India Hub/IBA/Control Catalogue — IBA Model Cyber Policy
Layer 1 · Risk Managers · Auditors — implementation

IBA Control Catalogue — IBA Model Cyber Policy

Key areas from the IBA Model Cybersecurity Policy and adjacent master circulars, mapped to RBI MD-ITGRC where applicable.

Last verified: June 2026
You're seeing 3 of 10 rows. 7 hidden behind Pro.
Sign in to unlock
#AreaKey IBA GuidanceRBI Cross-Reference
1Information Security GovernanceBoard IT/Risk Committee, CISO with board reporting line, annual cyber risk appetite, dedicated cyber risk budget — IBA template board charters availableAligns with MD-ITGRC §4 (Governance) — IBA expands RBI principles into model board minutes and charter language
2Cyber Hygiene ProgrammeEmployee security awareness at induction + annual refresh; quarterly phishing simulation campaigns; secure coding practices for in-house developers; SOC monitoring of unusual access patternsMaps to MD-ITGRC §22 (Awareness & Training) — IBA prescribes specific simulation cadences
3Vendor Risk (TPRM)IBA template TPRM questionnaire (200+ items) for banks to issue to fintech partners; tiered vendor classification; annual on-site audit for critical vendorsMaps to MD-ITGRC §4 (TPRM) + Outsourcing of IT Services MD 2023
Unlock all 10 rows — Pro

Sign in to unlock — every free trial includes full Pro access to the deep-dive catalogues.

Sign in to unlock

IBA guidance is non-binding but referenced by RBI in supervision. Verify the source IBA document before relying on any specific clause.

Made with Emergent