Compliance hub
SEBI CSCRF: identity and access controls for regulated market entities
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF, 2024) consolidates cyber obligations for regulated entities — brokers, depositories, AMCs, exchanges and intermediaries — around the NIST functions. Its 'Protect' expectations lean heavily on identity: access control, authentication assurance and periodic review. IamLogic delivers that layer with evidence attached.
Context
What the framework expects
CSCRF applies a graded approach by entity category, but access control, MFA and log retention expectations run through all categories.
Market infrastructure entities face the strictest timelines and audit cadence; smaller intermediaries still must demonstrate baseline identity hygiene.
CSCRF explicitly expects management of privileged access, review of user rights, and retention of logs to support incident investigation and regulatory reporting.
Identity obligations
The requirements that touch IAM
- Role-based access control aligned to least privilege
- Multi-factor authentication for critical system access and remote access
- Periodic review of access rights, including privileged accounts
- Segregation of duties across trading, settlement and back-office functions
- Log collection and retention supporting cyber resilience and audits
Control mapping
Requirement → IamLogic control
The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.
| Requirement | IamLogic control | Product |
|---|---|---|
| RBAC and least privilege | Role-based access enforced at login through SSO; role model maintained and mined in governance | Both products |
| MFA on critical and remote access | Adaptive MFA including VPN protection over RADIUS and passwordless WebAuthn | Access Manager |
| Periodic access-rights review | Certification campaigns with enforced revocations and audit-ready sign-off reports | IamLogic IGA |
| Segregation of duties | SoD policies across trading, settlement and finance entitlements | IamLogic IGA |
| Access log retention | Centralised authentication and provisioning logs, retained per CSCRF-aligned policy, deployable fully in India | Both products |
This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.
FAQ
Common questions
We're a mid-size broker. Does CSCRF really reach us?
Yes — CSCRF's graded approach lowers the audit cadence for smaller entities but not the core expectations. Access control and MFA are baseline for every category.
Map SEBI CSCRF to your environment
A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.