- The 2026 Directions
- The Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued and in force on 31 July 2026.
- ITSC
- IT Strategy Committee — the Board-level committee that oversees IT strategy and IT and cyber risk; it meets at least quarterly.
- ISC
- Information Security Committee — the management committee under the ITSC that manages cyber and information security, headed from the risk management side.
- ACB
- Audit Committee of the Board — oversees IS audit and approves the IS audit policy.
- DAKSH
- The Reserve Bank’s Advanced Supervisory Monitoring System, where banks report cyber incidents within six hours.
- CSOC
- Cyber Security Operations Centre — the function that provides continuous surveillance of the bank’s environment.
- CCMP
- Cyber Crisis Management Plan — the Board-approved plan covering detection, containment, response and recovery.
- VA / PT
- Vulnerability assessment (a systematic search for weaknesses) and penetration testing (an attempt to defeat the security controls, as an attacker would).
- Red teaming
- A simulated adversarial exercise against the bank’s objectives, testing people and processes as well as technology.
- RTO / RPO
- Recovery time objective (how long a system can be down) and recovery point objective (how much data can be lost).
- IB-CART
- The Indian Banks – Centre for Analysis of Risks and Threats, set up by IDRBT for sharing threat intelligence among banks.
- DMARC
- An email authentication standard that stops others sending mail as your domain; the Directions require it.
- Comply or explain
- The approach for foreign bank branches: listed provisions apply unless the bank gives the RBI a justifiable explanation it accepts.
- bank.in
- The domain reserved for Indian banks, registered through IDRBT, so customers can recognise genuine bank websites.