Member’s attention is drawn to SEBI circular no. SEBI/HO/MIRSD/CIR/PB/2018/147 dated December 03, 2018, SEBI/HO/MIRSD/DOP/CIR/P/2019/109 dated October 15, 2019 and Exchange circular no. 20191022-27 dated October 22, 2019, in relation to Cyber Security & Cyber Resilience framework for Stock Brokers / Depository Participants and Exchange notice no. 20230331-68 dated March 31, 2023, on Revised and Standardized “Terms Of Reference” for “Cyber Security and Cyber Resilience Audit report” of Stock Brokers / Trading Members across Exchanges.
Reference is further drawn to para 5 of the said SEBI Circular dated October 15, 2019, wherein periodicity of audit for the purpose of compliance with Cyber Security and Cyber Resilience is defined. Accordingly, trading members are required to carry-out Cyber Security & Cyber Resilience Audit for the period ended March 31, 2024, as per the applicability criteria given below in Table 1:
Table 1: Categorization of member and periodicity of Cyber Audit
|
Sr. No
|
Type of stockbroker as specified in SEBI circular CIR/MRD/DMS/34/2013 dated November 06, 2013
|
Periodicity
|
1
|
Type I
Member using trading software provided by the Exchange (TWS) and software provided by Application Service Provider (ASP)
|
Annual
|
2
|
Type II
Members using CTCL Facility
|
Annual
|
3
|
Type III
All Members using Algorithmic Trading Facility (ATF)/Algo Facility
|
Half-yearly
|
Timelines for submission of Cyber Security & Cyber Resilience Audit Report for the period ended March 31, 2024, is given below in Table 2:
Table 2: Report Submission Timelines
|
Type of Trading Members
|
Audit Period
|
Due Date for Submission
|
Preliminary Audit Report submission
|
Corrective Action Report (If Applicable)
|
QSB & Non QSB
|
Half Yearly
|
30-Jun-24
|
30-Sep-24
|
(October 2023 - March 2024)
|
Yearly Submission
|
30-Jun-24
|
30-Sep-24
|
(April 2023 - March 2024)
|
Stock Brokers may note that the above mentioned reports are required to be submitted only in electronic form through BEFS (BSE Electronic Filing s) – http://befs.bseindia.com
All Trading members are requested to take note that, for each non-compliance reported by the auditor, trading members are required to submit corrective action taken report as per above mentioned timelines. On review of details of corrective action submitted by trading member, the auditor shall submit the status of compliance as Compliant or Non-Compliant on BEFS.
Submission of Cyber Audit Report with Management comments shall be considered complete only after Member submits the report to the Exchange and receives an acknowledgment email. Saved reports/reports submitted by auditor will not be considered as final submission. Further, auditor must provide compliance status for each TOR item i.e., Compliant/Non-Compliant and Not Applicable and in case of any TOR item which is not applicable, auditor is required to provide justification for the non-applicability of said TOR.
Trading members shall comply with any non-compliance/ non-conformities (NCs) pending submissions for cyber audit report for the previous audit period by submitting ATR through BEFS Portal.
Trading members are requested to take note of the Exchange circular 20231005-54 dated October 05, 2023, regarding “Revised Penalties/disciplinary action(s)/charges for System Audit Report & Cyber Security and Cyber Resilience Audit Report related submissions”. The details of Penalties/disciplinary action(s)/charges have been provided in Annexure V.
Stockbrokers/Trading Members are requested to refer to the following documents while submitting the Cyber Security & Cyber Resilience Audit Report.
Ø Auditor Selection Norms – Annexure I
Ø Audit Process – Annexure II
Ø Auditor User Manual – Annexure III
Ø Member User Manual – Annexure IV
Ø Penalty/disciplinary action for Delay/Non-submission of Preliminary?Audit Report / Corrective Action Taken Report and non-Closure of observations – Annexure V
Ø Cyber Terms of Reference (TOR) - II and III
All Trading Members are advised to take note of the above and comply to avoid disincentives.
In case of any queries/clarifications, you may contact us on the below numbers in Table 4.
Table 4: Contact Details
|
Sr. No
|
Purpose
|
Contact Nos.
|
Email ID
|
1
|
Cyber Security Audit XBRL related issues
|
1800233 0445
|
Bse(dot)xbrl(at)bseindia.com
|
2
|
CSAR Process related
|
22725841/5842/8888
|
Bse(dot)msc(at)bseindia.com
|
For and on behalf of BSE Ltd.
Devendra Kulkarni
Additional General Manager |