SEBI – IS Audit
SEBI-IS Audit involves evaluating the cybersecurity measures of entities regulated by the Securities and Exchange Board of India. It ensures compliance with SEBI’s guidelines, focusing on information security, data protection, and risk management in securities trading. The audit assesses controls, processes, and procedures to mitigate cyber threats and safeguard investor interests.
Over the past decade, cyber-attacks have significantly impacted the global landscape. The main cause can be attributed to the continuous evolution of hackers, surpassing the existing security measures employed by online merchants.
Cyber-attacks have had a profound impact on a global scale in the past decade, driven by the relentless evolution of hackers surpassing existing security measures. Recognizing the pivotal role of brokers in securities investments, SEBI has identified a critical need for stringent cybersecurity guidelines.
SEBI Guidelines Highlights for Sharebrokers
1. Digital Security Measures for Electronic Communication Networks (ECNs): All ECNs sent via email must be digitally signed, encrypted, non-tamperable, and compliant with the IT Act, 2000.
Brokers are accountable for maintaining non-tamperable backups of all ECNs in accordance with IT Act provisions and SEBI guidelines.
2. Internet-Based Trading (IBT) and Wireless Technology Usage: Brokers are authorized to provide IBT and securities trading through wireless technology using devices like mobile phones and laptops with data cards, adhering to Internet Protocol (IP).
3. Client Awareness and Communication: Brokers must inform clients about features, risks, responsibilities, obligations, and liabilities associated with securities trading through various technologies, including wireless and internet-based platforms.
The purpose of the audit
The audit serves several crucial purposes:
-
- Ensuring compliance with the Securities Exchange Board of India Act, 1992, in maintaining books of account, records, and documents.
- Verifying the establishment and adherence to internal control systems, procedures, and safeguards by intermediaries.
- Assessing the intermediary’s fitness for dealing in the securities market.
- Verifying compliance with securities laws, SEBI directions, circulars, stock exchange bye-laws, notices, and instructions.
- Enabling inquiries into matters deemed fit by the auditor in the interest of investors or the securities market.
Why Work with us?

CERT-IN Empaneled Security Auditor
We are empaneled by CERT-In to conduct digital security verification services, validating organizations and their systems’ readiness.

Flexible Delivery
Our team understands the need for flexibility in scheduling tests, ensuring customers achieve the best results.
Are you ready for the next steps?
Related Insights
Navigating the Path to CERT-IN Compliance: A Step-by-Step Guide
Ensuring the security of India's internet infrastructure hinges significantly on the...
GST Suvidha Providers System Audit: A wholesome Approach
Who is a GST Suvidha Provider or GSP? GST Suvidha Provider or GSP focuses to an...
Process Guidelines For CERT-In Empanelled Information Security Auditing Organizations
Introduction to CERT-In CERT-In (the Indian Computer Emergency Response Team) is a...



