Compliance hub

SEBI CSCRF: identity and access controls for regulated market entities

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF, 2024) consolidates cyber obligations for regulated entities — brokers, depositories, AMCs, exchanges and intermediaries — around the NIST functions. Its 'Protect' expectations lean heavily on identity: access control, authentication assurance and periodic review. IamLogic delivers that layer with evidence attached.

  • ISO/IEC 27001:2022 certified
  • Made in India
  • On-premises · Cloud · Hybrid
  • SAML · OIDC · OAuth2 · RADIUS
  • 24×7 support

Context

What the framework expects

CSCRF applies a graded approach by entity category, but access control, MFA and log retention expectations run through all categories.

Market infrastructure entities face the strictest timelines and audit cadence; smaller intermediaries still must demonstrate baseline identity hygiene.

CSCRF explicitly expects management of privileged access, review of user rights, and retention of logs to support incident investigation and regulatory reporting.

Identity obligations

The requirements that touch IAM

  • Role-based access control aligned to least privilege
  • Multi-factor authentication for critical system access and remote access
  • Periodic review of access rights, including privileged accounts
  • Segregation of duties across trading, settlement and back-office functions
  • Log collection and retention supporting cyber resilience and audits

Control mapping

Requirement → IamLogic control

The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.

RequirementIamLogic controlProduct
RBAC and least privilegeRole-based access enforced at login through SSO; role model maintained and mined in governanceBoth products
MFA on critical and remote accessAdaptive MFA including VPN protection over RADIUS and passwordless WebAuthnAccess Manager
Periodic access-rights reviewCertification campaigns with enforced revocations and audit-ready sign-off reportsIamLogic IGA
Segregation of dutiesSoD policies across trading, settlement and finance entitlementsIamLogic IGA
Access log retentionCentralised authentication and provisioning logs, retained per CSCRF-aligned policy, deployable fully in IndiaBoth products

This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.

FAQ

Common questions

We're a mid-size broker. Does CSCRF really reach us?

Yes — CSCRF's graded approach lowers the audit cadence for smaller entities but not the core expectations. Access control and MFA are baseline for every category.

Map SEBI CSCRF to your environment

A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.