Technical12 min read

SIEM Compliance for RBI, SEBI & MeitY India — How Log360 Helps You Meet Indian Cybersecurity Regulations

SIEM Compliance for RBI, SEBI & MeitY India — How Log360 Helps You Meet Indian Cybersecurity Regulations

Indian cybersecurity regulations have never been more demanding — or more specific about what organisations must be able to demonstrate to regulators. This guide explains the key requirements from India's major cybersecurity frameworks and how ManageEngine Log360 produces the audit evidence each framework demands.


The Indian Cybersecurity Compliance Landscape

FrameworkWho It Applies ToAuthority
RBI Cyber Security FrameworkBanks, NBFCs, payment aggregators, co-operative banksReserve Bank of India
SEBI LODR (Regulation 62A)Listed companies and their material subsidiariesSecurities and Exchange Board of India
MeitY GuidelinesGovernment organisations, IT intermediariesMinistry of Electronics and Information Technology
CERT-In Directions 2022All ICT providers above a threshold sizeCERT-In (MeitY)
DPDP Act 2023Any entity processing personal data of Indian citizensData Protection Board of India
IRDAI Cyber Security GuidelinesInsurance companiesIRDAI
IFSCA GuidelinesGIFT City financial entitiesInternational Financial Services Centres Authority

If your organisation falls under any of these frameworks, you need documented evidence of security monitoring, incident detection and response capability. SIEM is the primary technology for generating this evidence.


RBI Cyber Security Framework

What the Framework Requires

The RBI Cyber Security Framework (issued 2016, updated with subsequent circulars) mandates that regulated entities implement:

Log management and monitoring:

  • Collect and retain security logs from all critical assets
  • Implement a Security Operations Centre (SOC) or equivalent monitoring capability
  • Detect and respond to cybersecurity incidents
  • Minimum log retention: 3 years

Specific monitoring requirements:

  • Privileged user activity monitoring (admin accounts, IT staff)
  • Monitoring of critical transaction systems
  • User authentication events
  • Network perimeter events (firewall, IDS/IPS)
  • Application logs for banking systems

Incident reporting:

  • Report incidents to RBI within defined timelines
  • Maintain incident documentation
  • Conduct post-incident analysis

How Log360 Addresses RBI Requirements

RBI RequirementLog360 Capability
Log collection from critical assets700+ log source integrations; Windows, Linux, network devices, applications
Privileged user monitoringADAudit Plus module — all admin/privileged access tracked
User authentication monitoringPre-built authentication reports; failed/successful login tracking
Network perimeter monitoringFirewall syslog integration; IPS event correlation
3-year log retentionConfigurable retention policy with archiving to NAS/tape
SOC monitoring capabilityReal-time alert console; UEBA risk scoring; correlation engine
Incident documentationIncident management workflow; timeline export; PDF audit reports

Log360 provides a pre-built RBI Cyber Security Framework compliance report that maps log events to specific framework controls — reducing audit preparation from days to hours.


SEBI LODR Regulation 62A (Cybersecurity for Listed Companies)

What the Framework Requires

SEBI's 2024 LODR amendments (Regulation 62A) require listed companies and their material subsidiaries to:

  • Implement a cybersecurity policy aligned to SEBI's framework
  • Monitor and detect cybersecurity incidents in real time
  • Report material cybersecurity incidents to stock exchanges within 6 hours of detection
  • Maintain an incident register
  • Conduct annual cybersecurity audits
  • Provide board-level reporting on cybersecurity posture

The 6-hour incident reporting timeline is particularly demanding — it requires automated detection capability (SIEM), not manual log review.

How Log360 Addresses SEBI LODR Requirements

Real-time incident detection: Log360's correlation rules detect attack patterns in real time — the moment an anomalous event matches a detection rule, an alert fires. This makes the 6-hour reporting window achievable.

Incident documentation for exchange reporting: Log360's incident management workflow generates a documented incident timeline — from initial alert through investigation to resolution — which can be exported as the evidence needed for exchange reporting.

Annual audit reports: The pre-built SEBI compliance report covers:

  • Access control events (privileged access, account changes)
  • Authentication events (successful/failed logins, session records)
  • System changes (configuration modifications, software changes)
  • Network events (firewall logs, unusual traffic patterns)
  • Data access events (file server, database access)

Board-level reporting: Log360's dashboard can be configured to show executive-level metrics — number of security events, incidents detected, mean time to detection/response — suitable for board reporting.


CERT-In Directions 2022

What the Framework Requires

CERT-In's 2022 directions (applicable to all ICT providers above a threshold) require:

  • Log retention: 180 days minimum (rolling), accessible for CERT-In investigation
  • Reporting of specified incident types within 6 hours of detection
  • Synchronisation of all ICT system clocks to NTP servers (government-specified)
  • Maintaining KYC information for customers and subscribers

How Log360 Addresses CERT-In Requirements

Log retention: Configure Log360 archiving to retain logs for 180+ days. CERT-In may request specific log ranges for investigation — Log360's search allows instant extraction of events by time range and source.

NTP synchronisation: Log360 displays timestamps using the system clock of each log source. Ensure all log sources (servers, network devices) are configured to sync with NTP servers. Log360 can alert on timestamp anomalies.

Incident reporting: Log360 can detect most CERT-In reportable incident categories:

  • Malicious code activity (RTDMI correlation from integrated firewalls)
  • Unauthorised access attempts (authentication failure correlation)
  • Data exfiltration patterns (volume-based anomaly detection)
  • Website defacement indicators (web server log monitoring)

DPDP Act 2023 (Digital Personal Data Protection Act)

What the Framework Requires

The DPDP Act 2023 creates obligations for "Data Fiduciaries" (organisations that process personal data of Indian citizens):

  • Implement appropriate technical and organisational security measures
  • Report personal data breaches to the Data Protection Board within prescribed timelines
  • Maintain processing records
  • Demonstrate purpose limitation and data minimisation compliance

How Log360 Supports DPDP Compliance

Data breach detection: Log360's UEBA and correlation engine can detect the patterns associated with personal data breaches:

  • Bulk download of customer records
  • Access to personal data outside normal business hours
  • Exfiltration attempts (upload patterns, USB writes with file volume anomalies)
  • Lateral movement toward systems storing personal data

Breach documentation: Log360 maintains a searchable record of all access events to systems storing personal data. In the event of a breach investigation, you can reconstruct exactly which accounts accessed which systems, when, and what data volumes were involved.

Access control evidence: Log360's AD auditing module tracks who had access to personal data systems — critical for demonstrating purpose limitation compliance (only authorised users accessing data for legitimate purposes).


ISO 27001 — SIEM as ISMS Evidence

ISO 27001 requires an Information Security Management System (ISMS) with documented controls across 93 control areas (ISO 27001:2022). SIEM provides direct evidence for several controls:

ISO 27001:2022 ControlLog360 Evidence Generated
A.8.15 — LoggingLog collection from all information processing systems
A.8.16 — Monitoring activitiesReal-time monitoring console; alert records
A.8.17 — Clock synchronisationTimestamp records from all log sources
A.5.25 — Assess and decide on information security eventsAlert investigation records; incident timeline
A.5.26 — Response to information security incidentsIncident management workflow records
A.5.28 — Collection of evidenceTamper-evident log storage; chain of custody for log data
A.8.34 — Protection of information systems during audit testingMonitoring logs during vulnerability assessments

Log360 generates a pre-built ISO 27001 compliance report mapping log events to the relevant controls — suitable for ISMS certification audits.


PCI DSS — Payment Card Compliance

For Indian organisations processing payment card data (merchants, payment aggregators, banks):

PCI DSS Requirement 10 — Log and Monitor All Access to System Components This is the most directly SIEM-relevant PCI DSS requirement:

  • Capture all individual user access to cardholder data
  • Capture all actions taken by individuals with root or administrative privileges
  • Capture invalid logical access attempts
  • Retain audit logs for at least 12 months (3 months immediately available)

Log360 addresses all Requirement 10 sub-requirements with pre-built report templates. The PCI DSS compliance report in Log360 generates the exact documentation required for a QSA (Qualified Security Assessor) audit.


Practical Steps to Get Compliance-Ready with Log360

1. Map your applicable frameworks

Identify which regulations apply based on your industry, listing status and data processing activities.

2. Configure log retention accordingly

Set Log360 archiving to meet the longest retention period among your applicable frameworks:

  • CERT-In: 180 days minimum
  • PCI DSS: 12 months
  • RBI: 3 years
  • ISO 27001: As defined in your ISMS scope

3. Enable compliance report templates

In Log360, activate report templates for each applicable framework and schedule monthly generation.

4. Configure incident response workflows

Set up Log360's incident management module with named responders, escalation paths and documentation templates — especially for frameworks with strict reporting timelines (SEBI: 6 hours, CERT-In: 6 hours).

5. Document your monitoring capability

Generate a monthly "security monitoring activity report" from Log360 — showing events reviewed, alerts raised, incidents detected and responded to. This demonstrates active monitoring capability to auditors.


Cloudfy Systems deploys and configures ManageEngine Log360 for Indian compliance requirements, including report template setup for RBI, SEBI, CERT-In and PCI DSS frameworks.

Contact us: +91 97600 50555 · connect@cloudfysystems.com


Frequently Asked Questions

Does Log360 generate reports specifically for SEBI LODR Regulation 62A?

Yes. Log360 includes a SEBI compliance report template. However, because SEBI LODR 62A is relatively recent (2024 amendments), Cloudfy recommends having a compliance consultant review the report template against the specific control requirements for your organisation's scope.

What is the minimum log retention period for Indian regulated entities?

CERT-In requires 180 days; PCI DSS requires 12 months; RBI Cyber Security Framework requires 3 years. For organisations subject to multiple frameworks, configure to the longest applicable period (3 years if you are an RBI-regulated entity).

Can Log360 send alerts to my compliance team when a reportable incident is detected?

Yes. Log360 alert notifications can be sent to email, SMS or webhook. Configure a dedicated alert rule for CERT-In and SEBI reportable incident categories with escalation to your compliance team and CISO.

Does DPDP Act compliance require a SIEM?

The DPDP Act does not specifically mandate SIEM. However, the requirement to report data breaches and demonstrate appropriate technical safeguards makes SIEM the most practical way to meet the detection and evidence requirements — particularly the breach reporting timelines.

Free Consultation

Talk to a Cloud Expert

Tell us about your team and stack — we'll recommend the right cloud and SaaS setup with transparent pricing in INR.

Google Cloud PartnerMicrosoft PartnerZoho Authorised
Already decided? Submit your details to start provisioning

Request a Callback

Fill the form — we'll get back within one business day.

We respond within one business day · No spam, ever.