Compliance Guide

RBI Cyber Security Framework for Banks

A Practical Guide to Endpoint-Level Compliance for Banks and NBFCs

The RBI's Cyber Security Framework, now reinforced by the 2024 Master Directions on IT Governance, sets 23 baseline controls covering patch management, access control, encryption, and data leak prevention. This guide breaks down what those controls require at the endpoint, and how Zecurit Endpoint Manager helps banks and NBFCs meet them.

Published byZecurit
CategoryCompliance & Regulation
AudienceBank IT Teams, CISOs, NBFC Compliance Officers

Why RBI Treats the Endpoint as a Board-Level Concern

At a Glance
  • Who is impacted: All scheduled commercial banks, urban cooperative banks, and payment system providers, with NBFCs covered through related RBI circulars and Master Directions.
  • What the framework requires: A board-approved cybersecurity policy and 23 baseline controls spanning patch management, access control, encryption, and data leak prevention, now reinforced by the 2024 Master Directions on IT Governance.
  • Why endpoints matter now: Baseline Control 8 (access management), patch management SLAs, and removable media restrictions are explicit, examiner-tested controls that live on the device.
  • How Zecurit helps: Patch management, BitLocker encryption, device control, access management, and audit-ready compliance reporting from a single agent and console.

The Reserve Bank of India issued its Cyber Security Framework for Banks on 2 June 2016 under circular RBI/2015-16/418, DBS.CO/CSITE/BC.11/33.01.001/2015-16, following a period of rapid digital expansion in Indian banking and a corresponding rise in cyber incidents with no standardised response playbook in place. The framework was deliberately written from the assumption that a breach has already happened, or will happen, shifting the emphasis from pure prevention toward detection, containment, and response.

Since 2016, RBI has steadily expanded its expectations through supplementary circulars on ATM network security, application whitelisting, and CERT-In reporting norms, capped by the 2024 Master Directions on IT Governance, Risk, Controls and Assurance Practices, which made several previously informal expectations mandatory across the board.

RBI's Position Is Not Hypothetical: In April 2024, RBI barred Kotak Mahindra Bank from onboarding new customers through its online and mobile banking channels and from issuing new credit cards, citing specific deficiencies in user access management, data security, patch management, and IT risk governance across two consecutive years of inspections. The bank's share price dropped over 10% the same day. These are not abstract compliance categories; they are the exact areas RBI inspectors test first.

This guide maps the framework's endpoint-relevant baseline controls to specific capabilities in Zecurit Endpoint Manager, so bank and NBFC IT teams can turn circular language into day-to-day operational controls.

Key Terminology Under the RBI Framework

A handful of terms recur across RBI's circulars and supervisory exams:

  • C-SOC

    Cyber Security Operations Centre: a dedicated facility for continuous, real-time monitoring, threat detection, and incident response, operationalised under Annex 2 of the 2016 circular.

  • Baseline Controls

    The 23 specific control areas under Annex 1 of the framework, spanning network security, access management, patch management, anti-phishing, and customer education.

  • CSITE

    Cyber Security and Information Technology Examination cell, the RBI department in Mumbai to which board-approved cybersecurity policies must be communicated.

  • CCMP

    Cyber Crisis Management Plan: a documented, tested incident response plan covering classification, escalation, communication, and recovery time objectives, now mandatory for all covered entities under the 2024 Master Directions.

  • CERT-In Empanelled Auditor

    An auditor empanelled by India's Computer Emergency Response Team, the de-facto standard for VAPT engagements that RBI inspectors will accept without further scrutiny.

  • IT Strategy Committee

    A dedicated board-level committee for IT governance, made mandatory under the 2024 Master Directions, distinct from the broader audit or risk committee.

Who Must Comply With the Framework?

The framework's coverage has expanded steadily since 2016 and now extends to:

  • All scheduled commercial banks: nationalised, private, and foreign bank branches in India
  • Urban Cooperative Banks, brought under comparable requirements via a 2019 directive
  • Regional Rural Banks, subject to baseline requirements with proportionality flexibility
  • Payment aggregators and payment gateways under separate March 2020 RBI norms
  • NBFCs, particularly those with assets above ₹500 crore under the Master Direction on IT Framework
  • Fintech lenders processing large customer data volumes
  • Foreign banks' India branches, regardless of global parent-group compliance status
  • Critical third-party vendors: cloud, core banking, AML, and KYC service providers
This Is Not a Checkbox Exercise: RBI has been explicit that banks must conduct genuine risk assessments calibrated to their actual threat environment, not adopt templated policies written to satisfy an examiner. Foreign banks cannot substitute group-level compliance, such as DORA conformance in Europe, for India-specific controls; a fully DORA-compliant European bank still needs to separately satisfy RBI's requirements for its Indian branch.

From the 2016 Circular to the 2024 Master Directions

The framework has evolved through layered circulars rather than a single rewrite, and IT teams need to track all three layers to stay current.

2016
2 June 2016 — Founding Circular

The Original Cyber Security Framework

RBI/2015-16/418 established the board-approved cybersecurity policy requirement, 23 baseline controls under Annex 1, C-SOC guidance under Annex 2, and an incident reporting template under Annex 3, applicable to scheduled commercial banks.

2019
20
2019–2020 — Expanded Scope

UCBs and Payment Systems Brought In

Urban Cooperative Banks were brought under comparable requirements through a separate 2019 directive. Payment aggregators and payment gateways became subject to dedicated RBI cybersecurity norms in March 2020 as digital payment volumes accelerated.

2024
April 2024 — Master Directions

IT Governance, Risk, Controls and Assurance Practices

RBI consolidated and tightened expectations: a mandatory board-level IT Strategy Committee, a Board-approved IT Risk Framework, a mandatory Cyber Crisis Management Plan for all covered entities, and significantly tightened third-party risk management with exit clauses and concentration risk monitoring.

2025
26
2025–2026 — Supervisory Maturity

Exams Test Outcomes, Not Just Documentation

Supervisory exams have shifted from "did you run a scan" to "did you run a manual penetration test, were findings remediated, and were they re-tested." CERT-In empanelment of the auditor has become the de-facto standard for inspector acceptance.

The Framework's Core Pillars

Across the original circular and the 2024 Master Directions, RBI's expectations cluster around four operational pillars, each carrying direct endpoint implications.

Pillar 01

Board-Level Governance

A board-approved cybersecurity policy, an IT Strategy Committee at board level, and a CISO reporting outside the IT function. RBI has been explicit that cybersecurity is a board concern, not a CIO problem.

Pillar 02

Baseline Technical Controls

Network segmentation, privileged access management, endpoint protection, encryption of data at rest and in transit, and patch management with a documented SLA, the heart of Annex 1's 23 controls.

Pillar 03

Continuous Monitoring and Testing

A 24/7 C-SOC, continuous vulnerability scanning, annual VAPT by CERT-In empanelled auditors for internet-facing assets, and quarterly patch compliance reviews.

Pillar 04

Rapid Incident Reporting

Incidents involving customer data compromise or financial loss reported within 2 hours; other significant incidents within 6 hours; a full post-incident analysis within 21 days.

Baseline Controls Mapped to Zecurit Endpoint Manager

The following sections translate the framework's endpoint-relevant baseline controls into the specific Zecurit capabilities that support each one.

Baseline Control 8

User Access Control and Management

Annex 1, Control 8.4

Banks must implement centralised authentication and authorisation across all systems, explicitly including a strong password policy, multi-factor authentication where risk assessment warrants it, the principle of least privilege, and separation of duties. This is one of the first areas RBI inspectors examine when something goes wrong, as the Kotak Mahindra Bank action made clear.

Zecurit Endpoint Manager

Configuration Management's User and Group Management lets IT teams create, modify, and disable local user accounts remotely and enforce password policy across the fleet. Remote Access sessions require explicit session confirmation from the end user and are governed by role-based access controls, with full session logging supporting both least-privilege enforcement and separation of duties.

User and Group ManagementRole-Based AccessSession Confirmation and Audit
Baseline Control

Patch and Vulnerability Management

Annex 1; Master Directions, 2024

Patch management with a documented SLA is named explicitly as a mandatory baseline control, and quarterly patch compliance reviews are expected as part of ongoing supervisory cadence, alongside annual VAPT for internet-facing assets by CERT-In empanelled auditors.

Zecurit Endpoint Manager

Patch Management continuously scans every managed endpoint for missing patches, ranking them by CVSS score and active exploit intelligence, with automated deployment during configured maintenance windows. Patch Compliance Reports give your IT risk committee the dated, documented SLA evidence RBI examiners expect, and Vulnerability Management supports remediation tracking between formal VAPT cycles.

Patch ManagementCVSS PrioritisationPatch Compliance Reports
Baseline Control

Encryption of Customer Data

Annex 1; Master Directions, 2024

Encryption of customer data at rest and in transit is a named mandatory control. Given the volume of sensitive financial data on banking endpoints, from loan officer workstations to branch terminals, demonstrable encryption coverage is central to what examiners verify.

Zecurit Endpoint Manager

BitLocker Management enforces drive encryption across every managed Windows endpoint from a central console, with TPM-only, TPM+PIN, and passphrase authentication modes. Recovery keys are backed up automatically, and BitLocker Compliance Reports identify any unprotected device, giving your CISO fleet-wide, examiner-ready evidence of encryption at rest.

BitLocker ManagementTPM Policy ManagementBitLocker Compliance Reports
Baseline Control

Data Leak Prevention and Removable Media Restrictions

Annex 1; Data Leak Prevention chapter

The framework dedicates an entire chapter to data loss, calling for protection against data loss, leak, and theft across its lifecycle. It explicitly requires banks to define and implement a policy restricting and securing the use of removable media on devices, plus secure data erasure procedures.

Zecurit Endpoint Manager

Device Control enforces allow, block, or trusted-only policies for removable storage, Bluetooth, and wireless adapters, with BadUSB keystroke injection prevention and policy enforcement that holds even when endpoints are offline. Every connection attempt and blocked event is logged with a timestamp and user account, supporting the lifecycle-wide data protection this chapter requires.

Device ControlUSB/Removable Storage PoliciesOffline Policy Enforcement
Baseline Control

IT Asset Inventory and Criticality Rating

UCB-specific controls; general baseline applicability

Banks must maintain an updated register identifying every IT asset, including which systems store or process customer data, with each asset assigned a criticality rating based on the sensitivity of data it handles. This inventory is the foundation every other baseline control depends on.

Zecurit Endpoint Manager

Hardware Inventory and Asset Discovery maintain a continuously updated, automatic record of every device on the network the moment it connects. Software Inventory identifies exactly which applications, and therefore which customer-data-handling systems, run on each endpoint, supporting accurate criticality classification.

Hardware InventoryAsset DiscoverySoftware Inventory
Baseline Control

Rapid Incident Detection and Reporting

2-to-6-hour reporting window; 21-day post-incident report

Cyber incidents involving customer data compromise or financial loss must be reported within 2 hours, with other significant incidents reported within 6 hours and a full post-incident analysis due within 21 days. Meeting this window depends entirely on how fast detection happens at the endpoint, where most incidents actually start.

Zecurit Endpoint Manager

Real-time Security Alerts flag disabled antivirus, disabled firewalls, and BitLocker protection turning off the moment they happen, rather than during a periodic scan. Device Control logs and User Logon Reports give incident response teams the forensic detail needed to classify and scope an incident quickly enough to meet the 2-to-6-hour reporting clock.

Real-Time Security AlertsAudit Device LogsUser Logon Reports
Baseline Control

Endpoint Protection on Critical Systems

2024 Master Directions; supplementary application whitelisting circulars

RBI's mandatory controls explicitly name endpoint protection on critical systems, supplemented by circulars requiring application whitelisting, particularly on systems supporting core banking and ATM networks, to prevent unauthorised or malicious software from executing.

Zecurit Endpoint Manager

Security Alerts notify IT teams instantly when antivirus or antimalware protection is disabled on any critical endpoint. Software Alerts flag prohibited or unauthorised software installations the moment they occur, and Configuration Management enforces consistent security hardening baselines across systems supporting core banking operations.

Security AlertsSoftware AlertsConfiguration Management
Supervisory Evidence

Audit-Ready Reporting for RBI Inspections

Supports CSITE reviews and annual IT/cybersecurity audits

Reports must be available to inspectors covering patch compliance, security configuration, and access control, and the gap between an examiner's request and producing that evidence is exactly where the deficiencies cited in actions like the Kotak Mahindra Bank case tend to surface.

Zecurit Endpoint Manager

Compliance and Reporting provides 100+ built-in report templates including pre-mapped templates for ISO 27001, PCI-DSS, HIPAA, GDPR, CIS, and NIST. Security Reports surface BitLocker gaps, firewall status, and antivirus health across all endpoints, and Scheduled Report Delivery automates this evidence for your IT Strategy Committee well ahead of the next CSITE review or annual audit.

100+ Compliance ReportsSecurity ReportsScheduled Report Delivery

RBI Baseline Controls and Zecurit Endpoint Manager Capabilities

A consolidated reference mapping each endpoint-relevant RBI baseline control to the relevant Zecurit features, useful for CSITE review preparation and IT Strategy Committee reporting.

RBI Baseline ControlZecurit Endpoint Manager Capability
User Access Control (Control 8.4)User and Group ManagementRole-Based AccessSession Confirmation and Audit
Patch & Vulnerability ManagementPatch ManagementCVSS PrioritisationPatch Compliance Reports
Encryption of Customer DataBitLocker ManagementTPM Policy ManagementBitLocker Compliance Reports
Data Leak Prevention / Removable MediaDevice ControlUSB/Removable Storage PoliciesOffline Policy Enforcement
IT Asset Inventory & Criticality RatingHardware InventoryAsset DiscoverySoftware Inventory
Rapid Incident Detection (2–6 Hr Window)Real-Time Security AlertsAudit Device LogsUser Logon Reports
Endpoint Protection on Critical SystemsSecurity AlertsSoftware AlertsConfiguration Management
Audit-Ready Reporting (CSITE)100+ Compliance ReportsSecurity ReportsScheduled Report Delivery

RBI Inspectors Test Outcomes, Not Just Policy Documents

The Kotak Mahindra Bank action made one thing unmistakable: RBI's supervisory exams test whether baseline controls actually work, not whether a policy document describing them exists. User access management, patch management, and data security deficiencies, repeated across two consecutive years of inspection, were enough to halt new customer onboarding at one of India's largest private banks.

With the 2024 Master Directions raising the bar further, mandatory board-level IT governance, mandatory Cyber Crisis Management Plans, and tightened third-party oversight, the endpoint controls underpinning the framework's baseline requirements matter more, not less, heading into FY 2026-27.

Zecurit Endpoint Manager addresses the framework's core endpoint-relevant baseline controls from a single lightweight agent and unified console, giving bank and NBFC IT teams the patch management, encryption, access control, and audit-ready reporting that RBI examiners test for, without assembling evidence from a dozen disconnected tools when CSITE comes calling.

About Zecurit

Zecurit develops cloud-based IT management solutions designed for modern IT teams. The Zecurit platform helps organisations manage endpoints, track assets, enforce security policies, and securely support distributed workforces through centralised, easy-to-use tools.

To learn more about Zecurit Endpoint Manager and how it supports your RBI cybersecurity compliance programme, start a free 14-day trial or contact the Zecurit team.

Contact Zecurit
Secret Link