BSEIndia
      Close  
NOTICES
Notice No.   20240426-61   Notice Date   26 Apr 2024
Category   Others   Segment   General
Subject   Cyber Security & Cyber Resilience framework for Stock Brokers / Depository Participants.
Attachments   CSAR_Annexure III.pdf ; CSAR_Annexure_I.pdf ; CSAR_Audit_TOR.pdf ; CSAR_Annexure_IV.pdf ; CSAR_Annexure_II.pdf ; CSAR_Annexure_V.pdf ;
Content

Member’s attention is drawn to SEBI circular no. SEBI/HO/MIRSD/CIR/PB/2018/147 dated December 03, 2018, SEBI/HO/MIRSD/DOP/CIR/P/2019/109 dated October 15, 2019 and Exchange circular no. 20191022-27 dated October 22, 2019, in relation to Cyber Security & Cyber Resilience framework for Stock Brokers / Depository Participants and Exchange notice no. 20230331-68 dated March 31, 2023, on Revised and Standardized “Terms Of Reference” for “Cyber Security and Cyber Resilience Audit report” of Stock Brokers / Trading Members across Exchanges.

Reference is further drawn to para 5 of the said SEBI Circular dated October 15, 2019, wherein periodicity of audit for the purpose of compliance with Cyber Security and Cyber Resilience is defined. Accordingly, trading members are required to carry-out Cyber Security & Cyber Resilience Audit for the period ended March 31, 2024, as per the applicability criteria given below in Table 1: 

Table 1: Categorization of member and periodicity of Cyber Audit

Sr. No

Type of stockbroker as specified in SEBI circular CIR/MRD/DMS/34/2013 dated November 06, 2013

Periodicity

1

Type I

Member using trading software provided by the Exchange (TWS) and software provided by Application Service Provider (ASP)

Annual

2

Type II

Members using CTCL Facility

Annual

3

Type III

All Members using Algorithmic Trading Facility (ATF)/Algo Facility

Half-yearly

Timelines for submission of Cyber Security & Cyber Resilience Audit Report for the period ended March 31, 2024, is given below in Table 2:

Table 2: Report Submission Timelines

Type of Trading Members

Audit Period

Due Date for Submission

Preliminary Audit Report submission

Corrective Action Report (If Applicable)

QSB & Non QSB

Half Yearly

30-Jun-24

30-Sep-24

(October 2023 - March 2024)

Yearly Submission

30-Jun-24

30-Sep-24

(April 2023 - March 2024)

 

Stock Brokers may note that the above mentioned reports are required to be submitted only in electronic form through BEFS (BSE Electronic Filing s) –  http://befs.bseindia.com

All Trading members are requested to take note that, for each non-compliance reported by the auditor, trading members are required to submit corrective action taken report as per above mentioned timelines. On review of details of corrective action submitted by trading member, the auditor shall submit the status of compliance as Compliant or Non-Compliant on BEFS.

 

Submission of Cyber Audit Report with Management comments shall be considered complete only after Member submits the report to the Exchange and receives an acknowledgment email. Saved reports/reports submitted by auditor will not be considered as final submission. Further, auditor must provide compliance status for each TOR item i.e., Compliant/Non-Compliant and Not Applicable and in case of any TOR item which is not applicable, auditor is required to provide justification for the non-applicability of said TOR.

Trading members shall comply with any non-compliance/ non-conformities (NCs) pending submissions for cyber audit report for the previous audit period by submitting ATR through BEFS Portal.

 

Trading members are requested to take note of the Exchange circular 20231005-54 dated October 05, 2023, regarding “Revised Penalties/disciplinary action(s)/charges for System Audit Report & Cyber Security and Cyber Resilience Audit Report related submissions”. The details of Penalties/disciplinary action(s)/charges have been provided in Annexure V.

 

Stockbrokers/Trading Members are requested to refer to the following documents while submitting the Cyber Security & Cyber Resilience Audit Report.

 

Ø  Auditor Selection Norms – Annexure I

Ø  Audit Process – Annexure II

Ø  Auditor User Manual – Annexure III

Ø  Member User Manual – Annexure IV

Ø  Penalty/disciplinary action for Delay/Non-submission of Preliminary?Audit Report / Corrective Action Taken Report and non-Closure of observations Annexure V

Ø  Cyber Terms of Reference (TOR) - II and III

 

All Trading Members are advised to take note of the above and comply to avoid disincentives.

In case of any queries/clarifications, you may contact us on the below numbers in Table 4.

Table 4: Contact Details

Sr. No

Purpose

Contact Nos.

Email ID

1

Cyber Security Audit XBRL related issues

1800233 0445

Bse(dot)xbrl(at)bseindia.com

2

CSAR Process related

22725841/5842/8888

Bse(dot)msc(at)bseindia.com

 

For and on behalf of BSE Ltd. 

  

Devendra Kulkarni                                                                                                                          

Additional General Manager