NABARD's Cyber Security Framework for Regional Rural Banks
A Guided Path to Strengthening Digital Banking
- Guidelines for cyber security controls in Regional Rural Banks (RRBs) tailored to their digital sophistication and connectivity.
- Outlines the responsibilities of the Board of Directors, top management, and Sponsor Bank in ensuring robust cyber security governance and reporting.

Four-Tiered Framework and Tailored Controls for RRB Cyber Security
Levels of Cyber Security Controls.
Level 3 (RRBs with Advanced Digital Interfaces)
If RRBs have their own ATM switch or SWIFT interface, they need to follow the advanced controls detailed in Annexure-III, in addition to the controls from Level 1 and 2. This includes advanced real-time threat defense and management, as well as risk-based transaction monitoring.
Level 4 (Digitally Advanced RRBs)
RRBs with a data center or those providing software support to other banks must implement an even more advanced set of controls outlined in Annexure-IV, alongside all the controls from previous levels. This level includes setting up a Cyber Security Operation Centre (C-SOC) and developing an IT and Information Security Governance Framework.
Self-Assessment & Timely Compliance

– RRBs are encouraged to undertake a self-assessment to identify their respective levels based on the given criteria.
– It’s imperative for the Board of Directors to oversee the information security of the bank.
– RRBs should comply with the prescribed control requirements within the timelines stipulated in the circular.
The Vulnerability Index for Cyber Security Framework (VICS)
Level 1 (All RRBs)
– Utilize the VICS tool to assess the cyber security posture of your bank, as a guide to establish and enhance cyber security controls.
Controls to be Implemented by Respective Levels
Level 1 (All RRBs)
Under this level, RRBs are required to adhere to basic cyber security controls as specified in Annexure-I, which includes:
– Inventory Management of Business IT Assets
– Board approved Cyber Security Policy distinct from IT policy
– Cyber Crisis Management Plan
– Secure Mail and Messaging Systems
– User Access Control/Management
– Antivirus and Patch Management
– Environmental Controls and Network Management
Level 2 (RRBs with Internet or Mobile Banking)
In addition to Level 1 controls, RRBs in this category must implement further controls listed in Annexure-II, such as:
– Application Security Lifecycle (ASLC)
– Change Management and Periodic Testing
– Anti-Phishing Measures
– Authentication Framework for Customers
– Incident Response and Management
– Enhanced User/Employee/Management Awareness
Level 3 (RRBs with Advanced Digital Interfaces)
RRBs at this level need to adhere to the controls of Level 1 and 2, plus additional controls from Annexure-III, which include:
– Advanced Real-time Threat Defense and Management
– Risk-based Transaction Monitoring
– Maintenance, Monitoring, and Analysis of Audit Logs
– Enhanced Incident Response and Management
Level 4 (Digitally Advanced RRBs)
Alongside the controls from previous levels, RRBs here are required to implement advanced controls as outlined in Annexure-IV, like:
– Establishment of Cyber Security Operation Centre (C-SOC)
– IT and IS Governance Framework
– Participation in Cyber Drills
– Forensics and Metrics
– Security Team/Function establishment
– Continuous Surveillance and Incident Response Management
WE'D LOVE TO HEAR FROM YOU
Your path to NABARD Compliance
We can support you in adhering to the NABARD’s Cyber Security Framework for Regional Rural Banks.
Prefer to email? Reach us at [email protected]