Breaking
Business

SEBI proposes extending IT and cyber security rules to MIIs' subsidiaries

SEBI suggests applying IT and cyber security framework of Market Infrastructure Institutions to their subsidiaries, reflecting on the use of these arms for certain services.

SEBI proposes extending IT and cyber security rules to MIIs' subsidiaries
AI Generated | MinuteBrief Team

The Securities and Exchange Board of India (SEBI) has proposed extending the information technology (IT) and cybersecurity framework currently applicable to Market Infrastructure Institutions (MIIs) to their subsidiaries. MIIs include stock exchanges, depositories and clearing corporations, which are regulated by SEBI and operate under its existing IT and cybersecurity requirements.

The proposal follows observations that MIIs could potentially leverage their subsidiaries to undertake certain activities and services. However, while MIIs are subject to SEBI’s IT and cybersecurity framework, its applicability and regulatory jurisdiction over their subsidiaries are not explicitly defined.

SEBI’s proposal seeks to address this gap by bringing the subsidiaries of MIIs within the scope of the same IT and cybersecurity framework. This would provide broader regulatory oversight of the technology and cyber risks associated with the overall operational structure of MIIs.

The move also reflects SEBI’s focus on ensuring that entities connected to market infrastructure institutions operate under consistent IT and cybersecurity standards. By extending the framework to subsidiaries, the regulator aims to strengthen oversight and address potential risks arising from activities or services carried out through these entities.

Overall, the proposal represents a step towards strengthening IT and cybersecurity governance across the wider MII structure and ensuring that regulatory oversight keeps pace with the way market infrastructure entities organise and undertake their activities.

More from Business