RBI Cyber Security Framework for Banks: CAIIB ITDB Guide (2026)

CAIIB By Ashish Jain · IIBF STORE Editorial · 25 July 2026 · Updated 25 Jul 2026 · 8 min read हिन्दी में पढ़ें
RBI Cyber Security Framework for Banks: CAIIB ITDB Guide (2026)

The RBI Cyber Security Framework is the single most tested regulatory topic in the CAIIB ITDB elective, and for good reason. Issued by the Reserve Bank of India on 2 June 2016 (circular DBS.CO/CSITE/BC.11/33.01.001/2015-16), it made a board-approved cyber security policy mandatory for every scheduled commercial bank and reshaped how banks defend their core systems. If you understand the RBI Cyber Security Framework — its baseline controls, the Cyber Crisis Management Plan, the incident-reporting clock and the graded approach for cooperative banks — you can comfortably clear the security-heavy questions in Module C and Module D. This guide breaks it down the way examiners frame it, with a comparison table, exam tips and practice MCQs.

🛡️ What the RBI Cyber Security Framework Actually Requires

The 2016 framework was RBI's response to a sharp rise in card fraud, ATM malware and phishing losses. Its core insight is simple: cyber security is not the same as IT security. RBI directed every bank to put in place a distinct, board-approved Cyber Security Policy, separate from the broader IT or Information Security (IS) policy, so that cyber risk gets independent board attention rather than being buried inside general IT governance. Banks were told to first carry out a gap assessment against RBI's baseline requirements, then draw up a time-bound plan to close those gaps urgently.

The framework rests on three pillars. First, prevention — hardening networks, endpoints and databases so intrusions are harder. Second, detection — continuous, near-real-time surveillance so an attack is spotted quickly, not months later. Third, response and recovery — containing the fallout and restoring service. RBI deliberately assumed breaches are inevitable; the test of a bank is how fast it detects and recovers. This mindset, drawn from RBI's earlier work on information systems in banking, is why the framework stresses resilience over a false promise of perfect security. For exam purposes, remember it applies to the bank's entire IT environment, including services outsourced to third-party vendors.

💡 Exam Tip: The Cyber Security Policy must be separate from the IT/IS Security Policy and approved by the Board — not merely by IT management. This distinction is a favourite one-mark trap in CAIIB ITDB.

🔐 Baseline Controls and the Annexures

RBI's circular attached indicative baseline cyber security and resilience requirements (Annex 1) plus a template for reporting cyber incidents (Annex 3). The baseline is a checklist of controls every bank must implement regardless of size. These include inventory management of business IT assets, preventing execution of unauthorised software (application whitelisting), environmental controls, network management and security, secure configuration, anti-malware, patch and vulnerability management, user access controls, secure email and browser settings, and data leak prevention. The philosophy borrows heavily from established computer security controls such as least-privilege access and defence-in-depth.

Two baseline expectations get tested often. One, continuous surveillance: banks must arrange near-real-time monitoring, typically through a Security Operations Centre (SOC or C-SOC) that ingests logs, detects anomalies and raises alerts round the clock. Two, vulnerability assessment and penetration testing (VAPT) carried out periodically, with critical findings remediated promptly. RBI expects the cyber posture to keep pace with emerging technologies like cloud, mobile and API-driven services, since each new channel widens the attack surface. A crucial nuance: RBI held that the responsibility for cyber security cannot be outsourced — a bank remains accountable even when a managed service provider runs its SOC.

⚠️ Common Mistake: Candidates assume a bank can transfer cyber-risk liability to its IT vendor. RBI is explicit that accountability stays with the bank's board even when operations are outsourced.
Key Concepts — Information Technology and Digital Banking (Elective)
Key Concepts — Information Technology and Digital Banking (Elective)

🚨 Cyber Crisis Management Plan and the 2–6 Hour Reporting Clock

Beyond prevention, RBI mandated that each bank adopt a Cyber Crisis Management Plan (CCMP) addressing the four dimensions of Detection, Response, Recovery and Containment. The CCMP should be crafted using inputs from CERT-In, IDRBT and the National Critical Information Infrastructure Protection Centre (NCIIPC). It defines who does what during a live attack — a ransomware outbreak, an ATM cash-out, a data breach — so the bank is not improvising under pressure.

The most frequently examined number is the incident-reporting timeline. Under the framework, banks must report unusual cyber-security incidents to RBI (Department of Supervision / CSITE Cell) within 2 to 6 hours of detection. Separately, CERT-In's 2022 directions require reporting specified incidents within 6 hours of noticing them. Banks must also share information on cyber incidents with RBI to help build sector-wide threat intelligence. This overlaps neatly with governance topics such as the SDLC controls in banking IT projects, where secure development reduces the very defects attackers exploit. Boards must review cyber preparedness periodically, and a senior official — often the Chief Information Security Officer (CISO) — owns the framework's execution.

📌 Remember: Two clocks — report to RBI within 2–6 hours and to CERT-In within 6 hours. Mixing these up is the most common ITDB error on incident-reporting questions.

🏦 The Graded Approach for Cooperative Banks and 2026 Updates

The 2016 framework targeted commercial banks, but RBI extended cyber discipline to Urban Cooperative Banks (UCBs) through a graded, four-level approach issued on 31 December 2019. Controls scale with a bank's digital footprint: a small UCB with only basic connectivity sits at Level I with baseline controls, while a UCB offering internet banking, mobile banking and payment gateways sits at Level IV with the heaviest obligations, including a dedicated SOC and advanced real-time monitoring. This proportionate design ensures small banks are not crushed by enterprise-grade mandates while systemically important ones face stricter scrutiny.

For 2026 currency, note that RBI has layered newer directions on top of the 2016 base. The Master Direction on IT Governance, Risk, Controls and Assurance Practices (issued November 2023, effective 1 April 2024) consolidated IT and cyber governance expectations, mandating an IT Strategy Committee and strengthening the CISO's role. The Master Directions on Cyber Resilience and Digital Payment Security Controls (2024) tightened controls for payment system operators. Together these keep the framework current against threats to digital signature and PKI infrastructure. Strong cyber controls also reinforce broader prudential goals — a large breach is an operational-risk event, linking this topic to risk mitigation techniques in banks. Explore more revision notes on the ITDB topic hub.

Process & Framework — Information Technology and Digital Banking (Elective)
Process & Framework — Information Technology and Digital Banking (Elective)

📊 RBI Cyber Security Framework: Key Directions at a Glance

Requirement2016 Framework (SCBs)UCB Level IUCB Level IV
Board-approved Cyber Security Policy✔ Mandatory✔ Mandatory✔ Mandatory
Cyber Crisis Management Plan (CCMP)✔ Yes✔ Yes✔ Yes
Dedicated Security Operations Centre (SOC)✔ Expected✘ Not required✔ Required
Periodic VAPT✔ YesBasic✔ Advanced
Incident reporting to RBI2–6 hours2–6 hours2–6 hours
Real-time / continuous surveillance✔ Yes✘ Limited✔ Yes

Use this grid to answer "which control applies to whom" questions. The graded logic — heavier controls for greater digital depth — is itself a common conceptual MCQ. Build your speed on these facts with full-length mocks on iibf.store tests and the structured CAIIB course.

In Practice — Information Technology and Digital Banking (Elective)
In Practice — Information Technology and Digital Banking (Elective)

🧠 Practice MCQs: RBI Cyber Security Framework

Q1. As per RBI's 2016 framework, the Cyber Security Policy must be approved by whom? (a) IT Head (b) CISO (c) Board of Directors (d) RBI

Answer: (c) — RBI requires a distinct Cyber Security Policy approved by the bank's Board, separate from the IT/IS policy.

Q2. Within what time must banks report a cyber-security incident to RBI under the framework? (a) 24 hours (b) 2 to 6 hours (c) 48 hours (d) 7 days

Answer: (b) — Unusual cyber-security incidents must be reported to RBI within 2 to 6 hours of detection.

Q3. The four dimensions addressed by a Cyber Crisis Management Plan are Detection, Response, Recovery and: (a) Reporting (b) Containment (c) Audit (d) Insurance

Answer: (b) — The CCMP covers Detection, Response, Recovery and Containment.

Q4. RBI's graded cyber security approach for UCBs (2019) has how many levels? (a) Two (b) Three (c) Four (d) Five

Answer: (c) — The graded approach classifies UCBs into four levels based on their digital depth.

Q5. Under RBI's stance, responsibility for cyber security when operations are outsourced: (a) shifts to the vendor (b) is shared equally (c) remains with the bank (d) shifts to RBI

Answer: (c) — Accountability for cyber security cannot be outsourced; it stays with the bank's board.

Want chapter-wise mock tests with 100+ MCQs? Start practising free

❓ Frequently Asked Questions

Authoritative reference: see the latest guidelines on the Reserve Bank of India website and the IIBF syllabus portal.

When was the RBI Cyber Security Framework issued?

It was issued on 2 June 2016 via circular DBS.CO/CSITE/BC.11/33.01.001/2015-16, applicable to all scheduled commercial banks.

How is a Cyber Security Policy different from an IT Security Policy?

RBI requires the Cyber Security Policy to be a distinct, board-approved document focused on cyber threats, separate from the broader IT/IS security policy, so cyber risk gets independent board oversight.

What is a Cyber Crisis Management Plan (CCMP)?

The CCMP is a board-mandated plan covering Detection, Response, Recovery and Containment of cyber incidents, prepared using inputs from CERT-In, IDRBT and NCIIPC.

Does the 2016 framework still apply in 2026?

Yes. It remains the foundation, now reinforced by the Master Direction on IT Governance (effective April 2024) and the 2024 Cyber Resilience and Digital Payment Security Controls directions.

Master this high-yield topic and lock in easy marks: attempt a timed ITDB mock on our free test series or follow the full syllabus in the CAIIB preparation course.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

Information Technology and Digital Banking (Elective) · 5 questions · instant result
Q1. A treasury officer describes RTGS to a new recruit as a system where each customer instruction is settled one-by-one the moment it is received, without bundling it with other instructions. Which feature of RTGS is being described?
Q2. A bank decides to levy the maximum RTGS processing charge permitted by RBI, which the chapter states is capped at ₹50 per transaction. A corporate customer puts through 8 separate RTGS outward remittances in a single day. Ignoring taxes, what is the maximum processing charge the bank can levy for that day?
Q3. A customer needs to send ₹9,00,000 to a vendor immediately during banking hours and wants the funds credited to the beneficiary instantly rather than waiting for a batch cycle. Which is the best channel to recommend?
Q4. A trainee is asked to state the most accurate distinction between a Net Settlement System and a Gross Settlement System. Which statement is most accurate?
Q5. A daily-wage worker without a smartphone wants to withdraw cash and check balance at a banking correspondent point using only his Aadhaar number and biometric authentication. Which NPCI-supported system enables this?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading