Author: Vinayak P

IRDAI Item 14: Centralised Authentication as a Compliance Requirement

Introduction IRDAI ICS Annexure III Item 14 requires that all access to organisational systems be authenticated through a centralised authentication…

3 weeks ago

GDPR for Indian Companies: What EU Data Protection Law Requires From Your Technical Infrastructure

Indian companies with EU customers, EU operations, or EU-based employees are subject to the General Data Protection Regulation regardless of…

1 month ago

SOC 2 Type II for Indian ITeS and BPO: Implementing Trust Services Criteria

SOC 2 Type II has become a commercial prerequisite for Indian ITeS and BPO companies serving enterprise clients in North…

1 month ago

ISO 27001:2022 Annex A Access Controls: A Technical Guide for IT and Security Teams

ISO 27001:2022 reorganised the Annex A control set from 114 controls across 14 domains to 93 controls across four themes.…

1 month ago

IRDAI ICS Guidelines: Technical Requirements for Indian Insurance Companies

The Insurance Regulatory and Development Authority of India's Information and Cyber Security Guidelines, 2023 apply to all insurers, re-insurers, and…

1 month ago

SEBI CSCRF Explained: Technical Requirements for Capital Markets Entities

The Securities and Exchange Board of India's Cybersecurity and Cyber Resilience Framework applies to all SEBI-regulated entities: stock brokers, depository…

1 month ago

RBI IT Governance and Cybersecurity Framework: What Regulated Entities Must Implement

The Reserve Bank of India's 2023 Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices applies to all…

1 month ago

Five IAM Controls Every Major Compliance Framework Requires

Your organisation is likely operating under more than one compliance framework. RBI if you are a bank or NBFC. SEBI…

1 month ago

What DPDPA Actually Requires From Your IT Team

The Digital Personal Data Protection Act, 2023 is not a policy compliance exercise. The obligations it creates land directly on…

1 month ago

PAM Coverage Gaps on Linux: Why SSH Sessions Are Your Highest-Risk Ungoverned Access

Your PAM platform covers privileged access. Ask your infrastructure team how much of it, and the answer will involve a…

1 month ago