
The RBI Cyber Security Framework is a set of mandatory guidelines issued by the Reserve Bank of India to protect banks and financial institutions against cyber risks. It ensures the Confidentiality, Integrity and Availability (the CIA triad) of digital banking systems and lays down minimum baseline controls every bank must implement.
It was introduced through the landmark circular “Cyber Security Framework in Banks” dated 2 June 2016 (Circular No. RBI/2015-16/418, DBS.CO/CSITE/BC.11/33.01.001/2015-16). This topic is highly important for banking exams such as IBPS, SBI PO/Clerk, RBI Grade B, NABARD, JAIIB and CAIIB. This guide covers the framework, its components, recent updates, and a full bank of practice MCQs.
What Is the RBI Cyber Security Framework?
The framework is a board-approved, mandatory regime requiring banks to build “next-generation” cyber-defence capabilities. It recognises that as banks adopt more technology, cyber incidents have risen sharply, so a robust, continuously updated security and resilience system is essential. A defining structural requirement is that IT operations and IT security (information security) must be run as two separate functions, giving cybersecurity its own dedicated oversight.
- Issued by: Reserve Bank of India (RBI).
- Date: 2 June 2016.
- Applies to: All Scheduled Commercial Banks — public sector, private, and foreign banks (later extended progressively to Urban Co-operative Banks and NBFCs).
- Supervised by: The Cyber Security and IT Examination (CSITE) Cell of RBI’s Department of Supervision, Mumbai.
- Core goal: Cyber resilience — the ability to withstand, respond to, and recover from cyber incidents.
Objectives of the Framework
- Protect digital banking and payment systems (UPI, IMPS, NEFT, RTGS, ATM, cards, mobile banking).
- Prevent cyber frauds and data breaches.
- Ensure secure technology architecture and vendor / third-party management.
- Enable continuous monitoring and early fraud detection.
- Protect customer data and privacy.
- Ensure prompt cyber-incident reporting and a coordinated response.
The Three Annexes of the 2016 Framework
The 2016 circular contains the main guidance plus three annexes — a frequently tested structural point.
| Annex | Title | What It Covers |
|---|---|---|
| Annex 1 | Baseline Cyber Security and Resilience Requirements | An indicative set of minimum security controls (inventory management, access control, anti-phishing, patch management, etc.). |
| Annex 2 | Setting up a Cyber Security Operations Centre (C-SOC) | How to build and operationalise a 24×7 monitoring centre. |
| Annex 3 | Cyber Security Incident Reporting (CSIR) Format | The template and process for reporting incidents to the RBI. |
Key Components of the RBI Cyber Security Framework
| Component | Explanation |
|---|---|
| Cyber Security Policy & Governance | A distinct, board-approved cyber-security policy; the Board of Directors holds ultimate responsibility. |
| Security Controls & Access Management | Multi-Factor Authentication (MFA), encryption, “least privilege” access, network security. |
| Cyber Crisis Management Plan (CCMP) | Board-approved plan covering Detection, Response, Containment and Recovery. |
| Security Operations Centre (SOC / C-SOC) | Continuous, real-time 24×7 surveillance and threat analysis. |
| VAPT & Red Teaming | Vulnerability Assessment & Penetration Testing of critical applications. |
| Incident Response & Recovery Plan (IRRP) | Escalation, communication and business-continuity procedures. |
| Audits & Compliance Reporting | Periodic independent audits and supervisory reporting to RBI. |
| Vendor / Third-party Risk Management | Secure outsourcing, cloud and fintech collaboration controls. |
Phase-Wise Approach: Prevent, Detect, Respond, Recover
| Phase | Key Deliverables |
|---|---|
| Prevention | Firewalls, MFA, encryption, secure architecture, patch management. |
| Detection | SOC, real-time threat intelligence, AI/ML-based monitoring. |
| Response | CCMP activation, incident reporting to RBI, coordination with CERT-In. |
| Recovery | Restoring services, customer protection, root-cause analysis. |
Incident Reporting Timeline (Important)
Banks must report any unusual cyber incident to the RBI’s CSITE Cell within 2 to 6 hours of detection. This tight window is a popular exam point — it demands mature, real-time detection and response capability.
Important Initiatives & Related Measures
| Initiative | Purpose |
|---|---|
| CSITE Cell | RBI cell that supervises banks’ cybersecurity practices. |
| Data Localisation (2018) | All payment-system data must be stored only in India. |
| Digital Payment Security Controls (Master Direction, Feb 2021) | Secures Internet/Mobile Banking, UPI, cards and other digital products. |
| Central Fraud Registry (CFR) | Lets banks share fraud data to prevent repeat frauds. |
| Cyber Swachhta Kendra | Botnet/malware detection and cleanup (run by CERT-In). |
| CERT-In | National nodal agency for cyber incident response. |
| NPCI Fraud Risk Management (FRM) | Real-time fraud monitoring for UPI / IMPS transactions. |
Graded (Tiered) Approach for Urban Co-operative Banks
RBI later extended cybersecurity norms to Urban Co-operative Banks (UCBs) through a graded / tiered framework (2019, updated 2020). UCBs are classified into four levels based on their digital depth and connectivity, with progressively stricter controls at higher levels. This proportionate approach helps smaller banks comply without bearing big-bank costs.
Latest Update: RBI IT Governance Master Direction, 2023
The most important recent development is the RBI (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023, issued on 7 November 2023 and effective from 1 April 2024. It consolidates earlier scattered IT and cyber instructions into one master framework.
- Applies to: Scheduled Commercial Banks (excluding RRBs), Small Finance Banks, Payments Banks, NBFCs in the Top/Upper/Middle layers, Credit Information Companies, and All-India Financial Institutions (EXIM, NABARD, NaBFID, NHB, SIDBI).
- Focus areas: Strategic alignment, risk management, resource management, performance management, and business continuity / disaster recovery.
- Requires: A Board-level IT Strategy Committee, an IT Steering Committee, and a senior Head of IT.
- Note: The 2016 Cyber Security Framework still applies as a sector-specific overlay alongside the 2023 Master Direction.
Cyber Threats Addressed
- Phishing, vishing and smishing.
- Malware and ransomware attacks.
- SIM swap and Account Takeover (ATO).
- UPI fraud and QR-code scams.
- Mobile-banking cloning.
- DDoS attacks on banking infrastructure.
- ATM jackpotting.
- Insider fraud and privilege misuse.
Benefits and Limitations
The framework strengthens customer trust, reduces financial crime and data breaches, ensures uninterrupted secure banking, aligns India with global standards, and improves threat monitoring. However, it faces real challenges: cyber threats evolve faster than defences (constant upgrades needed), success still depends on customer awareness (social-engineering attacks persist), implementation cost is high (small banks and co-operatives struggle), and complex vendor/fintech integration creates new weak points.
2-Minute Quick Revision Sheet
- Framework introduced: 2 June 2016 (Circular RBI/2015-16/418).
- Supervisor: CSITE Cell, RBI, Mumbai.
- Three Annexes: Baseline controls, C-SOC, Incident Reporting format.
- Board of Directors: ultimate responsibility for cyber governance.
- Incident reporting window: 2–6 hours to RBI.
- Core tools: SOC, MFA, VAPT, CCMP, encryption.
- Key updates: Digital Payment Security Controls (2021); IT Governance Master Direction (2023, effective April 2024).
- Related bodies: CERT-In, Cyber Swachhta Kendra, NPCI FRM, Central Fraud Registry.
- Cyber fraud helpline: 1930.
- Principles: CIA triad; Zero Trust (“never trust, always verify”); Defence-in-depth.
- Data localisation: payment data stored only in India.
Most Important MCQs — RBI Cyber Security Framework
Read each question with its options, attempt it, then click “Show Answer” to check. Useful for IBPS, SBI, RBI Grade B, NABARD, JAIIB and CAIIB.
How this topic is tested: Note that RBI, IIBF and IBPS do not officially release their question papers, so these are original practice questions modelled on the patterns examiners favour. Across recent cycles, questions cluster around a few reliable angles — the date and circular of the 2016 framework, who holds responsibility (Board of Directors / CSITE Cell), full forms (SOC, CCMP, VAPT, CSITE), the incident-reporting window, the data-localisation rule, and the 2023 IT Governance Master Direction. Master these facts and you cover the high-probability questions.
Chapter 1: Basics & Governance
Q1. The primary objective of RBI’s Cyber Security Framework for banks is to:
a) Increase rural branch expansion b) Regulate priority sector lending c) Strengthen resilience of IT systems against cyber threats d) Promote cash-based transactions
Show Answer
Answer: c) The framework focuses on protection, detection and response to cyber risks.
Q2. The ultimate responsibility for cyber risk management in a bank lies with the:
a) CISO b) IT Department c) Board of Directors d) Branch Manager
Show Answer
Answer: c) Board of Directors — RBI places overall responsibility for cyber governance on the Board.
Q3. The RBI Cyber Security Framework for Banks was issued on:
a) 2 June 2016 b) 1 April 2014 c) 7 November 2023 d) 1 January 2018
Show Answer
Answer: a) 2 June 2016 (Circular RBI/2015-16/418).
Q4. Banks must adopt which approach towards cyber risk?
a) One-time compliance b) “Set and forget” c) Continuous, dynamic, risk-based d) Paper-based manual
Show Answer
Answer: c) Cybersecurity is an ongoing process, not a one-time task.
Q5. “Cyber Resilience” refers to a bank’s ability to:
a) Increase deposits after an attack b) Withstand, respond to and recover from cyber incidents c) Reduce staff using automation d) Eliminate manual operations
Show Answer
Answer: b) Resilience covers both protection and recovery.
Q6. The framework was initially applicable to:
a) Only foreign banks b) Only cooperative banks c) All scheduled commercial banks (public, private, foreign) d) Only RRBs
Show Answer
Answer: c) It initially targeted scheduled commercial banks, later extended to UCBs and NBFCs.
Q7. Which RBI cell supervises banks’ cybersecurity practices?
a) DRG b) CSITE Cell c) FIU-IND d) BCSBI
Show Answer
Answer: b) CSITE Cell (Cyber Security and IT Examination Cell), based in Mumbai.
Chapter 2: Components & Technical Controls
Q8. Which component monitors threats in real time, 24×7?
a) Customer Call Centre b) Security Operations Centre (SOC) c) HR Training Cell d) Currency Chest
Show Answer
Answer: b) SOC — monitors, detects and responds to incidents round the clock.
Q9. VAPT stands for:
a) Virtual Asset Protection Technique b) Vulnerability Assessment and Penetration Testing c) Verified Audit of Payment Transactions d) Value-added Processing Technology
Show Answer
Answer: b) Used to identify and fix security weaknesses.
Q10. The “Least Privilege” principle means:
a) Employees access all systems anytime b) Users get only the minimum access needed for their role c) Only senior management can access systems d) Access rights never change
Show Answer
Answer: b) It reduces misuse of excess privileges.
Q11. Encryption of critical data mainly ensures:
a) Profitability b) Confidentiality and integrity of data c) Faster onboarding d) Lower CRR
Show Answer
Answer: b) Encryption prevents unauthorised reading or tampering.
Q12. How many annexes does the 2016 Cyber Security Framework contain?
a) One b) Two c) Three d) Five
Show Answer
Answer: c) Three — Baseline controls, C-SOC setup, and the Incident Reporting format.
Q13. Which is NOT a technical requirement of the framework?
a) Firewalls & Intrusion Detection b) Multi-factor authentication c) Hedging of forex exposures d) Patch and vulnerability management
Show Answer
Answer: c) Forex hedging is treasury risk, not cyber risk.
Chapter 3: Digital Payment Security & Customer Protection
Q14. RBI’s Digital Payment Security Controls (2021) mainly aim to secure:
a) Only cash transactions b) Non-digital deposits c) Internet/Mobile Banking, UPI, cards and digital products d) Only export transactions
Show Answer
Answer: c) They focus on end-to-end digital payment security.
Q15. Banks must ensure customers are:
a) Encouraged to share OTP with RM b) Educated regularly about phishing, vishing and fraud c) Prevented from using mobile banking d) Forced to close UPI ID
Show Answer
Answer: b) Customer awareness is a mandatory part of protection.
Q16. RBI’s “Limited Liability of Customers” rule primarily aims to:
a) Put full loss on the customer b) Fix liability only on bank staff c) Balance and limit customer loss if promptly reported d) Ignore small-value frauds
Show Answer
Answer: c) Liability depends on negligence and reporting time.
Q17. NPCI’s Fraud Risk Management (FRM) system mainly helps:
a) Print cheque books b) Early detection and blocking of fraudulent UPI/IMPS transactions c) Open new accounts d) Maintain CRR
Show Answer
Answer: b) FRM supports real-time transaction risk checks.
Q18. For authenticating high-risk transactions, banks should use:
a) Only password b) Password + OTP/PIN + device/biometric factor c) Only customer name d) Only mobile number
Show Answer
Answer: b) Multi-Factor Authentication (MFA) is mandated.
Q19. The national cyber-fraud helpline number is:
a) 1090 b) 1930 c) 1818 d) 1553
Show Answer
Answer: b) 1930
Chapter 4: Incident Response, Reporting & Coordination
Q20. The Cyber Crisis Management Plan (CCMP) refers to:
a) Plan for cash shortage b) Plan for interest-rate hikes c) Organised response plan for major cyber incidents d) Staff transfer plan
Show Answer
Answer: c) CCMP defines roles, actions and escalation for cyber crises.
Q21. Banks must report significant cyber incidents to RBI:
a) Once a year b) Only if loss exceeds ₹10 crore c) Within 2 to 6 hours of detection d) Only if a customer complains
Show Answer
Answer: c) RBI prescribes a 2–6 hour reporting window.
Q22. Coordination with which national agency is important for major cyber incidents?
a) IRDAI b) TRAI c) CERT-In d) FSSAI
Show Answer
Answer: c) CERT-In — the national nodal agency for cyber incidents.
Q23. The RBI’s latest consolidated IT Governance Master Direction came into effect on:
a) 1 April 2024 b) 2 June 2016 c) 1 January 2021 d) 7 November 2023
Show Answer
Answer: a) 1 April 2024 (issued 7 November 2023).
Q24. Vendor / third-party risk management is important because:
a) Vendors run all branches b) Outsourced IT services can be a cyber weak point c) Vendors decide CRR/SLR d) Vendors control interest rates
Show Answer
Answer: b) Fintech, cloud and IT vendors must follow strong security.
Q25. The overall philosophy of RBI’s framework is best summarised as:
a) “Technology first, risk later” b) “Comply now, think later” c) “Security by design, defence-in-depth and continuous monitoring” d) “Only manual controls suffice”
Show Answer
Answer: c) RBI stresses layered security and ongoing vigilance.
Chapter 5: High-Probability Factual Questions
Q26. The RBI’s data-localisation rule (Storage of Payment System Data) requires payment data to be stored:
a) Anywhere globally b) Only in India c) Only in the bank’s home country d) Only on cloud servers
Show Answer
Answer: b) Only in India — directed by the RBI circular dated 6 April 2018, with a six-month compliance window.
Q27. CCMP, a key requirement of the framework, stands for:
a) Cyber Control Management Policy b) Cyber Crisis Management Plan c) Critical Cyber Monitoring Program d) Customer Complaint Management Plan
Show Answer
Answer: b) Cyber Crisis Management Plan
Q28. The full form of “C-SOC” as used in the RBI framework is:
a) Central Security Operations Cell b) Cyber Security Operations Centre c) Continuous Surveillance Operations Code d) Customer Service Online Centre
Show Answer
Answer: b) Cyber Security Operations Centre — its setup is detailed in Annex 2 of the 2016 framework.
Q29. Under which Act did the RBI issue the data-localisation directive for payment systems?
a) Banking Regulation Act, 1949 b) Payment and Settlement Systems Act, 2007 c) RBI Act, 1934 d) IT Act, 2000
Show Answer
Answer: b) Payment and Settlement Systems Act, 2007
Q30. The RBI IT Governance Master Direction, 2023 does NOT apply to which of the following?
a) Scheduled Commercial Banks b) Small Finance Banks c) Regional Rural Banks (RRBs) d) Payments Banks
Show Answer
Answer: c) Regional Rural Banks (RRBs) — they are excluded from the 2023 Master Direction.
Q31. “CIA” in the context of information security stands for:
a) Central Intelligence Agency b) Confidentiality, Integrity, Availability c) Cyber Incident Authority d) Control, Inspection, Audit
Show Answer
Answer: b) Confidentiality, Integrity, Availability — the core CIA triad.
Q32. The “Zero Trust” security model is best described by the principle:
a) “Trust everyone inside the network” b) “Never trust, always verify” c) “Trust but don’t verify” d) “Verify once, trust forever”
Show Answer
Answer: b) “Never trust, always verify”
Q33. RBI extended cybersecurity norms to Urban Co-operative Banks (UCBs) using a:
a) Single uniform standard for all b) Graded / tiered framework with four levels c) Voluntary code d) One-time audit only
Show Answer
Answer: b) Graded / tiered framework with four levels — a proportionate approach based on each UCB’s digital depth.
Frequently Asked Questions (FAQs)
When was the RBI Cyber Security Framework introduced?
It was issued on 2 June 2016 through Circular RBI/2015-16/418, titled “Cyber Security Framework in Banks.”
Who is responsible for cybersecurity governance in a bank?
The Board of Directors holds ultimate responsibility, supported by the CISO and a board-approved cyber-security policy.
What is the cyber-incident reporting timeline to RBI?
Banks must report unusual cyber incidents to RBI’s CSITE Cell within 2 to 6 hours of detection.
What is the latest RBI direction on IT and cyber governance?
The RBI (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023 — issued 7 November 2023 and effective 1 April 2024 — consolidate earlier IT and cyber rules.
What is the cyber fraud helpline number in India?
The national cybercrime helpline is 1930.
Conclusion
The RBI Cyber Security Framework is the backbone of digital banking security in India. For exams, anchor your memory on the key facts: the 2 June 2016 circular, the CSITE Cell as supervisor, the three annexes, the Board’s ultimate responsibility, the 2–6 hour reporting window, and the 2023 IT Governance Master Direction (effective April 2024). Combined with the CIA triad, Zero Trust, and defence-in-depth principles, these points cover almost everything examiners ask on this topic.
