cyber security framework: RBI & CERT-In Exam Guide 2026
The cyber security framework governing Indian banks is one of the most heavily tested areas in the IIBF Prevention of Cyber Crime certification. Understanding how the Reserve Bank of India (RBI). The Indian Computer Emergency Response Team (CERT-In) together mandate.
Monitor. And enforce cyber hygiene across the banking sector is essential for both the exam. For practical banking careers.
The cyber security framework issued by the RBI in 2016 set baseline controls. Escalation procedures. And incident response obligations that every bank must follow. And the subsequent CERT-In directions of 2022 tightened reporting timelines dramatically. This comprehensive guide covers every pillar: the RBI 2016 circular.
Baseline security controls. Cyber Crisis Management Plan (CCMP). Mandatory CERT-In 6-hour incident reporting. Security Operations Centres (SOC), and the broader concept of cyber resilience.
Candidates preparing for this certification should bookmark the IIBF news feed on iibf.store for the latest regulatory updates, and supplement this guide with the Prevention of Cyber Crime mock tests to reinforce conceptual understanding with timed practice.
The RBI Cyber Security Framework 2016 — Origins and Scope
The cyber security framework for banks was formally established through the RBI circular dated 2 June 2016. Titled "Cyber Security Framework in Banks." This document. Issued under Section 35A of the Banking Regulation Act 1949.
Was the first comprehensive. Mandatory baseline specifically dedicated to cyber security for scheduled commercial banks (SCBs) in India. It emerged from a recognition that the earlier IT security guidelines.
Particularly the 2011 "Working Group on Information Security. Electronic Banking. Technology Risk Management and Cyber Frauds" report.
Needed to be upgraded into binding directions with defined minimum standards.
Why a Dedicated Framework Was Needed
Prior to 2016. Banks followed a patchwork of IT security advisories. The broad principles of the RBI's IT Framework for NBFCs and banks.
The Bangladesh Bank heist of February 2016. In which attackers used compromised SWIFT credentials to steal USD 81 million. Demonstrated that global banking infrastructure was vulnerable even in institutions with basic IT controls.
Indian banks, rapidly expanding digital channels, faced analogous risks. The RBI responded within months with a structured cyber security framework that moved beyond general IT governance into specific cyber security obligations.
Applicability and Compliance Responsibility
The 2016 framework applies to all scheduled commercial banks operating in India. Including foreign banks. The Board of Directors of each bank is required to approve a Cyber Security Policy distinct from the broader IT policy.
This separation is deliberate: cyber security has a distinct threat landscape. Distinct response timelines. And distinct stakeholder implications compared to routine IT service management.
The Chief Information Security Officer (CISO). Reporting to the Board or a senior executive no lower than the Chief Risk Officer. Is responsible for implementation.
Banks were required to submit a copy of their Board-approved Cyber Security Policy to the RBI.
Risk-Based Approach and Tiering
The framework acknowledges that a one-size-fits-all prescription would be unworkable across banks ranging from large public sector banks with thousands of branches to small payment banks and regional rural banks. Accordingly, banks are expected to implement controls proportionate to the nature and complexity of their operations, volume of digital transactions, and their assessed cyber risk profile. However, certain baseline controls are non-negotiable regardless of bank size — these form the floor of the cyber security framework. Explore related regulatory concepts on the iibf.store blog for a broader understanding of banking compliance.

Baseline Security Controls Under the RBI Framework
The cyber security framework specifies a set of baseline controls that all banks must implement as a minimum. These controls span technology architecture. Access management, data protection, network security, and monitoring.
For the IIBF exam. Candidates must know not just what these controls are. Also why each one addresses a specific category of cyber threat.
Network and Perimeter Security
Banks are required to maintain a secure network architecture with clear segregation between internet-facing systems (demilitarised zone or DMZ). The core banking network, and administrative management networks. Firewalls.
Intrusion detection and prevention systems (IDS/IPS). And web application firewalls (WAF) must be deployed and actively monitored. Network segmentation prevents a breach in one segment from cascading into critical systems.
A principle known as "defence in depth." Banks must also maintain an up-to-date inventory of all network devices. Applications. Since unmanaged assets are a common attack vector.
Patch Management and Vulnerability Assessment
The framework mandates a structured patch management programme: all operating systems. Middleware, and applications must be kept current with security patches. Critical patches must be applied within a defined timeframe (typically 30 days for critical.
90 days for medium severity). Banks must conduct Vulnerability Assessment and Penetration Testing (VAPT) at regular intervals. At least annually for the full environment.
More frequently for internet-facing applications. VAPT findings must be tracked to closure with defined remediation timelines. And the results must be reported to senior management.
Access Control and Privileged Access Management
Strict access control is a cornerstone of the baseline controls. Banks must implement the principle of least privilege. Users.
Systems should have only the minimum access necessary to perform their functions. Privileged Access Management (PAM) solutions are required for administrators who have elevated rights over critical systems. Including core banking, payment gateways, and SWIFT infrastructure.
Multi-factor authentication (MFA) is mandatory for all privileged access. For customer-facing digital banking channels. Shared or generic accounts must be eliminated.
Every access event must be attributable to a named individual for audit purposes.
Data Protection and Encryption
Sensitive data — including customer PII, authentication credentials, and financial transaction data — must be encrypted both in transit and at rest. Banks must implement a Data Loss Prevention (DLP) solution to detect and block unauthorized exfiltration of sensitive data. Backup data must be encrypted and stored separately from production systems, with offline or air-gapped copies maintained to ensure recoverability in the event of a ransomware attack. The RBI's framework aligns with global standards such as ISO 27001 and the NIST Cybersecurity Framework, references that the CERT-In official portal also cites for implementation guidance.
Cyber Security Awareness and Training
Technology controls alone cannot address the human element of cyber risk. The baseline requires banks to conduct mandatory cyber security awareness training for all staff at onboarding and at least annually thereafter. Special training must be provided to technology, operations, and customer-facing staff on phishing recognition, social engineering, and incident reporting procedures. Board members and senior management must receive periodic briefings on the evolving cyber threat landscape. Banks must also run phishing simulation exercises to test staff awareness under realistic conditions. Use the iibf.store match game to reinforce your recall of these specific control categories.

Cyber Crisis Management Plan (CCMP)
The Cyber Crisis Management Plan is a mandatory component of the cyber security framework for banks. A CCMP defines how an organisation detects. Escalates.
Contains. Eradicates. And recovers from a cyber crisis.
Distinguished from routine incident handling by its severity. Scale, and potential for systemic impact. The National Cyber Security Policy 2013.
Subsequent RBI guidance both emphasise the CCMP as the bridge between day-to-day security operations. Full business continuity activation.
What a CCMP Must Cover
A bank's CCMP must address the following elements in a structured document approved by the Board:
- Crisis classification: criteria that distinguish a cyber incident (routine) from a cyber crisis (escalated). Criteria include estimated financial impact. Number of customers affected. Media attention, and potential for contagion to other institutions.
- Crisis Management Team (CMT): named roles — typically the CEO. CISO. CTO. Head of Operations. General Counsel. And Head of Communications — with clearly defined decision-making authority. Alternates, and 24×7 contact details.
- Containment and isolation procedures: pre-authorised steps for isolating affected systems. Disabling compromised accounts. And invoking emergency change management processes without the usual approval delays.
- Communication protocols: internal escalation (Board. Senior management). Regulatory communication (RBI. CERT-In, NPCI as applicable), law enforcement coordination, and external communication (customers, media).
- Business continuity integration: triggers for invoking the Business Continuity Plan (BCP). Disaster Recovery Plan (DRP) from within the CCMP. Since a major cyber event may necessitate failover to the DR site.
- Post-crisis review: root cause analysis. Lessons-learned documentation, and regulatory reporting obligations after the crisis is resolved.
CCMP Testing and Drills
A CCMP that is never tested is a paper plan. The RBI expects banks to conduct tabletop exercises simulating realistic cyber crisis scenarios — such as a ransomware attack on core banking, a DDoS attack on internet banking, or a data breach affecting customer records — at least once a year. Full-scale simulation drills involving technical teams, management, and communication functions should be conducted periodically. Exercise findings must be documented and used to update the CCMP. The National Critical Information Infrastructure Protection Centre (NCIIPC) also coordinates sector-wide cyber crisis exercises in which banks are encouraged to participate. Candidates can track such regulatory exercises through the RBI regulatory updates tracker.
CCMP and the RBI's Supervisory Review
The RBI assesses CCMP adequacy during its Annual Financial Inspection (AFI). Thematic IT examinations. Banks that lack a Board-approved CCMP.
Have not tested it. Or cannot demonstrate that CMT members are aware of their roles can face adverse supervisory findings. Directions under Section 35A.
The CCMP is also a prerequisite for certain RBI approvals — for example. Banks seeking permission to launch new digital products may be asked to demonstrate that their CCMP covers the risks of the proposed product.

CERT-In 2022 Directions — Mandatory 6-Hour Incident Reporting
The cyber security framework landscape in India was significantly tightened when the Ministry of Electronics. Information Technology (MeitY) issued the CERT-In Directions on 28 April 2022. Effective 27 June 2022.
These directions. Issued under Section 70B(6) of the Information Technology Act 2000. Introduced one of the strictest incident reporting timelines in the world: a mandatory 6-hour window for reporting specified cyber incidents to CERT-In.
Who Must Report and What Must Be Reported
The CERT-In 2022 directions apply to all entities in India — including banks. Financial institutions. Intermediaries, data centres, cloud service providers, and virtual private server providers.
For banks. The directions overlap with. Go beyond the RBI's existing incident reporting requirements.
The categories of incidents that trigger the 6-hour reporting obligation include:
- Targeted scanning or probing of critical networks or systems.
- Compromise of critical systems including operational technology (OT). Industrial Control Systems (ICS).
- Unauthorised access to IT systems, data, or applications.
- Defacement of websites or intrusion into websites and unauthorised changes to content.
- Attacks on servers such as database, mail, and DNS.
- Identity theft, spoofing, and phishing attacks.
- Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks.
- Attacks on critical infrastructure, SCADA, and OT systems.
- Attacks on internet of things (IoT) devices and related systems.
- Data breaches and data leaks.
- Attacks on digital payment systems.
- Malicious code attacks such as spreading viruses, worms, Trojans, ransomware, spyware, etc.
- Fake mobile applications impersonating banking and financial services.
- Attacks or incidents affecting cloud computing systems, servers, software, applications.
The 6-Hour Clock and Reporting Format
The 6-hour countdown begins from the moment the entity becomes aware of the incident. Not from when the incident actually occurred. This distinction is critical for exam purposes. Entities must submit an initial report within 6 hours. This initial report may be a preliminary notification with whatever information is available at that time.
A more detailed final report must follow within 5 days. Reports are submitted through the CERT-In incident reporting portal. Failure to report within the 6-hour window is treated as non-compliance. Can attract penalties under Section 70B of the IT Act.
Additional Obligations Under the 2022 Directions
Beyond incident reporting. The 2022 CERT-In directions impose several other obligations that directly impact banks' cyber security framework:
- Log retention: all ICT systems must maintain logs of all ICT activity in India. Securely, for a rolling period of 180 days. Logs must be maintained within Indian jurisdiction. Must be provided to CERT-In upon requisition.
- Synchronised clocks: all systems must synchronise their clocks with the National Physical Laboratory (NPL) or National Information Centre (NIC) network time protocol (NTP) servers. This is essential for accurate forensic reconstruction of incident timelines.
- KYC for virtual private networks. Cloud services: VPN service providers. Cloud providers must maintain accurate subscriber records including names. Validated addresses. Contact numbers. IP addresses. And purposes of use for a period of 5 years after any cancellation. Banks using third-party VPN or cloud services must ensure their providers comply.
Stay current on CERT-In advisory updates through the IIBF news page, which aggregates key regulatory cyber security notifications relevant to banking exam candidates.
Security Operations Centre (SOC) and Cyber Resilience
The cyber security framework envisions a Security Operations Centre (SOC) as the nerve centre for real-time cyber monitoring. Response in every major bank. The SOC concept goes beyond reactive incident handling.
It embodies the principle of continuous monitoring. Threat intelligence integration. And proactive threat hunting that defines a mature cyber resilience posture.
What a Bank SOC Does
A bank SOC is a 24×7 operational facility — staffed by security analysts. Threat intelligence professionals. And incident responders — that continuously monitors the bank's networks. Endpoints, applications, and transaction channels for anomalous or malicious activity. Key SOC functions include:
- Security Information. Event Management (SIEM): aggregating logs from all systems into a centralised platform that applies correlation rules. Machine learning algorithms to detect suspicious patterns. SIEM is the technological backbone of the SOC.
- Threat intelligence: subscribing to internal. External threat intelligence feeds (including the Financial Services-ISAC. CERT-In advisories) to stay ahead of emerging attack techniques. Indicators of compromise (IoCs), and threat actors targeting the banking sector.
- Incident triage. Response: investigating alerts generated by SIEM and other detection tools. Determining whether they represent genuine threats. And escalating confirmed incidents to the Incident Response (IR) team for containment. Eradication.
- Vulnerability. Threat hunting: proactively searching for signs of adversary presence in the network that may not yet have triggered automated alerts. Particularly important for detecting advanced persistent threats (APTs).
- Fraud correlation: in banks. The SOC often operates alongside the fraud operations team to correlate cyber indicators with transactional fraud patterns. Enabling earlier detection of account takeovers and payment fraud.
- IIBF International Trade Finance Study Material Pdf
- Prevention Of Cyber Crime And Fraud Management IIBF Book Pdf
- CAIIB
- CAIIB Hrm Syllabus
- BRBL CAIIB Syllabus
- CAIIB Exam
- Protection To Paying Banker
- ABFM CAIIB
- Locker Rules
In-House vs. Managed SOC
Small. Mid-sized banks may not have the resources to build a fully staffed in-house SOC. The RBI framework permits banks to outsource SOC services to a Managed Security Service Provider (MSSP). Provided that the outsourcing arrangement complies with the RBI's IT Outsourcing Guidelines.
Data is not taken offshore without appropriate controls. And the bank retains ultimate responsibility for the security posture. Banks using shared SOC services must ensure contractual obligations regarding incident reporting timelines.
Especially the CERT-In 6-hour rule — are flowed down to the MSSP. For IIBF exam purposes. Remember that outsourcing does not outsource accountability: the bank's Board remains responsible.
Cyber Resilience — Beyond Cyber Security
Cyber resilience is a broader concept than cyber security. While cyber security focuses on preventing incidents. Cyber resilience acknowledges that some incidents are inevitable.
Focuses on the bank's capacity to withstand. Adapt to. And recover rapidly from cyber events without unacceptable disruption to critical business functions.
The RBI's cyber security framework embeds resilience principles through three requirements:
- Recovery Time Objectives (RTO). Recovery Point Objectives (RPO): banks must define. Test RTO/RPO for all critical systems. Digital banking systems typically require RTOs of hours rather than days.
- Resilient architecture: active-active or active-passive redundant data centres. With geographically separated primary and disaster recovery sites. The RBI mandates that the DR site be at a minimum geographic distance from the primary site to prevent both sites from being affected by a single regional disaster.
- Cyber resilience testing: banks must conduct cyber resilience exercises including Red Team assessments (simulated real-world attacks by ethical hackers attempting to breach systems end-to-end). Participate in CERT-In and sector-wide exercises. Red Team assessments go beyond standard VAPT and test the people. Processes, and technology of the bank's defences under realistic adversary simulation.
The CAIIB course on iibf.store covers IT risk management extensively — many of the SOC and resilience concepts appear across both the CAIIB Information Technology paper and the IIBF Prevention of Cyber Crime certification, making cross-study highly efficient.
Frequently Asked Questions
What is the RBI Cyber Security Framework 2016 and which banks does it apply to?
The RBI Cyber Security Framework 2016 is a mandatory set of cyber security directions issued by the Reserve Bank of India through a circular dated 2 June 2016. Under Section 35A of the Banking Regulation Act 1949. It applies to all scheduled commercial banks operating in India. Including foreign banks.
The framework requires each bank to have a Board-approved Cyber Security Policy distinct from its IT policy. Appoint a Chief Information Security Officer (CISO). Implement baseline technical controls (network segmentation.
Patch management. Access control. Encryption.
VAPT). Establish a Security Operations Centre. Maintain a Cyber Crisis Management Plan.
And report cyber incidents to the RBI. The framework adopts a risk-based approach. With baseline controls mandatory for all banks.
Additional controls proportionate to the bank's digital footprint and risk profile.
What are the CERT-In 2022 directions and what is the 6-hour incident reporting rule?
The CERT-In Directions 2022 were issued by the Ministry of Electronics. Information Technology (MeitY) on 28 April 2022. Effective 27 June 2022, under Section 70B(6) of the Information Technology Act 2000.
They require all entities operating in India. Including banks. To report specified cyber incidents to CERT-In within 6 hours of becoming aware of the incident.
The 6-hour clock starts from awareness. Not from the time the incident occurred. An initial report must be filed within 6 hours. A detailed final report must follow within 5 days. Additional obligations include maintaining ICT logs for 180 days.
Synchronising all system clocks with NPL/NIC NTP servers. And ensuring VPN/cloud service providers maintain subscriber records for 5 years. Non-compliance can attract penalties under the IT Act.
What is a Cyber Crisis Management Plan (CCMP) and why is it different from an Incident Response Plan?
A Cyber Crisis Management Plan (CCMP) is a Board-approved document that defines how a bank responds to cyber events that rise to the level of a crisis. Characterised by significant financial impact. Large-scale customer disruption, regulatory attention, or systemic risk.
It is distinct from a routine Incident Response Plan (IRP) in scope. Authority: the CCMP activates a senior Crisis Management Team (including the CEO. Board representatives).
Triggers integration with Business Continuity and Disaster Recovery plans. And governs regulatory and external communications. An IRP handles day-to-day security incidents within the IT/CISO function.
In exam terms: an incident is handled by the SOC. IR team under the IRP. A crisis escalates to the CMT under the CCMP.
Banks must test their CCMP through tabletop exercises at least annually.
What is the role of a Security Operations Centre (SOC) in a bank's cyber security framework?
A Security Operations Centre (SOC) is a 24×7 monitoring. Response facility that forms the operational core of a bank's cyber security framework. It aggregates logs.
Alerts from across the bank's IT environment using a SIEM platform. Applies threat intelligence to detect malicious activity. Triages and investigates alerts, and coordinates incident response.
The SOC also conducts proactive threat hunting to detect advanced persistent threats that have evaded automated detection. Banks can operate an in-house SOC or outsource to a Managed Security Service Provider (MSSP). But the bank's Board retains full accountability for the security posture regardless of the delivery model.
For the IIBF exam. Key SOC components to remember are SIEM. Threat intelligence feeds, incident response, and fraud correlation capabilities.
Key Takeaways and Exam Preparation
The cyber security framework for Indian banks is a multi-layered regulatory architecture anchored by the RBI 2016 circular. Reinforced by the CERT-In 2022 directions. For the IIBF Prevention of Cyber Crime certification.
The key themes to master are: the structure. Mandatory elements of the RBI framework (Board policy. CISO.
Baseline controls. SOC. CCMP); the specific baseline controls (network segmentation.
VAPT. PAM. DLP.
Encryption. Awareness training). The CCMP structure and testing requirements.
The CERT-In 6-hour reporting rule. The full list of reportable incident categories. Additional CERT-In 2022 obligations (180-day log retention.
NTP synchronisation. VPN KYC). The distinction between cyber security (prevention) and cyber resilience (recovery).
And the SOC's role in continuous monitoring and incident response.
The progression from detection to response to recovery — SOC detects, CCMP escalates, BCP/DRP recovers — is the operational backbone of this framework. For deeper study, refer to the authoritative source: the Reserve Bank of India's official website hosts the full text of the 2016 Cyber Security Framework circular and subsequent updates under the "Notifications" section. Pair this regulatory reading with the IIBF Prevention of Cyber Crime practice tests on iibf.store to convert regulatory knowledge into exam-ready recall. With consistent practice, the framework's layers — RBI baseline, CCMP, CERT-In reporting, SOC, and cyber resilience — will become second nature before exam day.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Use the free tests to check what you know.
Watch the video if a part feels hard.
Do a bit each day.
Ask us on WhatsApp if you get stuck.
You can pass this exam.
Stay calm and trust your prep.
Come back to this guide often.
Small steps add up fast.
Skim the box below first.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Watch the video if a part feels hard.
Do a bit each day.
Ask us on WhatsApp if you get stuck.
You can pass this exam.
Stay calm and trust your prep.
Come back to this guide often.
Small steps add up fast.
Skim the box below first.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Watch the video if a part feels hard.
Do a bit each day.
Ask us on WhatsApp if you get stuck.
You can pass this exam.
Stay calm and trust your prep.
Come back to this guide often.
Small steps add up fast.
Skim the box below first.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Watch the video if a part feels hard.
Do a bit each day.
Ask us on WhatsApp if you get stuck.
You can pass this exam.
Stay calm and trust your prep.
Come back to this guide often.
Small steps add up fast.
Skim the box below first.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.