Irda issues cyber security norms of insurers

MUMBAI: The Insurance Regulatory and Development Authority of India has asked insurance companies to have board approved information/cyber security policy by 31 July 2017.

The regulator has asked companies to have a cyber security assurance program to be approved by the Board by 30 September 2017. It has asked insurers to appoint chief information security officer who would be responsible for enforcing policies to protect information assets. CISO would be head of risk management and will have working relationship with CIO.

The regulator laid down cyber security guidelines classifying critical systems, cyber resilience program, identification, detection and protection.

The regulator has asked insurers to segregate IT & Information Security functions. Also, information security as a function cannot be outsourced.

It has asked insurers to form information security committee comprising of operations, IT, legal, finance, compliance etc. – headed by a senior official reporting into Board.

Related Articles

Defence, cyber security among 22 pacts inked between India, Bangladesh

Sharing information key to ensure cyber security: Experts

India, US renew agreement for cyber security coordination

New cyber security norms send wallet firms in a tizzy

Stay on top of business news with
The Economic Times App.
DOWNLOAD NOW
FROM AROUND THE WEB MORE FROM ECONOMIC TIMES

Have let my emotions slip, I apologise: Steve Smith

Rupee hits 65 mark for first time since Oct 2015

Government slaps 10% import duty on wheat, tur dal

From Around the WebMore from The Economic Times

Buy 2 BHK luxury apartments in Kalwa (W)

Wadhwa Evergreen

Great looking ergonomic office chairs

By Workstore.in

Where Are You Planning This Weekend Getaway?

Ola Outstation

Book your home @53K only in Delta Vrindavan

Delta Venture