Last updated: 01 April 2024
Approved by Board of Directors · Ashiana Fincap Private Limited
1. Purpose
This policy establishes the cyber security framework for Ashiana Fincap Private Limited in accordance with RBI guidelines on IT Framework for the NBFC sector and the DPDP Act, 2023.
2. Governance
- The Board is responsible for oversight of the cyber security framework.
- An IT/Cyber Security Committee reviews the framework at least annually.
- Designated IT Security Officer coordinates day-to-day security operations.
3. Key Controls
- Multi-factor authentication for all critical systems.
- Data encryption at rest and in transit.
- Regular vulnerability assessments and penetration testing (at least annually).
- Business continuity and disaster recovery planning tested at least once a year.
- Third-party vendor security assessments for cloud and SaaS providers.
- Employee training on phishing and social engineering.
4. Incident Response
Cyber incidents are classified by severity. Critical incidents are reported to the Board within 24 hours. Reporting to RBI is made as per prescribed timelines. Affected customers are notified as per DPDP Act requirements.
5. Audit
The IT audit is included in the Internal Audit plan and reviewed by the Audit Committee.
