ब्लॉग

क्या आपके bank का email सच में “RBI-Ready” है? एक control-by-control reality check

English

क्या आपके bank का email सच में RBI-ready है? XgenPlus की तरफ से एक control-by-control reality check।

भारत के हर bank, NBFC और insurer के लिए email आज भी मुख्य दरवाज़ा है, और attackers सबसे पहले इसी दरवाज़े पर दस्तक देते हैं। Phishing, business email compromise (BEC) और senior executives की impersonation, आज भी fraud और data leakage की शुरुआत सबसे ज्यादा इन्हीं रास्तों से होती है। Regulators यह जानते हैं, इसीलिए email सीधे उन चीज़ों के दायरे में आता है जिन पर वे regulated entities से control की उम्मीद रखते हैं।

लेकिन एक असुविधाजनक सवाल है जिसका ज्यादातर IT और compliance टीमें साफ जवाब नहीं दे पातीं: क्या आप control by control दिखा सकते हैं कि आपका email platform regulator की उम्मीदों पर खरा उतरता है?

Regulators email से असल में क्या उम्मीद रखते हैं

भारतीय BFSI के लिए कई frameworks सीधे email को छूते हैं:

  • RBI Cyber Security Framework: strong authentication, least-privilege access, transit और rest दोनों में encryption, और continuous audit।
  • RBI Digital Payment Security Controls: anti-phishing, sender authentication, और customer communications की integrity।
  • RBI data-localisation direction: customer और payment data भारत के भीतर ही store हो।
  • CERT-In Directions (2022): security logs retain करना, synchronised time रखना, और incidents की तेज़ी से reporting के लिए तैयार रहना।
  • DPDP Act (2023): lawful और minimised processing; data-principal safeguards; accountability और breach readiness (Act खुद भारत में storage को mandate नहीं करता; payment data के लिए RBI ऐसा करता है)।

इनमें से कोई भी आपको ऐसा checkbox नहीं देता जिस पर लिखा हो “email: compliant”। ये controls बताते हैं, और हर उम्मीद को एक specific technical control से map करना और inspection के दौरान उसका evidence देना, यह ज़िम्मेदारी institution की है।

वह ईमानदार बात जिसकी कोई marketing नहीं करता

कोई भी email product “RBI-certified” नहीं होता। जो कोई आपको इसके उलट बताता है, वह आपको ऐसी कहानी बेच रहा है जिसे आपको auditor के सामने वापस लेना पड़ेगा। एक अच्छा platform आपको देता है वह infrastructure और controls जिनसे आप इन obligations को साफ-साफ demonstrate कर सकें: data-in-India, SPF/DKIM/DMARC, S/MIME encryption और signing, MFA और role-based access, DLP, और पूरे audit trails; साथ में deployment की flexibility (cloud, private cloud, या on-premise/air-gapped) ताकि data-sovereignty और jurisdiction की requirements पूरी हो सकें।

यही फर्क, aligned controls, न कि कोई compliance certificate, ठीक वही तरीका है जिससे आपकी अपनी audit और compliance functions को भी इसे देखना चाहिए।

एक checklist जिस पर आपकी IS-audit टीम सीधे काम कर सकती है

हमने एक control-by-control mapping worksheet बनाई है: हर regulatory उम्मीद (RBI, CERT-In, DPDP), email के लिए उसका मतलब क्या है, और कौन सा specific control उसे support करता है, साथ में ईमानदार markers कि आज क्या available है और क्या हर deployment के हिसाब से confirm किया जाता है। यही वह document है जिसे लेकर आपके auditors और CISO किसी solution-design workshop में बैठ सकते हैं।

→ RBI-Aligned Email Security Checklist download करें

अगर आपका email उन controls से साफ-साफ map नहीं हो पाता, तो यह बात inspection से पहले जान लेना बेहतर है, inspection के दौरान नहीं।

← सभी पोस्ट पढ़ें