastructure offered by a commercial provider. A private cloud is dedicated to one institution, whether on-premises or hosted. A community cloud is shared by institutions with common regulatory needs — the model the Indian financial sector has been actively developing so that smaller banks and cooperative banks get cloud economics without each one negotiating its own controls. A hybrid cloud stitches two or more of these together.

Layered on top are the service models: IaaS (you rent compute, storage and network), PaaS (you rent a runtime and database platform) and SaaS (you rent finished software). The higher you climb, the less you operate — and the more your assurance depends on contracts, certifications and monitoring rather than on hands-on configuration.

What does not change across any of these models is the control objective. Confidentiality, integrity, availability, auditability and regulatory compliance still have to be demonstrated to the RBI, to statutory auditors and to the bank's own audit committee. That is why cloud questions in the IT Security paper are rarely about a vendor's product names; they are about governance, evidence and residual risk.

💡 Exam Tip: If an option says the cloud service provider "becomes responsible for regulatory compliance", it is wrong. Accountability to the regulator always stays with the regulated entity — the bank.

🏛️ The RBI Rulebook You Must Be Able to Name

Two RBI instruments dominate this topic. The first is the Master Direction on Outsourcing of Information Technology Services, April 2023, which brings cloud computing within the definition of IT outsourcing. The second is the Master Direction on IT Governance, Risk, Controls and Assurance Practices, issued in November 2023, which sets the board-level governance structure any cloud decision must sit inside. Read both from the Reserve Bank of India's official website — the definitions are examinable.

The IT outsourcing direction requires a board-approved IT outsourcing policy, a framework for identifying material outsourcing, due diligence, a comprehensive agreement, ongoing monitoring, business continuity planning and a tested exit strategy. Outsourcing must also never impede the RBI's supervisory access — inspectors must reach the bank's records wherever they physically sit.

The IT governance direction adds the organisational scaffolding: an IT Strategy Committee of the Board, an executive-level IT Steering Committee, a designated senior official heading information security, and an independent assurance stream reporting to the audit committee rather than to the CIO. Naming that separation of duties earns marks, because it is the control that stops a technology team from marking its own homework.

Two non-RBI instruments also apply. CERT-In's April 2022 directions require reporting of specified cyber incidents within six hours, ICT logs maintained for 180 days within India, and five-year retention of subscriber records by cloud and VPN providers. The Digital Personal Data Protection Act, 2023 governs personal data handled by any processor the bank appoints — in a cloud arrangement, the provider itself.

⚠️ Common Mistake: The six-hour incident-reporting clock is a CERT-In requirement. The RBI IT Directions of 2023 do not prescribe a fixed hour limit; RBI's separate two-to-six hour expectation traces back to its 2016 cyber security framework circular. Do not merge the three.
Key Concepts — IT Security
Key Concepts — IT Security

🔐 The Shared Responsibility Model, Line by Line

Every cloud contract rests on a shared responsibility model: the provider secures the cloud, the customer secures what it puts in the cloud. Most real-world breaches in cloud environments are not provider failures at all — they are customer-side misconfigurations such as an open storage bucket, an over-privileged access key or a security group left wide open to the internet.

The split moves as you change service model, which is exactly what a well-set MCQ tests. The table below maps the usual division and, in the last column, the point that never moves.

Control layerIaaSPaaSSaaSBank still accountable to RBI?
Physical data centre and hardwareProviderProviderProvider✅
Hypervisor and host operating systemProviderProviderProvider✅
Guest OS patching and hardeningBankProviderProvider✅
Application code and secure developmentBankBankProvider✅
Network configuration and firewall rulesBankSharedProvider✅
Identity, access rights and privileged accountsBankBankBank✅
Data classification and encryption keysBankBankBank✅
Regulatory compliance and supervisory accessBankBankBank✅

Notice the pattern in the bottom three rows. Identity, data classification and key custody stay with the bank in every model, which is why the bank's own cryptographic key management in banks programme decides whether cloud data is genuinely protected or merely stored behind someone else's login screen. Holding keys outside the provider's control plane — or at minimum in a customer-managed key service — is what converts encryption from a checkbox into a control.

🧾 Due Diligence, Contracts and the Right to Audit

Before a single workload moves, the bank has to complete due diligence on the service provider. Assess financial soundness, ownership and jurisdiction, track record with regulated customers, sub-contracting chains, insurance cover, and the independent assurance the provider can furnish — typically ISO/IEC 27001 certification supplemented by the cloud-specific ISO/IEC 27017 and privacy-focused ISO/IEC 27018 codes of practice, plus a current independent service-auditor report.

The agreement then has to carry hard clauses rather than marketing language. Examiners expect you to list them:

  • Right to audit — for the bank, its statutory auditors and the RBI, including access to the provider's premises and records.
  • Data location and localisation — where data is stored, processed and backed up, honouring RBI's payment-system data storage requirement and any sectoral restriction on cross-border transfer.
  • Confidentiality and data ownership — the bank owns the data; the provider is a custodian with no secondary-use rights.
  • Sub-contracting controls — prior consent, and flow-down of the same obligations to the fourth party.
  • Service levels with penalties — availability, recovery time objective, recovery point objective and incident-notification timelines.
  • Breach notification — a contractual clock tight enough to let the bank meet its own CERT-In and RBI reporting duties.
  • Termination assistance and data return or destruction — in a documented, portable format, with certified deletion.

Monitoring does not stop at signature. Periodic reassessment, review of assurance reports, and independent testing keep the arrangement current, and the assurance function should test the cloud estate exactly as it tests on-premises systems. The syllabus material on security standards and best practices and on organisational security and risk management is the study anchor for this section.

Process & Framework — IT Security
Process & Framework — IT Security

🛡️ Technical Controls Examiners Keep Returning To

Governance answers earn the framework marks; technical answers earn the rest. Five control families come up repeatedly.

Identity and access management. Cloud has no perimeter, so identity is the perimeter. Enforce multi-factor authentication for every administrative console, apply least privilege through roles rather than standing permissions, use just-in-time elevation for privileged tasks, rotate access keys, and never embed long-lived credentials in code or images.

Data protection. Classify data before migration, because classification decides what may leave the country and what may not. Then apply encryption in transit and at rest consistently, with the bank retaining key custody wherever the risk assessment demands it.

Network isolation. Virtual private clouds, subnet-level segregation, security groups, private connectivity back to the data centre and strict egress filtering keep tenant workloads apart from each other and from the open internet. Revise this alongside the chapter on network controls.

Workload and pipeline security. Immutable images, hardened baselines, automated vulnerability scanning and signed artefacts protect what actually runs. Where the bank ships microservices, the discipline described in container security in banks applies directly, and it pairs with the chapter on software security control.

Logging and continuous configuration monitoring. Centralise cloud audit trails into the bank's own monitoring platform, retain them in India for the mandated period, and run automated posture checks that flag a public bucket or a disabled log stream within minutes rather than at the next audit.

📌 Remember: Misconfiguration, not provider compromise, is the leading cause of cloud data exposure. Continuous configuration monitoring is therefore a detective control the RBI expects to see evidenced, not an optional maturity extra.
In Practice — IT Security
In Practice — IT Security

🚨 Concentration Risk, Incident Response and Exit

Three residual risks close the topic, and each has a direct exam angle.

Concentration risk arises when many banks — or many critical systems inside one bank — depend on the same provider or the same availability region. A single regional outage then becomes a systemic event. Mitigations include multi-region architecture, portability of workloads, avoiding deep dependence on one provider's proprietary services, and honest board-level reporting of the exposure. The thinking mirrors prudential limit-setting elsewhere in banking, which is why studying large exposure limits for banks alongside this topic makes the logic click: you cap dependence on any single counterparty, whether it supplies credit or compute.

Incident response in a shared environment needs pre-agreed roles. Who declares an incident? How does the bank obtain forensic images from infrastructure it does not own? Which contact channel operates at 2 a.m.? These are contract questions answered before the incident, not during it. Joint tabletop exercises with the provider are the evidence an auditor looks for.

Exit strategy is the clause banks most often skip and regulators most reliably ask about. A credible exit plan names the trigger events, estimates the cost and time to migrate, keeps data in a portable format, preserves a tested alternative — another provider or a return on-premises — and confirms certified destruction of residual copies, including backups and snapshots held by sub-contractors.

Practise these themes across the whole paper using the IT Security tag hub, and check current policy figures on the RBI rates and policy reference page instead of memorising numbers that move.

🧠 Practice MCQs: Cloud Security in Banks

Q1. Under RBI's Master Direction on Outsourcing of IT Services, which responsibility can a bank transfer to its cloud service provider? (a) Board oversight of the outsourcing policy (b) Accountability to the RBI for outsourced activity (c) Day-to-day operation of the hosting infrastructure (d) Compliance with applicable banking regulations

Answer: (c) — Operational activity may be outsourced; board oversight, regulatory compliance and accountability to the RBI remain with the bank.

Q2. In a pure SaaS arrangement, which control still rests with the bank? (a) Guest operating system patching (b) User identity, access rights and data classification (c) Hypervisor hardening (d) Application source-code security

Answer: (b) — Identity, access governance and data classification stay with the customer in every service model, including SaaS.

Q3. A bank notices a reportable cyber incident in its cloud environment. The six-hour reporting timeline it must respect arises from which instrument? (a) RBI IT Governance Direction, 2023 (b) Digital Personal Data Protection Act, 2023 (c) RBI IT Outsourcing Direction, 2023 (d) CERT-In Directions of April 2022

Answer: (d) — The six-hour clock is a CERT-In requirement; the RBI IT Directions of 2023 prescribe no fixed hour limit.

Q4. Which risk is best mitigated by designing workloads for portability across providers and regions? (a) Concentration risk (b) Insider threat (c) Key compromise (d) Phishing risk

Answer: (a) — Portability and multi-region design directly reduce dependence on a single provider or region, which is the essence of concentration risk.

Q5. Which clause most directly preserves the RBI's supervisory reach over a bank's cloud-hosted records? (a) Service-level penalty clause (b) Right-to-audit and inspection clause (c) Confidentiality clause (d) Force majeure clause

Answer: (b) — The right-to-audit clause extends inspection rights to the bank, its auditors and the regulator over the provider's premises and records.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Does RBI treat cloud adoption as outsourcing?

Yes. The Master Direction on Outsourcing of Information Technology Services, issued in April 2023, brings cloud computing arrangements within its scope, so the due diligence, contractual, monitoring, business continuity and exit requirements for IT outsourcing apply to cloud engagements.

Who is responsible if data is exposed by a misconfigured cloud storage bucket?

The bank. Configuration of storage, network rules and access permissions sits on the customer side of the shared responsibility model in IaaS and PaaS, and regulatory accountability for customer data never transfers to the provider.

Can a bank store customer data with a cloud provider outside India?

Only within the limits set by law and regulation. Payment system data must be stored in India under RBI's directive, CERT-In requires ICT logs to be maintained within India, and personal data transfers are governed by the Digital Personal Data Protection Act, 2023. Data location must be fixed contractually before migration.

What must a cloud exit strategy contain?

Defined trigger events, an estimate of migration cost and time, data held in a portable format, a tested alternative arrangement, termination assistance obligations on the provider, and certified deletion of all residual copies including backups held by sub-contractors.

✅ Key Takeaways and Next Step

Answer any cloud question in three moves: name the framework (RBI IT outsourcing and IT governance directions, CERT-In, DPDP Act), place the control on the correct side of the shared responsibility line, and close with the residual risks — concentration, incident coordination and exit. That structure fits almost every question the paper asks.

Now convert the reading into recall. Take a timed chapter test on the IIBF certification course pages, or jump straight into free IT Security mock tests and see which of these control families you actually remember under pressure.

Prefer revising from a printed book?

Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.

All books →
ITSEC 2026 Edition
IT Security

118 pages · 299 MCQs

Learning Sessions · Ashish Sir

IT Security 20 chapters · 299 MCQs ₹1,199₹2,39850% off
MSME 2026 Edition
Micro, Small and Medium Enterprises (MSME)

132 pages · 225 MCQs

Learning Sessions · Ashish Sir

Micro, Small and Medium Enterprises (MSME) 15 chapters · 225 MCQs ₹1,199₹2,39850% off
CCP 2026 Edition
Certified Credit Professional (CCP)

188 pages · 435 MCQs

Learning Sessions · Ashish Sir

Certified Credit Professional (CCP) 29 chapters · 435 MCQs ₹1,199₹2,39850% off
KYCAML 2026 Edition
KYC, AML and CFT

117 pages · 236 MCQs

Learning Sessions · Ashish Sir

KYC, AML and CFT 16 chapters · 236 MCQs ₹1,199₹2,39850% off
TIRM 2026 Edition
Treasury, Investment and Risk Management (TIRM)

Learning Sessions · Ashish Sir

Treasury, Investment and Risk Management (TIRM) ₹1,199₹2,39850% off
RFS 2026 Edition
Risk in Financial Services

Learning Sessions · Ashish Sir

Risk in Financial Services ₹1,199₹2,39850% off
SFB 2026 Edition
Small Finance Banks

Learning Sessions · Ashish Sir

Small Finance Banks ₹1,199₹2,39850% off
TREASURY 2026 Edition
Treasury Management

Learning Sessions · Ashish Sir

Treasury Management ₹1,199₹2,39850% off
NBFC 2026 Edition
Non-Banking Financial Companies (NBFC)

115 pages · 255 MCQs

Learning Sessions · Ashish Sir

Non-Banking Financial Companies (NBFC) 17 chapters · 255 MCQs ₹1,199₹2,39850% off
ITF 2026 Edition
International Trade Finance

Learning Sessions · Ashish Sir

International Trade Finance ₹1,199₹2,39850% off
CAAP 2026 Edition
Certified Accounting and Audit Professional (CAAP)

334 pages · 936 MCQs

Learning Sessions · Ashish Sir

Certified Accounting and Audit Professional (CAAP) 63 chapters · 936 MCQs ₹1,199₹2,39850% off
RM 2026 Edition
Risk Management

Learning Sessions · Ashish Sir

Risk Management ₹1,199₹2,39850% off
FEFI 2026 Edition
Foreign Exchange Facilities for Individuals (FEFI)

115 pages · 344 MCQs

Learning Sessions · Ashish Sir

Foreign Exchange Facilities for Individuals (FEFI) 24 chapters · 344 MCQs ₹1,199₹2,39850% off
IIBF 2026 Edition
Debt Recovery Agents (DRA)

107 pages · 240 MCQs

Learning Sessions · Ashish Sir

Debt Recovery Agents (DRA) 16 chapters · 240 MCQs ₹1,199₹2,39850% off
DIGIBANK 2026 Edition
Digital Banking

90 pages · 150 MCQs

Learning Sessions · Ashish Sir

Digital Banking 10 chapters · 150 MCQs ₹1,199₹2,39850% off
BCP 2026 Edition
Banking Compliance Professional

Learning Sessions · Ashish Sir

Banking Compliance Professional ₹1,199₹2,39850% off
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading