RBI Cyber Security Framework for Banks
The 2016 circular the courseware teaches, and the 2026 Directions that replaced it.
On 2 June 2016 RBI issued its circular on the Cyber Security Framework in Banks to all scheduled commercial banks (excluding regional rural banks). It told banks that cyber risk could no longer be handled as a part of general IT policy. Every bank needed a board-approved cyber security policy of its own, round-the-clock monitoring, and a plan for when an attack succeeds.
The IIBF courseware (2025 edition) predates what came next, and the 2016 circular is still how most bankers describe the framework. On 31 July 2026 RBI folded it, with its later IT governance instructions, into a single set of Directions for commercial banks. The core ideas carried over; the detail grew.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The 2016 Circular in Brief
| Requirement | What it asked for |
|---|---|
| Board-approved cyber security policy | Distinct from the bank's IT or information security policy, so cyber risks and their controls are visible on their own |
| Risk-based approach | Assess inherent risk from technologies, channels, products and threats, and rate it low, moderate, high or very high |
| Security Operations Centre (SOC) | Set up at the earliest for continuous surveillance; an indicative SOC set-up was given in Annex 2 |
| Baseline controls | An indicative minimum set of cyber security and resilience controls in Annex 1 |
| Network and database security | No unauthorised access; temporary connections must not be left open |
| Protection of customer information | Confidentiality, integrity and availability of customer data, including data held by vendors |
| Cyber Crisis Management Plan (CCMP) | Part of the board-approved strategy, covering detection, response, recovery and containment |
| Reporting and information sharing | Report all unusual cyber incidents, successful or attempted, to RBI in the Annex 3 format; share with IB-CART set up by IDRBT |
| Awareness | For staff at all levels, top management, the Board, customers and vendors |
What the 2026 Directions Added
The Reserve Bank of India (Commercial Banks: Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026. Parallel Directions exist for small finance banks, payments banks, co-operative banks, NBFCs and AIFIs.
- check_circleIT governance and cyber security in one rulebook: Board-approved policies, a Board-level IT Strategy Committee, an IT Steering Committee and an Information Security Committee.
- check_circleA defined CISO role: preferably General Manager rank, no reporting line to the head of IT, no business targets, and a quarterly review of cyber risks before the Board or its committees.
- check_circleThirty-one baseline control areas, from asset inventory and patching to anti-phishing services, VAPT, red teaming, DR drills, customer education and forensics.
- check_circleA Cyber Security Operations Centre with defined capabilities, and an Information Systems audit function overseen by the Audit Committee of the Board.
- check_circleA firm reporting clock: cyber incidents reported on RBI's DAKSH platform within six hours of detection, with CERT-In notified as well.
- check_circleThe CCMP is kept, with its four aspects now listed as detection, containment, response and recovery.
Which Version Will Your Paper Test?
IIBF tests regulatory developments only up to a cut-off date: 30 June for sittings from September to February, and 31 December for sittings from March to August. The 2026 Directions came out on 31 July 2026, after the 30 June 2026 cut-off, so the September 2026 to February 2027 sittings should still reflect the 2016 circular and the instructions in force on 30 June 2026. Sittings from March 2027 onwards can test the 2026 Directions.
Quick practice on banking operations. No signup.
Terms Worth Knowing
- CSITE Cell
- The Cyber Security and Information Technology Examination Cell of RBI's supervision department, to which the 2016 circular asked banks to confirm their board-approved policy.
- SOC or CSOC
- A security operations centre: the team and tools that monitor logs and network activity continuously and escalate incidents.
- CCMP
- Cyber Crisis Management Plan: how the bank detects, contains, responds to and recovers from a serious cyber attack. RBI notes that ordinary business continuity plans may not be enough for cyber risk.
- IDRBT
- Institute for Development and Research in Banking Technology, which coordinates the banks' CISO forum and set up IB-CART.
How the IIBF Exam Tests This
Expect recall of the date (June 2016), the policy separation (cyber security policy distinct from the IT policy), the SOC requirement, and the four aspects of the CCMP. A favourite trap swaps the policy approver: it is the Board, not the CISO or the IT department. Another offers "traditional BCP and DR arrangements are sufficient"; RBI said the opposite.
FAQs
When did RBI issue the cyber security framework for banks?expand_more
On 2 June 2016, by circular DBS.CO/CSITE/BC.11/33.01.001/2015-16 to scheduled commercial banks other than regional rural banks. On 31 July 2026 it was replaced by the 2026 Cybersecurity, Technology Risk Directions.
What are the four aspects of the Cyber Crisis Management Plan?expand_more
Detection, response, recovery and containment, as listed in the 2016 circular. The 2026 Directions keep the same four, ordered detection, containment, response and recovery.
Why must the cyber security policy be separate from the IT policy?expand_more
So the bank can highlight cyber threats and the measures against them on their own, and the whole bank, not just the IT department, treats them as its concern.
Is a Security Operations Centre mandatory for banks?expand_more
Yes. The 2016 circular mandated a SOC, and the 2026 Directions require a Cyber Security Operations Centre for continuous surveillance.
Next steps
- Incident Reporting by Banksarrow_forward
- Cyber Risk Managementarrow_forward
- CERT-In & NCIIPCarrow_forward
- Syllabusarrow_forward
120 questions, 2 hours, scored instantly.
