परिपत्र सं.:पीएफआिडीए/2025/05/आईसीएस/01 04.09.2025 परिपत्र सेवा में सभी मध्यस्थ एवं ववनियममत संस्थाएँ ववषय: साइबि सुिक्षा घटिाओं के वर्गीकिण संबंधी दिशा-नििेश 1. यह परिपत्र सं. PFRDA/24/14/ICS/01 दिन ंक 01.08.2024 से संबद्ध है, जो मध्यस्थों/विननयममत संस्थ ओं हेतु सूचन एिं स इबि सुिक्ष नीनत दिश -ननिेश – 2024 से संबंधधत…
पेंशन निधि विनियामक और विकास प्राधिकरण PENSION FUND REGULATORY AND DEVELOPMENT AUTHORITY
परिपत्र सं.:पीएफआरडीए/2025/05/आईसीएस/01 04.09.2025
परिपत्र
सेवा में सभी मध्यस्थ एवं विनियमित संस्थाएँ
विषय: साइबर सुरक्षा घटनाओं के वर्गीकरण संबंधी दिशा-निर्देश
कविता सिंगम जेवियर
महाप्रबंधक सूचना एवं साइबर सुरक्षा विभाग
Circular No.: PFRDA/2025/05/ICS/01 04.09.2025
CIRCULAR
To All Intermediaries & Regulated entities
Subject: Guidelines on Classification of Cybersecurity Incidents
Kavita Singam Xavier
General Manager Information & Cyber Security Department
Annexure I
Guidelines on Classification of Cybersecurity Incidents
| S. No. | Category | Parameters |
|---|---|---|
| 1 | Critical | Cyber incidents of critical nature (such as successful penetration or Denial of Service attacks detected with significant impact on operations; ransomware attack; exfiltration of sensitive data; widespread instances of data corruption causing impact on operations; significant risk of negative financial or public relations impact, etc.) on any part of IT infrastructure. |
| 2 | High | Penetration or Denial of Service attacks attempted with limited impact on operations; widespread instances of a new malwares not handled by anti-virus software; unauthorized access to servers and network devices; unauthorized or unexpected configuration changes on network devices detected; data exfiltration; unusually high count of phishing emails; instances of outbound phishing emails; some risk of negative financial or public relations impact, etc. |
| 3 | Medium | Target recon or scans detected; penetration or Denial of Service attacks attempted with no impact on operations; widespread instances of known malwares easily handled by antivirus software; isolated instances of a new malwares not handled by anti-virus software; instances of phishing emails that were not recognized by employees and were clicked by them; instances of data corruption, modification and deletion being reported, etc. |
| 4 | Low |
Research the source law
This record is not yet linked to a specific provision. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source laws| System probes or scans detected on external systems; intelligence received concerning threats to which systems may be vulnerable; intelligence received regarding username password compromise; isolated instances of known malwares easily handled by antivirus software, etc. |