• Jll \4Hffl4 ~ ~f.i41qcfi ;,m Rlctim ~ •ul••r1th INSURANCE REGULATORY AND hdai DEVELOPMENT AUTHORITY OF INDIA Ref: IRDA/IT/CIR/MISC/232/10/2017 1 ih October, 2017 TO, CMDs/ CEOs - LIFE INSURERS, GENERAL INSURERS, HEAL TH INSURERS AND REINSURERS Re: Compliance on Guidelines related to Information and Cyber Security. We…
• Jll \4Hffl4 ~ ~f.i41qcfi ;,m Rlctim ~ •ul••r1th INSURANCE REGULATORY AND hdai DEVELOPMENT AUTHORITY OF INDIA Ref: IRDA/IT/CIR/MISC/232/10/2017 1 ih October, 2017 TO, CMDs/ CEOs - LIFE INSURERS, GENERAL INSURERS, HEAL TH INSURERS AND REINSURERS Re: Compliance on Guidelines related to Information and Cyber Security. We draw your attention to IRDAI Circular Ref: IRDA/IT/GDUMISC/082/04/2017 dated 7th April, 2017 setting out guidelines on Information and Cyber Security for Insurers. From the feedback/ updates received from Insurers, it is observed that many of the insurers still have not finalised their Gap Analysis report, Cyber Crisis Management Plan and Board approved Information & Cyber Security Policy. Ensuring that Information and Computer Technology (ICT) infrastructure of insurers are fully secured is of paramount importance. Any Vulnerabilities to !CT may result in compromise on confidentiality of policyholder related information and exposure to sensitive information of the insurance sector and the financial markets in general. This would have serious repercussions not only for the Insurance sector but for the financial system of the country as a whole. Therefore, Insurers are advised to take immediate steps for conducting Security Audit for their ICT infrastructures including Vulnerability Assessment and Penetration Tests (VAPT) through Cert-in empanelled Auditors, identify the gaps and ensure that audit findings are rectified swiftly. Insurers are al!so requested to firm-up their Cyber Crisis Management Plan (CCMP) for handling cyber incidents more effectively. The recently registered insurers and Reinsurers also must ensure that steps are taken for implementation of the Guidelines. In case CISOs have not yet been appointed by the recently registered entities, they are advised to ensure that they are appointed immediately. Further, in case of insurers who have not kept up the timelines given in the Guidelines referred above, they are advised to ensure to scale up their activities to comply with them. Confirmation of having noted the above and plan of action proposed may be submitted to it@irda.gov.in by 1 yth October, 2017. ,~ -~ \ 1 (Dr. Marut · P asad Tangirala) ~ Executive Director (IT) tffi'!Pl" 'lfi:R", "iftBU <'R"I, ~-~-500 004. ~ (() ; 91-040-2338 1100. ~; 91-040-6682 3334 · ,hr; www.lrda.gov.in Parisharam Bhavan, 3rd Floor. Basheer Bagh, Hyderabad-500 004. India. Ph.: 91-040-2338 1100, Fax: 91-040-6682 3334 Web.: www.irda.gov.in
Research the source law
This record is not yet linked to a specific provision. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source laws