CA NeWs Beta*: MCX India Auditor Selection Norms for Cyber Security & Cyber Resilience Audit of Member

Search This Site

Friday, July 24, 2020

MCX India Auditor Selection Norms for Cyber Security & Cyber Resilience Audit of Member


Cyber Security & Cyber Resilience Audit

Cyber Security & Cyber Resilience Audit of Member

In view of the circular issued regarding Cyber Security & Cyber Resilience Audit of Trading Members of the Exchange issued by SEBI, the members using trading software are required to conduct Cyber Security & Cyber
Resilience Audit of their trading facility in accordance with the Cyber Security & Cyber Resilience Framework which includes auditor selection norms, Terms of Reference (ToR). Separate ToRs are specified for the Members as categorized below:-
  1. Type I - Members who trade through exchange provided terminals such as TWS.
  2. Type II - Members who trade through API based trading terminals like CTCL or IBT or WT facility and who may also be Type I Members.
  3. Type III - Members who use Algorithmic Trading Facility (ATF/ALGO) to trade and who may also be TYPE I or Type II Members.

Members based on their category are required to undertake Cyber Security & Cyber Resilience Audit of their Software for the period specified below through System Auditor appointed as per Auditor Selection Norms and submit the Cyber Security & Cyber Resilience Audit Report (CSR) to the Exchange within the timeline as mentioned in the table below:
CategoriesAudit PeriodDue Date for Submission of Reports
System Audit ReportAction Taken Report, if applicableFollow-on Audit Report, if applicable
Type I - AnnualApril-March30-Jun31-Aug31-Dec
Type II – Annual
Type III – Half YearlyApril-September31-Dec28-Feb30-April
October-March30-Jun31-Aug31-Oct
  1. The Auditor shall have minimum 3 years of experience in IT audit of Commodities / Securities market participants e.g. exchanges, clearing corporations, depositories, stock brokers, depository participants etc. The audit experience should cover all the major areas mentioned under Terms of Reference (ToR) of the Cyber Security Resilience audit specified by SEBI / stock exchange from time to time.
  2. The appointed Auditor’s resources should possess at least one of the following certifications:
    • CISA (Certified Information System Auditors) from ISACA
    • DISA (Post Qualification Certification in Information Systems Audit) from Institute of Chartered Accountants of India (ICAI)
    • CISM (Certified Information Securities Manager) from ISACA
    • CISSP (Certified Information Systems Security Professional) from International Information Systems Security Certification Consortium, commonly known as (ISC)
    • CERT-IN empanelled auditor
  3. The Auditor should have experience of IT audit/governance frameworks and processes conforming to industry leading practices like CobiT.
  4. The Auditor shall not have any conflict of interest in conducting fair, objective and independent audit of the Trading Member. Further, the directors / partners of Auditor firm shall not be related to any Trading Member including its directors or promoters either directly or indirectly.
  5. The Auditor shall not have any cases pending against its previous audited companies/firms, which fall under SEBI’s jurisdiction, which point to its incompetence and/or unsuitability to perform the audit task.
  6. The Auditor can perform maximum of 3 successive Cyber Security Resilience audits of the Trading member. Follow-on audits conducted by the auditor shall not be considered in the successive audits.
Members are required to submit the System Audit Report online through Member Portal - https://member.mcxindia.com. Terms of Reference (ToR) are incorporated in the online Member portal and detailed help file for online submission is available on the path: https://sftp.mcxindia.com/Common. The online CSR portal will be available only to the applicable Members for report submission as per the schedule specified below:
Periodicity of System AuditPortal Availability
Half Yearly (April –September)October 01 to December 31
Half Yearly (October–March)April 01 to June 30
Annual / Yearly (April – March)April 01 to June 30

Members are requested to note the list of System Auditors available in the Member Portal - https://member.mcxindia.com. Kindly submit Annexure 1 to ctcl@mcxindia.com for updating the Auditor details which are not reflecting in online CSR portal of Exchange.
Penalty for Late Submission
Late submission charges of Rs. 500/- per day will be levied on trading members failing to submit the said reports for the period of non-submission. The penalty will commence after due date of respective audit period and will be levied up to the date of submission of report. Further, Non-compliant members shall render themselves liable for action as may be deemed fit by the Exchange.

No comments:

Post a Comment

Related Posts Plugin for WordPress, Blogger...
For mobile version of this site click here


News Archive

Recommended Post Slide Out For Blogger