RBI Cybersecurity Framework for Banks: An IIBF Guide
Every bank in India today runs on rails that are digital first, and that shift is exactly why the RBI cybersecurity framework for banks sits at the centre of the IIBF Prevention of Cyber Crime syllabus. Introduced through RBI's June 2016 circular on Cyber Security Framework in Banks and tightened by subsequent master directions, the framework is not a single rulebook but a layered set of expectations covering governance, technology controls, incident reporting and continuous audit. For candidates, understanding how these layers connect matters more than memorising a single circular number, because exam questions routinely test the "why" behind each requirement rather than just the "what". This article walks through the framework's building blocks, the reporting chain to CERT-In, the technical controls examiners love to test, and the practice questions that mirror the real paper.
🛡️ What Is the RBI Cybersecurity Framework for Banks
At its core, the RBI cybersecurity framework for banks asks every bank's board to treat cyber risk as a business risk, not an IT problem parked with the technology team. The circular mandates a board-approved cybersecurity policy, distinct from the bank's general IT policy, that spells out the institution's risk appetite, its inherent risk profile and the controls it will run to close the gap between the two. This risk-based, proportionate approach means a small urban cooperative bank and a large private bank are held to the same governance principle even though their control intensity differs. Students often confuse "IT policy" with "cybersecurity policy" — the exam frequently probes this distinction directly, so it is worth reading the Introduction To Cyber Crimes chapter alongside this framework to see how threat categories map onto policy clauses. The framework also introduces the idea of an inherent-risk-versus-residual-risk assessment, requiring banks to self-rate their exposure across categories such as technology adoption, delivery channels, and online/mobile footprint, and then demonstrate that controls bring residual risk down to an acceptable level. Because the underlying vulnerabilities driving this framework — weak patching, poor configuration management, unmonitored privileged access — are the same ones covered in the Computer Insecurity chapter, examiners often link a governance question with a technical-control question in the same case study, so treat the two topics as one continuous thread rather than separate silos.
💡 Exam Tip: Whenever a question mentions "board-approved" or "senior management oversight," it is almost always testing the RBI cybersecurity framework's governance layer, not a generic IT security concept.
🏛️ Board-Approved Policy, Governance and the Cyber Security Operations Centre
Governance under the RBI cybersecurity framework for banks is anchored by three linked artefacts: the board-approved cybersecurity policy, a Cyber Crisis Management Plan (CCMP), and a functioning Cyber Security Operations Centre (C-SOC) that provides round-the-clock monitoring. The CCMP is deliberately structured around four verbs — detect, respond, recover, contain — and banks are expected to rehearse this cycle through periodic drills rather than leave it as a paper document. A C-SOC's job is to correlate logs from firewalls, endpoint agents, application servers and network devices so that anomalies are flagged in near real time instead of being discovered days later during a routine audit. This operational backbone is what ties governance to the day-to-day work covered in the Incident Management chapter, since a C-SOC alert is usually the trigger event that starts the incident-management workflow. The framework also requires banks to appoint or designate a Chief Information Security Officer (CISO) who reports independently of the CIO/IT function, precisely so that security concerns are not diluted by delivery-timeline pressure. A recurring exam pattern asks candidates to identify which committee — IT Strategy Committee, IT Steering Committee, or the Board itself — is responsible for a given oversight action; the safest anchor is to remember that ultimate accountability for cyber risk rests with the Board, while the CISO owns day-to-day execution and escalation.
⚠️ Common Mistake: Candidates often assume the CISO reports to the CIO. Under the framework, the CISO's reporting line is kept independent of IT operations to avoid a conflict of interest.

📋 Incident Reporting, VA/PT Audits and the CERT-In Interface
Detection is only half the framework — the other half is disciplined reporting. Banks must report unusual cyber incidents to RBI within stipulated timelines, and where an incident meets defined thresholds it must also flow to CERT-In as India's national nodal agency for cyber incident response. This dual-reporting design means a single serious incident can trigger two parallel notification tracks: one regulatory (to RBI, as sectoral supervisor) and one national (to CERT-In, for broader threat intelligence and coordination). Candidates preparing this portion should also revisit the statutory backbone that criminalises the underlying acts, since the IT Act 2000 sections for cyber crime explain exactly which sections banks invoke when filing a police complaint alongside the regulatory report. Beyond incident reporting, the framework mandates periodic Vulnerability Assessment and Penetration Testing (VA/PT) of critical systems, red-team exercises for larger banks, and a well-defined patch-management cadence so that known vulnerabilities do not sit open for months. The table below summarises how the major components differ in scope, cadence and applicability — a comparison that comes up often in match-the-following and case-study style questions. Candidates who want the primary source rather than a summary can read RBI's own circulars and master directions on its official circulars index, which is the authoritative reference the exam ultimately draws from.
| Framework Component | Typical Cadence | Reports To | Mandatory for All Banks? |
|---|---|---|---|
| Board-approved cybersecurity policy | Reviewed annually | Board / IT Strategy Committee | ✅ Yes |
| Cyber incident reporting | Within hours of detection | RBI and CERT-In | ✅ Yes |
| VA/PT of critical systems | At least half-yearly | Internal audit / Board | ✅ Yes |
| Red-team exercises | Annually (larger banks) | Board / regulator on request | ❌ Risk-based, not universal |
| C-SOC continuous monitoring | 24x7 | CISO / IT Steering Committee | ✅ Yes |
🔒 Core Technical Controls: Network, Access and Channel Safeguards
The framework's technical annexure reads like a checklist of layered defence: network segmentation to isolate critical payment infrastructure, multi-factor authentication for privileged and remote access, encryption of data at rest and in transit, and strict change-management so that no single administrator can push a production change unreviewed. These controls exist because attackers rarely go straight for the vault — they move laterally from a weakly segmented branch network toward the core banking system, a pattern examined in depth in the Channels Of Cyber Crimes chapter. Customer-facing channels get their own controls too: card-present and card-not-present transaction monitoring, velocity checks, and tokenisation are all framework-driven responses to the fraud patterns detailed in the Electronic Card Frauds chapter, while broader customer-protection controls sit alongside the material in Computer Fraud Protection. Social-engineering-driven fraud remains the hardest control gap to close with technology alone, which is why the framework pairs technical controls with mandatory customer-awareness campaigns — a theme explored further in our piece on the digital arrest scam and in our breakdown of phishing vishing and smishing defences. For a wider view of how these controls interact with capital-market-facing systems, it is worth reading how depositories secure their own infrastructure in Stock Exchanges and Depositories in India, since NSDL and CDSL operate under a parallel but structurally similar regulatory security mandate.
📌 Remember: The RBI cybersecurity framework applies proportionately — a small finance bank and a large public-sector bank share the same principles but not the same minimum control intensity.
For a full topic map and revision checklist, browse every article tagged under Prevention of Cyber Crime, and cross-check current repo rates and policy figures against the live RBI rates resource before your exam, since the framework itself is periodically updated through fresh master directions.

🧠 Practice MCQs: RBI Cybersecurity Framework for Banks
Q1. The RBI Cyber Security Framework in Banks was first issued via circular in which year? (a) 2011 (b) 2013 (c) 2016 (d) 2019
Answer: (c) — RBI issued the Cyber Security Framework in Banks circular in June 2016.
Q2. Under the framework, to whom should the CISO's reporting line ideally NOT be tied, to avoid conflict of interest? (a) The Board (b) The CIO/IT function (c) The Audit Committee (d) RBI
Answer: (b) — The CISO is kept independent of the CIO/IT function so security concerns are not subordinated to delivery pressure.
Q3. A serious cyber incident at a bank must typically be reported to which two entities? (a) SEBI and IRDAI (b) RBI and CERT-In (c) Ministry of Finance and NPCI (d) Local police only
Answer: (b) — Reportable incidents flow to RBI as sectoral regulator and to CERT-In as the national nodal agency.
Q4. What is the primary purpose of a Cyber Security Operations Centre (C-SOC)? (a) Processing loan applications (b) Round-the-clock monitoring and detection of security anomalies (c) Filing GST returns (d) Managing HR payroll
Answer: (b) — A C-SOC continuously correlates logs and alerts to detect anomalies in near real time.
Q5. Which document defines a bank's detect-respond-recover-contain cycle for a major cyber incident? (a) Cyber Crisis Management Plan (b) Loan Policy Document (c) KYC Policy (d) Annual Report
Answer: (a) — The Cyber Crisis Management Plan (CCMP) structures the bank's response cycle around these four actions.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions
Is the RBI cybersecurity framework the same for every bank?
No. It follows a proportionate, risk-based approach — every bank must have a board-approved policy and core controls, but the intensity of controls scales with the bank's size, technology adoption and risk profile.
Who is responsible for reporting a cyber incident to RBI?
The bank's CISO or designated cybersecurity function is responsible for escalating and reporting incidents within the timelines set by RBI, with parallel reporting to CERT-In where thresholds are met.
What is the difference between an IT policy and a cybersecurity policy under the framework?
An IT policy governs general technology operations, while the cybersecurity policy specifically addresses risk appetite, threat controls and incident response, and must be approved separately by the board.
How often must banks conduct VA/PT under the framework?
Critical systems are generally required to undergo Vulnerability Assessment and Penetration Testing at least half-yearly, with additional red-team exercises for larger institutions.
The RBI cybersecurity framework for banks is ultimately a discipline exercise — it forces institutions to translate board-level risk appetite into concrete, auditable controls, and it gives IIBF candidates a single lens through which governance, technology and incident-response questions all connect. Revisit the linked chapters above, work through the practice MCQs until every option feels familiar, and when you are ready to test your recall under exam conditions, head over to the CAIIB course page to access full-length mock papers for this elective.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.