India Account Aggregator Framework (RBI)
RBI AA Incident Response + Resilience

India Account Aggregator Framework (RBI) RBI-AA-IncidentResponse-Resilience-RBI-CERT-In-BCP-DR-Continuity: RBI AA Incident Response + Resilience - Cyber Incident Reporting to RBI + CERT-In + Business Continuity + Disaster Recovery + Resilience + Customer Communication + Forensics

Incident Response and Resilience are critical for the trust foundation of the AA ecosystem given the sensitive financial data flowing through it. (1) Incident Reporting: cyber security incidents reported to RBI via prescribed RBI Cyber Security Incident Report template + CERT-In within 6 hours per CERT-In Directions of 28 April 2022 + Department of Telecommunications (DoT) where applicable + Sahamati for ecosystem-wide awareness + DPDP Act 2023 breach notification to Data Protection Board of India (DPBI) within 72 hours for personal data breaches affecting customers + customer breach notification per DPDP Sec 8(6). (2) Incident Categories: data breach + unauthorised data access + ransomware + DDoS + insider threat + supply chain compromise + cryptographic key compromise + consent forgery + AA portal compromise + FIP/FIU API misuse + customer account takeover + payment fraud (if linked to AA-enabled lending). (3) Incident Response Plan: documented IR plan + IR team + IR phases (Detection + Containment + Eradication + Recovery + Lessons Learned) + tabletop exercises + crisis communication procedures + legal counsel engagement + forensics readiness + chain of custody. (4) Business Continuity Plan (BCP): aligned with RBI Guidelines on Information Security and Cyber Security + RBI Guidelines on Business Continuity Planning + RTO (Recovery Time Objective) per system criticality + RPO (Recovery Point Objective) + DR site in India per data localisation + redundant infrastructure + active-active or active-passive architecture + DR drills + crew training + alternate processing site + manual procedures + customer continuity (consent dashboard available during DR). (5) Resilience: continuous availability targets + capacity planning + scaling for traffic spikes + DDoS mitigation + Web Application Firewall (WAF) + bot management + rate limiting + degraded mode operation. (6) Customer Communication: notification of unavailability + customer status page + SLA commitments + RTO/RPO commitments transparent to customers + dispute escalation. (7) Forensics: forensically sound investigation capability + log preservation + chain of custody + cooperation with law enforcement (CERT-In + I4C Indian Cyber Crime Coordination Centre + state police cyber cells). Coordinates with RBI Cyber Security Framework + RBI BCP Guidelines + CERT-In Directions 28 April 2022 + DPDP Act 2023 Section 8(6) + ISO 22301 BCMS + ISO 27035 + NIST SP 800-61 + Sahamati incident sharing + India Cyber Crime Coordination Centre (I4C). RBI AA Incident Response + Resilience applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.