RBI Cyber Security Framework for Banks: CAIIB ITDB Guide (2026)
The RBI Cyber Security Framework is the single most tested regulatory topic in the CAIIB ITDB elective, and for good reason. Issued by the Reserve Bank of India on 2 June 2016 (circular DBS.CO/CSITE/BC.11/33.01.001/2015-16), it made a board-approved cyber security policy mandatory for every scheduled commercial bank and reshaped how banks defend their core systems. If you understand the RBI Cyber Security Framework — its baseline controls, the Cyber Crisis Management Plan, the incident-reporting clock and the graded approach for cooperative banks — you can comfortably clear the security-heavy questions in Module C and Module D. This guide breaks it down the way examiners frame it, with a comparison table, exam tips and practice MCQs.
🛡️ What the RBI Cyber Security Framework Actually Requires
The 2016 framework was RBI's response to a sharp rise in card fraud, ATM malware and phishing losses. Its core insight is simple: cyber security is not the same as IT security. RBI directed every bank to put in place a distinct, board-approved Cyber Security Policy, separate from the broader IT or Information Security (IS) policy, so that cyber risk gets independent board attention rather than being buried inside general IT governance. Banks were told to first carry out a gap assessment against RBI's baseline requirements, then draw up a time-bound plan to close those gaps urgently.
The framework rests on three pillars. First, prevention — hardening networks, endpoints and databases so intrusions are harder. Second, detection — continuous, near-real-time surveillance so an attack is spotted quickly, not months later. Third, response and recovery — containing the fallout and restoring service. RBI deliberately assumed breaches are inevitable; the test of a bank is how fast it detects and recovers. This mindset, drawn from RBI's earlier work on information systems in banking, is why the framework stresses resilience over a false promise of perfect security. For exam purposes, remember it applies to the bank's entire IT environment, including services outsourced to third-party vendors.
💡 Exam Tip: The Cyber Security Policy must be separate from the IT/IS Security Policy and approved by the Board — not merely by IT management. This distinction is a favourite one-mark trap in CAIIB ITDB.
🔐 Baseline Controls and the Annexures
RBI's circular attached indicative baseline cyber security and resilience requirements (Annex 1) plus a template for reporting cyber incidents (Annex 3). The baseline is a checklist of controls every bank must implement regardless of size. These include inventory management of business IT assets, preventing execution of unauthorised software (application whitelisting), environmental controls, network management and security, secure configuration, anti-malware, patch and vulnerability management, user access controls, secure email and browser settings, and data leak prevention. The philosophy borrows heavily from established computer security controls such as least-privilege access and defence-in-depth.
Two baseline expectations get tested often. One, continuous surveillance: banks must arrange near-real-time monitoring, typically through a Security Operations Centre (SOC or C-SOC) that ingests logs, detects anomalies and raises alerts round the clock. Two, vulnerability assessment and penetration testing (VAPT) carried out periodically, with critical findings remediated promptly. RBI expects the cyber posture to keep pace with emerging technologies like cloud, mobile and API-driven services, since each new channel widens the attack surface. A crucial nuance: RBI held that the responsibility for cyber security cannot be outsourced — a bank remains accountable even when a managed service provider runs its SOC.
⚠️ Common Mistake: Candidates assume a bank can transfer cyber-risk liability to its IT vendor. RBI is explicit that accountability stays with the bank's board even when operations are outsourced.

🚨 Cyber Crisis Management Plan and the 2–6 Hour Reporting Clock
Beyond prevention, RBI mandated that each bank adopt a Cyber Crisis Management Plan (CCMP) addressing the four dimensions of Detection, Response, Recovery and Containment. The CCMP should be crafted using inputs from CERT-In, IDRBT and the National Critical Information Infrastructure Protection Centre (NCIIPC). It defines who does what during a live attack — a ransomware outbreak, an ATM cash-out, a data breach — so the bank is not improvising under pressure.
The most frequently examined number is the incident-reporting timeline. Under the framework, banks must report unusual cyber-security incidents to RBI (Department of Supervision / CSITE Cell) within 2 to 6 hours of detection. Separately, CERT-In's 2022 directions require reporting specified incidents within 6 hours of noticing them. Banks must also share information on cyber incidents with RBI to help build sector-wide threat intelligence. This overlaps neatly with governance topics such as the SDLC controls in banking IT projects, where secure development reduces the very defects attackers exploit. Boards must review cyber preparedness periodically, and a senior official — often the Chief Information Security Officer (CISO) — owns the framework's execution.
📌 Remember: Two clocks — report to RBI within 2–6 hours and to CERT-In within 6 hours. Mixing these up is the most common ITDB error on incident-reporting questions.
🏦 The Graded Approach for Cooperative Banks and 2026 Updates
The 2016 framework targeted commercial banks, but RBI extended cyber discipline to Urban Cooperative Banks (UCBs) through a graded, four-level approach issued on 31 December 2019. Controls scale with a bank's digital footprint: a small UCB with only basic connectivity sits at Level I with baseline controls, while a UCB offering internet banking, mobile banking and payment gateways sits at Level IV with the heaviest obligations, including a dedicated SOC and advanced real-time monitoring. This proportionate design ensures small banks are not crushed by enterprise-grade mandates while systemically important ones face stricter scrutiny.
For 2026 currency, note that RBI has layered newer directions on top of the 2016 base. The Master Direction on IT Governance, Risk, Controls and Assurance Practices (issued November 2023, effective 1 April 2024) consolidated IT and cyber governance expectations, mandating an IT Strategy Committee and strengthening the CISO's role. The Master Directions on Cyber Resilience and Digital Payment Security Controls (2024) tightened controls for payment system operators. Together these keep the framework current against threats to digital signature and PKI infrastructure. Strong cyber controls also reinforce broader prudential goals — a large breach is an operational-risk event, linking this topic to risk mitigation techniques in banks. Explore more revision notes on the ITDB topic hub.

📊 RBI Cyber Security Framework: Key Directions at a Glance
| Requirement | 2016 Framework (SCBs) | UCB Level I | UCB Level IV |
|---|---|---|---|
| Board-approved Cyber Security Policy | ✔ Mandatory | ✔ Mandatory | ✔ Mandatory |
| Cyber Crisis Management Plan (CCMP) | ✔ Yes | ✔ Yes | ✔ Yes |
| Dedicated Security Operations Centre (SOC) | ✔ Expected | ✘ Not required | ✔ Required |
| Periodic VAPT | ✔ Yes | Basic | ✔ Advanced |
| Incident reporting to RBI | 2–6 hours | 2–6 hours | 2–6 hours |
| Real-time / continuous surveillance | ✔ Yes | ✘ Limited | ✔ Yes |
Use this grid to answer "which control applies to whom" questions. The graded logic — heavier controls for greater digital depth — is itself a common conceptual MCQ. Build your speed on these facts with full-length mocks on iibf.store tests and the structured CAIIB course.

🧠 Practice MCQs: RBI Cyber Security Framework
Q1. As per RBI's 2016 framework, the Cyber Security Policy must be approved by whom? (a) IT Head (b) CISO (c) Board of Directors (d) RBI
Answer: (c) — RBI requires a distinct Cyber Security Policy approved by the bank's Board, separate from the IT/IS policy.
Q2. Within what time must banks report a cyber-security incident to RBI under the framework? (a) 24 hours (b) 2 to 6 hours (c) 48 hours (d) 7 days
Answer: (b) — Unusual cyber-security incidents must be reported to RBI within 2 to 6 hours of detection.
Q3. The four dimensions addressed by a Cyber Crisis Management Plan are Detection, Response, Recovery and: (a) Reporting (b) Containment (c) Audit (d) Insurance
Answer: (b) — The CCMP covers Detection, Response, Recovery and Containment.
Q4. RBI's graded cyber security approach for UCBs (2019) has how many levels? (a) Two (b) Three (c) Four (d) Five
Answer: (c) — The graded approach classifies UCBs into four levels based on their digital depth.
Q5. Under RBI's stance, responsibility for cyber security when operations are outsourced: (a) shifts to the vendor (b) is shared equally (c) remains with the bank (d) shifts to RBI
Answer: (c) — Accountability for cyber security cannot be outsourced; it stays with the bank's board.
Want chapter-wise mock tests with 100+ MCQs? Start practising free
❓ Frequently Asked Questions
Authoritative reference: see the latest guidelines on the Reserve Bank of India website and the IIBF syllabus portal.
When was the RBI Cyber Security Framework issued?
It was issued on 2 June 2016 via circular DBS.CO/CSITE/BC.11/33.01.001/2015-16, applicable to all scheduled commercial banks.
How is a Cyber Security Policy different from an IT Security Policy?
RBI requires the Cyber Security Policy to be a distinct, board-approved document focused on cyber threats, separate from the broader IT/IS security policy, so cyber risk gets independent board oversight.
What is a Cyber Crisis Management Plan (CCMP)?
The CCMP is a board-mandated plan covering Detection, Response, Recovery and Containment of cyber incidents, prepared using inputs from CERT-In, IDRBT and NCIIPC.
Does the 2016 framework still apply in 2026?
Yes. It remains the foundation, now reinforced by the Master Direction on IT Governance (effective April 2024) and the 2024 Cyber Resilience and Digital Payment Security Controls directions.
Master this high-yield topic and lock in easy marks: attempt a timed ITDB mock on our free test series or follow the full syllabus in the CAIIB preparation course.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.