Markets regulator Securities and Exchange Board of India (Sebi) on Monday decided to introduce an IT Resilience Index (ITRI) to assess the functioning and resilience of information technology systems of market infrastructure institutions (MIIs), including stock exchanges, depositories and clearing corporations.
The move is aimed at strengthening oversight of the resilience of IT systems and identifying emerging weaknesses at an early stage, so that timely corrective measures can be taken.
Under the framework, the ITRI will be computed using a uniform set of nine parameters, each carrying a specific weightage to ensure comparability across MIIs, Sebi said in its circular.
Availability and security will carry the highest weightage of 20 per cent each, followed by integrity, governance, reliability and monitoring, business continuity, and modularity and flexibility at 10 per cent each.
Scalability and other aspects, including incident handling, will account for the remaining 5 per cent each.
MIIs have already implemented the beta version of the ITRI framework and will operationalise the framework, including the EWS and real-time monitoring of service delivery, by February 28, 2027.
The first ITRI computation under the framework will cover the half-year ended March 31, 2027.
MIIs will compute the index on a half-yearly basis within 60 days of the end of each half-year and submit a comparative analysis of two consecutive half-years, along with corrective actions taken or proposed, to their Standing Committee on Technology (SCOT) and governing boards.
Sebi said the computation of ITRI will be system-driven to ensure that the process remains objective, non-discretionary and foolproof.
In case any parameter cannot be computed automatically and requires manual intervention, the MII will undertake manual data retrieval only after discussing the exception with its SCOT.
The framework is designed as a self-operating model under which MIIs will periodically compute the ITRI and provide their governing boards with an assessment of the overall health of IT systems and areas requiring improvement.
Sebi said MIIs already continuously monitor the performance of processes and applications, as well as utilisation of system resources at the component level, to enable early detection of possible performance issues and system slowness.
Under the framework, MIIs will also build systems providing continuous visibility into service delivery to market participants. These systems will include consolidated dashboards for monitoring system and application performance, service delivery and any deviations or anomalies.
MIIs will further formulate SOPs to monitor system availability and continuity of service delivery to market participants and flag any disruption or deviation.
The framework has been formulated to strengthen performance monitoring, ensure timely service delivery to market participants, identify emerging weaknesses in IT systems at an early stage and facilitate timely corrective action, Sebi said.
In a separate circular, Sebi said it has aligned its Incident Reporting Portal with the “Format for Incident Reporting Exchange (FIRE)” framework developed by the Financial Stability Board (FSB) in order to streamline the reporting of cyber incidents.
FIRE enables structured incident reporting by defining common information fields, standardised definitions, and consistent classification of incident attributes, promoting harmonisation across sectors or jurisdictions.
“The portal will facilitate reporting of incidents in stages to reflect the incident life cycle from initial reporting to intermediate updates and final closure, while acknowledging that certain information may not be available at the time of initial reporting,” Sebi said.
Sebi asked regulated entities (REs) to report cyber incidents through the Cyber Incident Reporting Portal of Sebi, which can be accessed by logging into https:iportal.sebi.gov.in.
