# SEBI Cybersecurity and Cyber Resilience Framework for Regulated Entities

Framework id: `sebi_cscrf`. Financial Regulation. Publisher: Securities and Exchange Board of India (SEBI). Version: 2024. Region: India. Mapping licence: CC BY-SA 4.0.
Source text: https://www.sebi.gov.in/

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (41, average coverage 74%)
- AUDIT Periodic Audit and Compliance Reporting: CA-02, CA-05, CA-06, CA-07, AU-06, PM-06, PM-14 (62%)
- BCP-DR Business Continuity and Disaster Recovery: CP-01, CP-02, CP-03, CP-04, CP-05, CP-06, CP-07, CP-08, CP-09, CP-10, CP-11, PM-08, PM-11 (82%)
- CAPACITY Capacity Building and Cyber Awareness: AT-01, AT-02, AT-03, AT-04, AT-05, AT-06, PM-13, PM-15, PM-27 (72%)
- CCI Cyber Capability Index Assessment: CA-02, CA-07, PM-06, PM-14, PM-31 (58%)
- CCMP Cyber Crisis Management Plan: CP-02, CP-03, CP-04, IR-01, IR-03, IR-08, PM-08, PM-09 (68%)
- CERTIF ISO 27001 Certification and Standards Compliance: CA-02, CA-06, CA-09, PM-01, PM-10 (50%)
- CLASSIFY Entity Classification and Compliance Matrix: PM-01, PM-10, PM-11, PM-32, RA-02, PL-02 (42%)
- CYBER-INS Cyber Insurance: PM-09, PM-11 (25%)
- DATALOC Data Localisation and Cross-Border Data Transfer: SC-28, SC-12, SC-13, PT-02, PT-04, PT-05, AC-04, SI-12 (45%)
- DE.AU Detect — Audit Logging and Monitoring: AU-01, AU-02, AU-03, AU-04, AU-05, AU-06, AU-07, AU-08, AU-09, AU-10, AU-11, AU-12, AU-14 (90%)
- DE.CM Detect — Security Continuous Monitoring and SOC: SI-04, AU-06, AU-13, CA-07, IR-04, PM-14, PM-31, SC-26, SC-35, RA-10 (78%)
- DE.DP Detect — Detection Processes and Threat Intelligence: SI-03, SI-04, SI-05, PM-16, RA-05, RA-10, SC-44, AU-12 (82%)
- DE.VA Detect — Vulnerability Assessment and Penetration Testing: CA-02, CA-08, RA-05, RA-06, RA-07, RA-09, RA-10, PM-14 (78%)
- EMAIL-SEC Secure Communication and Email Security: SC-07, SC-08, SC-13, SI-08, AC-04 (82%)
- GV.OC Governance — Organisational Context: PM-01, PM-07, PM-08, PM-09, PM-11, PM-28, PM-32, PL-08, RA-09 (75%)
- GV.OV Governance — Oversight and Compliance: CA-02, CA-05, CA-06, CA-07, PM-06, PM-14, PM-31 (65%)
- GV.PO Governance — Cybersecurity and Cyber Resilience Policy: PM-01, PL-01, PL-02, PL-04, PM-09, PM-10, PM-11, PM-24 (72%)
- GV.RM Governance — Cyber Risk Management Framework: PM-01, PM-09, PM-28, PM-29, PM-30, RA-01, RA-03, RA-07, RA-09, PL-09 (80%)
- GV.RR Governance — Roles, Responsibilities and Authorities: PM-02, PM-13, PS-01, PS-02, PS-03, PS-06, PS-07, PS-09 (68%)
- GV.SC Governance — Supply Chain Risk Management: SA-04, SA-09, SA-21, SA-22, SR-01, SR-02, SR-03, SR-05, SR-06, PM-30, PS-07 (78%)
- ID.AM Identify — Asset Management: CM-08, CM-09, CM-12, CM-13, PM-05, RA-02, RA-09 (88%)
- ID.RA Identify — Risk Assessment: RA-01, RA-02, RA-03, RA-05, RA-07, RA-08, RA-09, RA-10, PM-16 (85%)
- PR.AA Protect — Identity Management, Authentication and Access Control: AC-01, AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-10, AC-11, AC-12, AC-17, AC-24, IA-01, IA-02, IA-04, IA-05, IA-06, IA-08, IA-12 (88%)
- PR.AS Protect — Application Security and SBOM: SA-03, SA-04, SA-08, SA-10, SA-11, SA-15, SA-17, SA-20, SA-21, SI-10, SR-04 (80%)
- PR.AT Protect — Awareness and Training: AT-01, AT-02, AT-03, AT-04, AT-05, AT-06, PM-13, PM-15 (82%)
- PR.CS Protect — Cloud Security: SA-09, AC-20, SC-07, SC-08, SC-28, SR-01, SR-06, CA-03 (72%)
- PR.DS Protect — Data Security and Classification: SC-08, SC-12, SC-13, SC-28, MP-01, MP-02, MP-04, MP-05, MP-06, AC-04, AC-23, SI-12, SI-19, SI-20, PT-02, PT-03 (78%)
- PR.ES Protect — Endpoint and Platform Security: CM-06, CM-07, CM-10, CM-11, CM-14, SC-18, SC-41, SI-03, SI-07, SI-16, AC-19 (86%)
- PR.IP Protect — Information Protection Processes and Procedures: CM-01, CM-02, CM-03, CM-04, CM-05, CM-06, CM-07, CM-10, CM-11, CM-14, SI-02, SI-07, SA-03, SA-08, SA-10, SA-11, SA-15 (87%)
- PR.MA Protect — Maintenance: MA-01, MA-02, MA-03, MA-04, MA-05, MA-06, SI-13 (88%)
- PR.NS Protect — Network Security and Segmentation: SC-01, SC-05, SC-07, SC-08, SC-20, SC-21, SC-22, SC-32, SC-39, SC-44, SC-47, AC-04, SI-04 (85%)
- PR.PE Protect — Physical and Environmental Security: PE-01, PE-02, PE-03, PE-04, PE-05, PE-06, PE-08, PE-09, PE-10, PE-11, PE-12, PE-13, PE-14, PE-15, PE-17, PE-18, PE-20 (87%)
- RC.CO Recover — Recovery Communication: IR-06, CP-02, PM-26, PM-27 (60%)
- RC.IM Recover — Recovery Improvements: CP-02, CP-04, CA-02, CA-05, PM-04, PM-14 (80%)
- RC.RP Recover — Incident Recovery Plan Execution: CP-01, CP-02, CP-04, CP-06, CP-07, CP-08, CP-09, CP-10, CP-11, CP-12, CP-13, SC-24, SI-17 (82%)
- RS.AN Respond — Incident Analysis and Forensics: AU-06, AU-09, AU-10, AU-11, IR-04, IR-05, IR-09, SI-04 (78%)
- RS.CO Respond — Incident Reporting and Communication: IR-06, PM-15, PM-16, PM-26, SI-05 (55%)
- RS.IM Respond — Incident Response Improvements: IR-04, IR-05, IR-08, CA-02, CA-05, CA-07, PM-04 (82%)
- RS.MA Respond — Incident Management: IR-01, IR-02, IR-03, IR-04, IR-05, IR-07, IR-08, IR-09 (80%)
- SOC Security Operations Centre Requirements: SI-04, AU-06, CA-07, IR-04, IR-05, PM-14, PM-16, SC-26, RA-10 (75%)
- VAPT VAPT and Red Team Exercises: CA-02, CA-08, RA-05, RA-06, RA-07, RA-09, RA-10, PM-14 (76%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=sebi_cscrf
- Control-to-clause mappings as JSON: /api/v1/frameworks/sebi_cscrf?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/sebi-cscrf.json
- Page for people: /frameworks/sebi-cscrf/
