CourtMesh

Section 23: Data security and system integrity safeguards

The Credit Information Companies (Regulation) 2005 - RulesCentral Rules · 2005

Every credit institution shall adopt such procedure and measures in relation to their daily operations as may be necessary to safeguard and protect the data, information and the credit information maintained by them, against any unauthorised access to or misuse of the same including the following safeguards, namely: -

(a) adopting the minimum standards for physical and operational security including site design, fire protection, environmental protection;

(b) keeping the round the clock physical security;

(c) issuance of instructions for removing, labeling and securing the removable electronic storage media at the end of the session or working day;

(d) providing physical access to the critical systems to be on dual control basis;

(e) making comprehensive succession plan for the key personnel so as to ensure that non-availability of a person does not disrupt the system;

(f) keeping of paper based records, documentation and backup data containing all confidential information in secured and locked containers or filing system, separately from all other records;

(g) adopting adequate procedure to ensure that the records could be accessed only by authorized persons on need to know basis;

(h) providing details of creation of firewalls and stress testing of systems through ethical hacking to evaluate and ensure its robustness;

(i) protecting systems against obsolescence;

(j) adopting procedure for change of software and hardware ;

(k) providing for disaster recovery and management plan; and

(l) taking necessary steps while handing over systems for maintenance to prevent unauthorized access or loss of data, information and credit information maintained by them.

CHAPTER IV 31 STEPS AND SECURITY SAFEGUARDS TO BE TAKEN BY CREDIT INFORMATION COMPANIES AND SPECIFIED USERS FOR ENSURING ACCURACY, COMPLETENESS AND PROTECTION OF DATA

Where this provision sits

ActThe Credit Information Companies (Regulation) 2005 - Rules
Section23
Marginal noteData security and system integrity safeguards
JurisdictionCentral
StatusIn force as published by the source

Find the provision, not just read it

The full text above is free, and it stays free. What a free CourtMesh account adds is everything you cannot do by reading one page at a time:

  • Search 49,000+ Central and State enactments by what a provision says, not by its number
  • Jump from any section to every judgment that has applied it
  • Search 300 million+ Indian court records alongside the statute
  • Ask a research agent to find and read the case law on a provision for you

Free account. No card. About a minute to create.

Create a free account

Need this as data, not as a page? The Credit Information Companies (Regulation) 2005 - Rules is one of 49,000+ enactments on CourtMesh. The Indian court cases API serves the case law that cites these provisions over JSON, with API documentation and plans and pricing. See also the judgment library.