Indian cybersecurity regulations have never been more demanding — or more specific about what organisations must be able to demonstrate to regulators. This guide explains the key requirements from India's major cybersecurity frameworks and how ManageEngine Log360 produces the audit evidence each framework demands.
The Indian Cybersecurity Compliance Landscape
| Framework | Who It Applies To | Authority |
|---|---|---|
| RBI Cyber Security Framework | Banks, NBFCs, payment aggregators, co-operative banks | Reserve Bank of India |
| SEBI LODR (Regulation 62A) | Listed companies and their material subsidiaries | Securities and Exchange Board of India |
| MeitY Guidelines | Government organisations, IT intermediaries | Ministry of Electronics and Information Technology |
| CERT-In Directions 2022 | All ICT providers above a threshold size | CERT-In (MeitY) |
| DPDP Act 2023 | Any entity processing personal data of Indian citizens | Data Protection Board of India |
| IRDAI Cyber Security Guidelines | Insurance companies | IRDAI |
| IFSCA Guidelines | GIFT City financial entities | International Financial Services Centres Authority |
If your organisation falls under any of these frameworks, you need documented evidence of security monitoring, incident detection and response capability. SIEM is the primary technology for generating this evidence.
RBI Cyber Security Framework
What the Framework Requires
The RBI Cyber Security Framework (issued 2016, updated with subsequent circulars) mandates that regulated entities implement:
Log management and monitoring:
- Collect and retain security logs from all critical assets
- Implement a Security Operations Centre (SOC) or equivalent monitoring capability
- Detect and respond to cybersecurity incidents
- Minimum log retention: 3 years
Specific monitoring requirements:
- Privileged user activity monitoring (admin accounts, IT staff)
- Monitoring of critical transaction systems
- User authentication events
- Network perimeter events (firewall, IDS/IPS)
- Application logs for banking systems
Incident reporting:
- Report incidents to RBI within defined timelines
- Maintain incident documentation
- Conduct post-incident analysis
How Log360 Addresses RBI Requirements
| RBI Requirement | Log360 Capability |
|---|---|
| Log collection from critical assets | 700+ log source integrations; Windows, Linux, network devices, applications |
| Privileged user monitoring | ADAudit Plus module — all admin/privileged access tracked |
| User authentication monitoring | Pre-built authentication reports; failed/successful login tracking |
| Network perimeter monitoring | Firewall syslog integration; IPS event correlation |
| 3-year log retention | Configurable retention policy with archiving to NAS/tape |
| SOC monitoring capability | Real-time alert console; UEBA risk scoring; correlation engine |
| Incident documentation | Incident management workflow; timeline export; PDF audit reports |
Log360 provides a pre-built RBI Cyber Security Framework compliance report that maps log events to specific framework controls — reducing audit preparation from days to hours.
SEBI LODR Regulation 62A (Cybersecurity for Listed Companies)
What the Framework Requires
SEBI's 2024 LODR amendments (Regulation 62A) require listed companies and their material subsidiaries to:
- Implement a cybersecurity policy aligned to SEBI's framework
- Monitor and detect cybersecurity incidents in real time
- Report material cybersecurity incidents to stock exchanges within 6 hours of detection
- Maintain an incident register
- Conduct annual cybersecurity audits
- Provide board-level reporting on cybersecurity posture
The 6-hour incident reporting timeline is particularly demanding — it requires automated detection capability (SIEM), not manual log review.
How Log360 Addresses SEBI LODR Requirements
Real-time incident detection: Log360's correlation rules detect attack patterns in real time — the moment an anomalous event matches a detection rule, an alert fires. This makes the 6-hour reporting window achievable.
Incident documentation for exchange reporting: Log360's incident management workflow generates a documented incident timeline — from initial alert through investigation to resolution — which can be exported as the evidence needed for exchange reporting.
Annual audit reports: The pre-built SEBI compliance report covers:
- Access control events (privileged access, account changes)
- Authentication events (successful/failed logins, session records)
- System changes (configuration modifications, software changes)
- Network events (firewall logs, unusual traffic patterns)
- Data access events (file server, database access)
Board-level reporting: Log360's dashboard can be configured to show executive-level metrics — number of security events, incidents detected, mean time to detection/response — suitable for board reporting.
CERT-In Directions 2022
What the Framework Requires
CERT-In's 2022 directions (applicable to all ICT providers above a threshold) require:
- Log retention: 180 days minimum (rolling), accessible for CERT-In investigation
- Reporting of specified incident types within 6 hours of detection
- Synchronisation of all ICT system clocks to NTP servers (government-specified)
- Maintaining KYC information for customers and subscribers
How Log360 Addresses CERT-In Requirements
Log retention: Configure Log360 archiving to retain logs for 180+ days. CERT-In may request specific log ranges for investigation — Log360's search allows instant extraction of events by time range and source.
NTP synchronisation: Log360 displays timestamps using the system clock of each log source. Ensure all log sources (servers, network devices) are configured to sync with NTP servers. Log360 can alert on timestamp anomalies.
Incident reporting: Log360 can detect most CERT-In reportable incident categories:
- Malicious code activity (RTDMI correlation from integrated firewalls)
- Unauthorised access attempts (authentication failure correlation)
- Data exfiltration patterns (volume-based anomaly detection)
- Website defacement indicators (web server log monitoring)
DPDP Act 2023 (Digital Personal Data Protection Act)
What the Framework Requires
The DPDP Act 2023 creates obligations for "Data Fiduciaries" (organisations that process personal data of Indian citizens):
- Implement appropriate technical and organisational security measures
- Report personal data breaches to the Data Protection Board within prescribed timelines
- Maintain processing records
- Demonstrate purpose limitation and data minimisation compliance
How Log360 Supports DPDP Compliance
Data breach detection: Log360's UEBA and correlation engine can detect the patterns associated with personal data breaches:
- Bulk download of customer records
- Access to personal data outside normal business hours
- Exfiltration attempts (upload patterns, USB writes with file volume anomalies)
- Lateral movement toward systems storing personal data
Breach documentation: Log360 maintains a searchable record of all access events to systems storing personal data. In the event of a breach investigation, you can reconstruct exactly which accounts accessed which systems, when, and what data volumes were involved.
Access control evidence: Log360's AD auditing module tracks who had access to personal data systems — critical for demonstrating purpose limitation compliance (only authorised users accessing data for legitimate purposes).
ISO 27001 — SIEM as ISMS Evidence
ISO 27001 requires an Information Security Management System (ISMS) with documented controls across 93 control areas (ISO 27001:2022). SIEM provides direct evidence for several controls:
| ISO 27001:2022 Control | Log360 Evidence Generated |
|---|---|
| A.8.15 — Logging | Log collection from all information processing systems |
| A.8.16 — Monitoring activities | Real-time monitoring console; alert records |
| A.8.17 — Clock synchronisation | Timestamp records from all log sources |
| A.5.25 — Assess and decide on information security events | Alert investigation records; incident timeline |
| A.5.26 — Response to information security incidents | Incident management workflow records |
| A.5.28 — Collection of evidence | Tamper-evident log storage; chain of custody for log data |
| A.8.34 — Protection of information systems during audit testing | Monitoring logs during vulnerability assessments |
Log360 generates a pre-built ISO 27001 compliance report mapping log events to the relevant controls — suitable for ISMS certification audits.
PCI DSS — Payment Card Compliance
For Indian organisations processing payment card data (merchants, payment aggregators, banks):
PCI DSS Requirement 10 — Log and Monitor All Access to System Components This is the most directly SIEM-relevant PCI DSS requirement:
- Capture all individual user access to cardholder data
- Capture all actions taken by individuals with root or administrative privileges
- Capture invalid logical access attempts
- Retain audit logs for at least 12 months (3 months immediately available)
Log360 addresses all Requirement 10 sub-requirements with pre-built report templates. The PCI DSS compliance report in Log360 generates the exact documentation required for a QSA (Qualified Security Assessor) audit.
Practical Steps to Get Compliance-Ready with Log360
1. Map your applicable frameworks
Identify which regulations apply based on your industry, listing status and data processing activities.
2. Configure log retention accordingly
Set Log360 archiving to meet the longest retention period among your applicable frameworks:
- CERT-In: 180 days minimum
- PCI DSS: 12 months
- RBI: 3 years
- ISO 27001: As defined in your ISMS scope
3. Enable compliance report templates
In Log360, activate report templates for each applicable framework and schedule monthly generation.
4. Configure incident response workflows
Set up Log360's incident management module with named responders, escalation paths and documentation templates — especially for frameworks with strict reporting timelines (SEBI: 6 hours, CERT-In: 6 hours).
5. Document your monitoring capability
Generate a monthly "security monitoring activity report" from Log360 — showing events reviewed, alerts raised, incidents detected and responded to. This demonstrates active monitoring capability to auditors.
Cloudfy Systems deploys and configures ManageEngine Log360 for Indian compliance requirements, including report template setup for RBI, SEBI, CERT-In and PCI DSS frameworks.
Contact us: +91 97600 50555 · connect@cloudfysystems.com
Frequently Asked Questions
Does Log360 generate reports specifically for SEBI LODR Regulation 62A?
Yes. Log360 includes a SEBI compliance report template. However, because SEBI LODR 62A is relatively recent (2024 amendments), Cloudfy recommends having a compliance consultant review the report template against the specific control requirements for your organisation's scope.
What is the minimum log retention period for Indian regulated entities?
CERT-In requires 180 days; PCI DSS requires 12 months; RBI Cyber Security Framework requires 3 years. For organisations subject to multiple frameworks, configure to the longest applicable period (3 years if you are an RBI-regulated entity).
Can Log360 send alerts to my compliance team when a reportable incident is detected?
Yes. Log360 alert notifications can be sent to email, SMS or webhook. Configure a dedicated alert rule for CERT-In and SEBI reportable incident categories with escalation to your compliance team and CISO.
Does DPDP Act compliance require a SIEM?
The DPDP Act does not specifically mandate SIEM. However, the requirement to report data breaches and demonstrate appropriate technical safeguards makes SIEM the most practical way to meet the detection and evidence requirements — particularly the breach reporting timelines.
