OVERVIEW
- A cyber security audit is an independent and systematic assessment of an entity’s cyber security governance framework, information systems, policies, procedures, and technical controls. Its primary objective is to determine whether adequate safeguards have been implemented to protect the confidentiality, integrity, and availability of information systems and data.
- Unlike routine IT maintenance or operational reviews, a cyber security audit evaluates regulatory compliance, the effectiveness of cyber risk management, and the entity’s overall cyber resilience.
- It examines whether appropriate governance policies, access controls, security monitoring systems, vulnerability management processes, and incident response mechanisms have been implemented in accordance with the applicable IFSCA guidelines.
- The audit assures the Board and senior management that cyber risks are effectively managed and the entity is prepared to respond to and recover from cyber incidents.
WHO IS REQUIRED TO CONDUCT CYBER SECURITY AUDIT IN IFSC?
- Cyber security audit requirements apply to all Regulated Entities (REs) in IFSC Gift City. According to the “Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs dated March 10, 2025” REs shall include any entity which is licensed, recognised, registered or authorised by IFSCA.
- The implementation of these Guidelines shall be undertaken in accordance with the principle of proportionality, after taking into due consideration: a. the scale and complexity of operations, b. the nature of the activity the entity is engaged in, c. its interconnectedness with the financial ecosystem and d. the corresponding cyber risks the entity is exposed to.
EXEMPTIONS UNDER THE IFSCA CYBER SECURITY GUIDELINES
- The IFSCA Cyber Security and Cyber Resilience Guidelines provide certain exemptions to specific categories of REs operating in IFSCs. As per the circular “Amendment to the Circular titled Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs March 10, 2026”
- The following categories of REs are exempted from the requirements mentioned in this Circular for a period of three (3) years from the date of its issuance: The RE operating in the form of a branch of a regulated Indian or foreign entity; The RE providing services to its group entities only e.g. Global In-House Centre (GIC); and The RE having less than 10 employees.
- These exemptions to the REs, are subject to fulfilment of the following conditions during the exempted period: 1. The RE shall adopt the Cyber Security and Cyber Resilience framework and IS Policy of its parent entity or the holding company of such parent entity; 2. The Chief Information Security Officer (CISO) of the parent entity shall act as the Designated Officer for the RE; 3.The parent entity or the holding company of such parent entity of the RE, in India or overseas, must be regulated by a regulator/ Government Body in its home jurisdiction; 4. The Designated Officer of the RE shall certify that all the necessary systems/processes, in line with these Guidelines, have been put in place, and shall submit the same to the respective supervision Department/ Division of IFSCA within ninety (90) days of the end of each financial year; and 5. The RE shall submit the annual cyber security audit report to IFSCA.
- The following categories of REs are exempted from the requirements mentioned in this Circular for a period of three (3) years from the date of its issuance: Foreign university set up in the IFSC; The RE which has been established as newly incorporated standalone entity within the IFSC and does not have any parent organisation; and Credit Rating Agency.
WHEN SHOULD CYBER SECURITY AUDIT BE CONDUCTED?
- The audit shall be conducted annually and a report in this regard shall be submitted to IFSCA by the REs within 90 days from the end of the financial year. The REs shall submit the audit report to the corresponding IFSCA Department/ Division in charge of the supervision of the RE. For FY 2025-26 the due date to submit Cyber security audit is 29 June 2026.
BY WHOM SHOULD CYBER SECURITY AUDIT BE CONDUCTED?
- IFSCA requires cyber security audit to be conducted by independent and qualified auditors with relevant expertise in cyber security. The audit may be conducted by:
- CERT-In Empanelled Cyber Security Auditors: Auditors empanelled with the Indian Computer Emergency Response Team (CERT-In) are recognised as qualified professionals for conducting cyber security audits. These auditors possess specialised technical expertise and experience in evaluating cyber security controls.
- Independent Professionals with Recognised Certifications:
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP)
- GIAC Systems and Network Auditor (GSNA)
- Audit Firms with Relevant Cyber Security Experience: An auditor having prior experience in conducting cybersecurity audit of entities with similar business activity as that of the RE
IMPORTANCE OF AUDIT INDEPENDENCE
- Independence is a critical requirement. The auditor conducting the cyber security audit must not have any conflict of interest with the entity. This means the auditor should not be involved in designing, implementing, or managing the entity’s cyber security systems. The objective is to ensure that the audit provides an unbiased and objective assessment.