The RBI's Cyber Security Framework, now reinforced by the 2024 Master Directions on IT Governance, sets 23 baseline controls covering patch management, access control, encryption, and data leak prevention. This guide breaks down what those controls require at the endpoint, and how Zecurit Endpoint Manager helps banks and NBFCs meet them.
The Reserve Bank of India issued its Cyber Security Framework for Banks on 2 June 2016 under circular RBI/2015-16/418, DBS.CO/CSITE/BC.11/33.01.001/2015-16, following a period of rapid digital expansion in Indian banking and a corresponding rise in cyber incidents with no standardised response playbook in place. The framework was deliberately written from the assumption that a breach has already happened, or will happen, shifting the emphasis from pure prevention toward detection, containment, and response.
Since 2016, RBI has steadily expanded its expectations through supplementary circulars on ATM network security, application whitelisting, and CERT-In reporting norms, capped by the 2024 Master Directions on IT Governance, Risk, Controls and Assurance Practices, which made several previously informal expectations mandatory across the board.
This guide maps the framework's endpoint-relevant baseline controls to specific capabilities in Zecurit Endpoint Manager, so bank and NBFC IT teams can turn circular language into day-to-day operational controls.
A handful of terms recur across RBI's circulars and supervisory exams:
Cyber Security Operations Centre: a dedicated facility for continuous, real-time monitoring, threat detection, and incident response, operationalised under Annex 2 of the 2016 circular.
The 23 specific control areas under Annex 1 of the framework, spanning network security, access management, patch management, anti-phishing, and customer education.
Cyber Security and Information Technology Examination cell, the RBI department in Mumbai to which board-approved cybersecurity policies must be communicated.
Cyber Crisis Management Plan: a documented, tested incident response plan covering classification, escalation, communication, and recovery time objectives, now mandatory for all covered entities under the 2024 Master Directions.
An auditor empanelled by India's Computer Emergency Response Team, the de-facto standard for VAPT engagements that RBI inspectors will accept without further scrutiny.
A dedicated board-level committee for IT governance, made mandatory under the 2024 Master Directions, distinct from the broader audit or risk committee.
The framework's coverage has expanded steadily since 2016 and now extends to:
The framework has evolved through layered circulars rather than a single rewrite, and IT teams need to track all three layers to stay current.
RBI/2015-16/418 established the board-approved cybersecurity policy requirement, 23 baseline controls under Annex 1, C-SOC guidance under Annex 2, and an incident reporting template under Annex 3, applicable to scheduled commercial banks.
Urban Cooperative Banks were brought under comparable requirements through a separate 2019 directive. Payment aggregators and payment gateways became subject to dedicated RBI cybersecurity norms in March 2020 as digital payment volumes accelerated.
RBI consolidated and tightened expectations: a mandatory board-level IT Strategy Committee, a Board-approved IT Risk Framework, a mandatory Cyber Crisis Management Plan for all covered entities, and significantly tightened third-party risk management with exit clauses and concentration risk monitoring.
Supervisory exams have shifted from "did you run a scan" to "did you run a manual penetration test, were findings remediated, and were they re-tested." CERT-In empanelment of the auditor has become the de-facto standard for inspector acceptance.
Across the original circular and the 2024 Master Directions, RBI's expectations cluster around four operational pillars, each carrying direct endpoint implications.
A board-approved cybersecurity policy, an IT Strategy Committee at board level, and a CISO reporting outside the IT function. RBI has been explicit that cybersecurity is a board concern, not a CIO problem.
Network segmentation, privileged access management, endpoint protection, encryption of data at rest and in transit, and patch management with a documented SLA, the heart of Annex 1's 23 controls.
A 24/7 C-SOC, continuous vulnerability scanning, annual VAPT by CERT-In empanelled auditors for internet-facing assets, and quarterly patch compliance reviews.
Incidents involving customer data compromise or financial loss reported within 2 hours; other significant incidents within 6 hours; a full post-incident analysis within 21 days.
The following sections translate the framework's endpoint-relevant baseline controls into the specific Zecurit capabilities that support each one.
Banks must implement centralised authentication and authorisation across all systems, explicitly including a strong password policy, multi-factor authentication where risk assessment warrants it, the principle of least privilege, and separation of duties. This is one of the first areas RBI inspectors examine when something goes wrong, as the Kotak Mahindra Bank action made clear.
Configuration Management's User and Group Management lets IT teams create, modify, and disable local user accounts remotely and enforce password policy across the fleet. Remote Access sessions require explicit session confirmation from the end user and are governed by role-based access controls, with full session logging supporting both least-privilege enforcement and separation of duties.
Patch management with a documented SLA is named explicitly as a mandatory baseline control, and quarterly patch compliance reviews are expected as part of ongoing supervisory cadence, alongside annual VAPT for internet-facing assets by CERT-In empanelled auditors.
Patch Management continuously scans every managed endpoint for missing patches, ranking them by CVSS score and active exploit intelligence, with automated deployment during configured maintenance windows. Patch Compliance Reports give your IT risk committee the dated, documented SLA evidence RBI examiners expect, and Vulnerability Management supports remediation tracking between formal VAPT cycles.
Encryption of customer data at rest and in transit is a named mandatory control. Given the volume of sensitive financial data on banking endpoints, from loan officer workstations to branch terminals, demonstrable encryption coverage is central to what examiners verify.
BitLocker Management enforces drive encryption across every managed Windows endpoint from a central console, with TPM-only, TPM+PIN, and passphrase authentication modes. Recovery keys are backed up automatically, and BitLocker Compliance Reports identify any unprotected device, giving your CISO fleet-wide, examiner-ready evidence of encryption at rest.
The framework dedicates an entire chapter to data loss, calling for protection against data loss, leak, and theft across its lifecycle. It explicitly requires banks to define and implement a policy restricting and securing the use of removable media on devices, plus secure data erasure procedures.
Device Control enforces allow, block, or trusted-only policies for removable storage, Bluetooth, and wireless adapters, with BadUSB keystroke injection prevention and policy enforcement that holds even when endpoints are offline. Every connection attempt and blocked event is logged with a timestamp and user account, supporting the lifecycle-wide data protection this chapter requires.
Banks must maintain an updated register identifying every IT asset, including which systems store or process customer data, with each asset assigned a criticality rating based on the sensitivity of data it handles. This inventory is the foundation every other baseline control depends on.
Hardware Inventory and Asset Discovery maintain a continuously updated, automatic record of every device on the network the moment it connects. Software Inventory identifies exactly which applications, and therefore which customer-data-handling systems, run on each endpoint, supporting accurate criticality classification.
Cyber incidents involving customer data compromise or financial loss must be reported within 2 hours, with other significant incidents reported within 6 hours and a full post-incident analysis due within 21 days. Meeting this window depends entirely on how fast detection happens at the endpoint, where most incidents actually start.
Real-time Security Alerts flag disabled antivirus, disabled firewalls, and BitLocker protection turning off the moment they happen, rather than during a periodic scan. Device Control logs and User Logon Reports give incident response teams the forensic detail needed to classify and scope an incident quickly enough to meet the 2-to-6-hour reporting clock.
RBI's mandatory controls explicitly name endpoint protection on critical systems, supplemented by circulars requiring application whitelisting, particularly on systems supporting core banking and ATM networks, to prevent unauthorised or malicious software from executing.
Security Alerts notify IT teams instantly when antivirus or antimalware protection is disabled on any critical endpoint. Software Alerts flag prohibited or unauthorised software installations the moment they occur, and Configuration Management enforces consistent security hardening baselines across systems supporting core banking operations.
Reports must be available to inspectors covering patch compliance, security configuration, and access control, and the gap between an examiner's request and producing that evidence is exactly where the deficiencies cited in actions like the Kotak Mahindra Bank case tend to surface.
Compliance and Reporting provides 100+ built-in report templates including pre-mapped templates for ISO 27001, PCI-DSS, HIPAA, GDPR, CIS, and NIST. Security Reports surface BitLocker gaps, firewall status, and antivirus health across all endpoints, and Scheduled Report Delivery automates this evidence for your IT Strategy Committee well ahead of the next CSITE review or annual audit.
A consolidated reference mapping each endpoint-relevant RBI baseline control to the relevant Zecurit features, useful for CSITE review preparation and IT Strategy Committee reporting.
| RBI Baseline Control | Zecurit Endpoint Manager Capability |
|---|---|
| User Access Control (Control 8.4) | User and Group ManagementRole-Based AccessSession Confirmation and Audit |
| Patch & Vulnerability Management | Patch ManagementCVSS PrioritisationPatch Compliance Reports |
| Encryption of Customer Data | BitLocker ManagementTPM Policy ManagementBitLocker Compliance Reports |
| Data Leak Prevention / Removable Media | Device ControlUSB/Removable Storage PoliciesOffline Policy Enforcement |
| IT Asset Inventory & Criticality Rating | Hardware InventoryAsset DiscoverySoftware Inventory |
| Rapid Incident Detection (2–6 Hr Window) | Real-Time Security AlertsAudit Device LogsUser Logon Reports |
| Endpoint Protection on Critical Systems | Security AlertsSoftware AlertsConfiguration Management |
| Audit-Ready Reporting (CSITE) | 100+ Compliance ReportsSecurity ReportsScheduled Report Delivery |
The Kotak Mahindra Bank action made one thing unmistakable: RBI's supervisory exams test whether baseline controls actually work, not whether a policy document describing them exists. User access management, patch management, and data security deficiencies, repeated across two consecutive years of inspection, were enough to halt new customer onboarding at one of India's largest private banks.
With the 2024 Master Directions raising the bar further, mandatory board-level IT governance, mandatory Cyber Crisis Management Plans, and tightened third-party oversight, the endpoint controls underpinning the framework's baseline requirements matter more, not less, heading into FY 2026-27.
Zecurit Endpoint Manager addresses the framework's core endpoint-relevant baseline controls from a single lightweight agent and unified console, giving bank and NBFC IT teams the patch management, encryption, access control, and audit-ready reporting that RBI examiners test for, without assembling evidence from a dozen disconnected tools when CSITE comes calling.
Zecurit develops cloud-based IT management solutions designed for modern IT teams. The Zecurit platform helps organisations manage endpoints, track assets, enforce security policies, and securely support distributed workforces through centralised, easy-to-use tools.
To learn more about Zecurit Endpoint Manager and how it supports your RBI cybersecurity compliance programme, start a free 14-day trial or contact the Zecurit team.
Contact Zecurit