Cyber Society wants RBI to empanel info security auditors

January 30, 2012 10:54 pm | Updated October 18, 2016 02:26 pm IST - CHENNAI:

In what is termed a significant suggestion, Cyber Society of India has asked the Reserve Bank of India (RBI) to raise a pool of ‘empanelled information security auditors' across the country. They could then be deployed or allotted to different banks like the RBI allots statutory auditors.

“All the banks do not have a proper information security policy and audit system. They have their own internal audit. Or, they get audited through their own known auditors,” according K. Srinivasan, President of the Cyber Society of India.

Mr. Srinivasan said the Cyber Society had asked the apex bank to empanel information security auditors based on specified minimum qualification and experience. “After auditing the banks, they could submit the report to the RBI and banks. This will improve the quality of information security audit,” he felt. From this year onwards, that is, March 2012, all banks are required to declare their information security status (IS) in their annual reports as per the Gopalakrishna Committee report. This is for the first time that the banking industry is going to declare such IS status. “Hence, an audit by competent RBI-nominated IS auditors may improve the quality of information security in banks,” he said.

The Cyber Society of India also wanted RBI to issue a fiat to all banks, making it mandatory for them to send out mobile alerts to their clients on withdrawals.

At present, mobile alerts are given by banks only on request. “Even educated customers are not aware of this facility.

Many cyber crime police cases could have been avoided, if the customers had a mobile alert,” Mr. Srinivasan said. Customers should get mobile alerts by default. “Only if they do not want, they have to request the bank, like ‘do not disturb' model,” he pointed out. “We are in the initial stage. Customer awareness is very low. Even a remote rural person is having credit and debit cards. All these justify the importance of information security to protect the interest of the customers," he added.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.