Project Report
of
DISA 3.0 Course
1|P a ge
CERTIFICATE
Project report of DISA 3.0 Course
This is to certify that we have successfully completed the DISA 3.0 course training conducted
at ICAI Tower, plot no C-40, G Block, Opp. MCA Academy, Besides Standard Chartered Bank, Bandra
Kurla Complex, Bandra (East), Mumbai - 400 051 from 15 March 2025 to 20 April 2025 and we have
the required attendance. We are submitting the Project titled:
REVIEW OF CYBER SECURITY POLICIES AND PROCEDURE
We hereby confirm that we have adhered to the guidelines issued by DAAB, ICAI for the
project. We also certify that this project report is the original work of our group and each one of us have
actively participated and contributed in preparing this project. We have not shared the project details or
taken help in preparing project report from anyone except members of our group.
Sr No Name Membership No. Signature
Mohammad Masoom Maqbool
1 624743
Deraiya
2 Janakraj Joshi 628092
3 Sarvesh Radheshamji Lahoti 628127
Place: Mumbai
Date: 06/04/2025
2|P a ge
TABLE OF CONTENT
Sr No Particulars Page No
1 Details of Case Study 4
2 Introduction 5
3 Auditee Environment 6
4 Background 8
5 Situation 8
6 Terms and Scope of assignment 9
7 Logistic arrangements required 11
8 Methodology and Strategy adapted for execution of assignment 13
9 Documents reviewed 15
10 References 16
11 Deliverables 16
12 Format of Report/Findings and Recommendations 17
13 Summary/Conclusion 18
3|P a ge
Project Report
TITLE : REVIEW OF CYBER SECURITY POLICIES & PROCEDURES
A. Details of Case Study/Project (Problem)
Cyber Threat Landscape Overview
Shift in Attack Focus:
Nova Cyber Solutions reported a rise in attacks on sectors crucial to post-COVID
recovery—healthcare, logistics, and renewable energy—due to rapid digitization and
increased demand.
• India’s Position:
o Ranked 3rd in Asia for most cyber-attacks (6.5% of incidents).
o Financial institutions were the top targets (55% of attacks).
o Manufacturing and IT services were also hit frequently.
o Ransomware was the main threat, causing 38% of incidents, leading to serious
disruptions and losses.
• Regulatory Response:
o The Reserve Authority of India (RAI) enforced stricter cybersecurity rules
under its Cybersecurity Framework for Banks.
o Example: Coastal Bank was fined Rs. 12 million in 2019 for not following the
guidelines.
• Monarch Bank’s Action:
o With 8,900 branches, 24,500 ATMs, and 59,000 employees, Monarch Bank is
a key player in India’s banking sector.
o Proactively strengthened its cybersecurity to protect against rising threats and
meet regulatory requirements.
4|P a ge
B. Project Report (solution)
1. Introduction
• Monarch Bank Ltd.
Monarch Bank Ltd., established in 1990, is one of India’s leading banks, headquartered
in Mumbai, Maharashtra. Over the past 30 years, it has become a key part of India’s financial
system, offering a wide range of services for both individual and business customers.
The bank provides services such as personal and corporate banking, loans for small and
medium businesses, treasury operations, and activities in financial markets. Its group
companies also offer insurance, investment services, wealth and asset management, and
financial advice.
With around 8,900 branches and 24,500 ATMs across India and select international
locations, Monarch Bank has a strong physical and digital presence. It focuses on financial
inclusion by opening branches in rural and semi-urban areas and investing in digital banking
solutions.
The bank employs about 59,000 people and promotes a culture of customer focus,
integrity, and continuous improvement. By using advanced technology and data analytics, it
ensures secure, efficient, and personalized services for its clients.
Monarch Bank’s vision is to be a trusted financial partner, supporting economic growth
and financial empowerment. Its mission is guided by strong governance, sustainable banking
practices, innovation, and operational excellence.
• Alpha Tech Consultants
Alpha Tech Consultants, founded in 2024, is a well-known name in the field of cyber
security and risk advisory services. The firm offers a wide range of services, including cyber
security audits, enterprise risk assessments, IT governance reviews, and regulatory compliance
support. It serves clients across industries such as finance, manufacturing, healthcare, and
technology, helping them strengthen their security systems and stay updated with regulatory
requirements.
The company operates from key locations in Mumbai, Hyderabad, and Kolkata,
allowing it to serve both regional and national clients effectively. Its team includes 3
experienced partners, 6 audit associates, and 12 skilled technical professionals who bring deep
knowledge in cyber security, auditing, and compliance.
5|P a ge
Audit and assurance services are led by Mr. Mohammad Masoom Maqbool Deraiya
(CA), an expert in cyber risk and IT audits. He works closely with Mr. Janakraj Joshi (CA) and
Mr. Sarvesh Lahoti (CA), both of whom have strong experience in handling complex IT
assurance and compliance projects.
Alpha Tech’s mission is to help organizations stay ahead of cyber threats by offering
customized solutions, maintaining high professional standards, and focusing on clients' needs.
2. Auditee Environment
Monarch Bank Ltd., based in Mumbai, Maharashtra, is a top private-sector bank in India
known for its focus on digital banking and innovation. With over 30 years of experience, it
serves a wide range of customers—from individuals to large companies.
Digital Innovation and Services
Monarch Bank leads in digital banking with advanced services across multiple platforms:
• Online Banking: A secure portal for fund transfers, bill payments, investments, loan
management, and personal finance tools. It includes two-factor authentication and real-
time fraud detection.
• Mobile App: A user-friendly app for Android and iOS offering key banking services,
UPI payments, mobile wallet integration, loan applications, and AI-powered chatbot
support.
• AI Support: Uses AI and machine learning for automated help, behavior analysis, and
personalized services. The chatbot handles basic queries and passes complex ones to
human agents.
• Contactless Payments: Offers NFC-enabled cards, QR-based payments, and digital
wallet integration for fast, secure transactions.
• Omnichannel Banking: Ensures a smooth, connected experience across branches,
ATMs, online banking, mobile apps, and call centers.
• IT Infrastructure
Monarch Bank uses a IT setup, comprising of data centers with secure cloud services for better
scalability and reliability. Key components include:
6|P a ge
• Tier-3 Data Centers in Pune and Hyderabad with backup power, strong physical
security, and disaster recovery systems.
• Virtual Servers hosting core banking systems, CRM, payment platforms, and
regulatory tools.
• 24/7 Security Operations Center (SOC) that monitors threats, vulnerabilities, and
unusual activity.
• Advanced Security Tools like next-gen firewalls, IDPS, SIEM, and endpoint
protection.
Policies and Governance
The bank has a strong policy framework to ensure compliance, efficiency, and risk control.
Key policies include:
• Information & Cyber Security Policy: Defines roles, access controls, encryption, and
incident handling.
• IT Governance Policy: Covers asset management, software development, change
management, and continuity planning.
• Data Privacy Policy: Protects personal data in line with local laws and global
standards.
• Document Retention Policy: Manages record storage, archiving, and disposal per
regulations.
• Whistleblower Policy: Offers a safe, confidential way to report fraud or misconduct.
Compliance and Risk Management
A multi-layered compliance model is led by the Risk Management and IT Sub-Committee. The
bank follows Reserve Authority of India (RAI) regulations and engages regularly with the
CSITE Cell to meet cybersecurity standards. Regular audits help identify gaps and strengthen
defenses.
Culture and Operations
With 59,000+ employees, 8,900 branches, and 24,500 ATMs, Monarch Bank promotes a
culture of innovation and customer focus. Ongoing staff training on cyber safety, fraud
prevention, and compliance ensures everyone contributes to protecting digital assets.
7|P a ge
3. Background
Cybersecurity Challenges and Response
After the global pandemic, cyber threats in the financial sector have surged. The rapid move to
digital banking, remote work, and cloud services has widened the attack surface for banks. In
response, the Reserve Authority of India (RAI) issued new guidelines urging banks to
strengthen their cybersecurity and resilience.
As a major bank in India, Monarch Bank Ltd. depends heavily on technology, with customers
using internet banking, mobile apps, and AI-powered platforms. This digital reliance also
brings increased risks like phishing, ransomware, DDoS attacks, and insider threats.
To meet RAI’s Cybersecurity Framework for Banks and tackle these growing risks, Monarch
Bank’s CTO, Mr. Arjun Desai, launched a strategic review of the bank’s cybersecurity setup.
The bank partnered with Alpha Tech Consultants, an expert IT audit firm, for an independent
security assessment.
The key goals of the assessment were to:
• Find gaps in existing cybersecurity policies, processes, and controls
• Ensure compliance with RAI’s cybersecurity framework
• Improve overall security and reduce cyber risks
• Create a clear plan to fix vulnerabilities and strengthen incident response
This initiative shows Monarch Bank’s strong focus on protecting customer data, securing
digital channels, and ensuring business continuity in a fast-changing threat landscape.
4. Situation
Cybersecurity Risks and Strategic Response
Monarch Bank Ltd., with large network of branches and operations in 12 countries, has
become a major player in Indian and global banking. As part of its digital transformation, the
bank has invested in online banking, mobile apps, and AI-driven services improving customer
experience but also expanding its cyber risk exposure.
The rise in digital transactions, especially after the pandemic, has increased the bank’s
vulnerability to threats such as:
• Ransomware attacks on financial institutions
• Phishing and spear-phishing targeting customers and staff
• Insider risks from hybrid and remote work setups
8|P a ge
To address these challenges, the Reserve Authority of India (RAI) introduced its 2016
Cybersecurity Circular, requiring banks to:
• Build strong cybersecurity and IT governance systems
• Conduct regular vulnerability assessments and penetration tests (VAPT)
• Improve real-time threat detection and incident response
• Report risks and mitigation efforts to appropriate government authority.
Recognizing these rising threats and the importance of trust, Monarch Bank’s leadership saw
the need to enhance its cybersecurity measures. Though existing controls were in place, they
needed to be strengthened to meet current risks and regulations.
Reputation risk was also a key driver, as any breach could lead to financial losses and damage
customer confidence.
In response, CTO Mr. Arjun Desai, in coordination with the bank’s IT Sub-Committee,
initiated a full cybersecurity assessment. The project, carried out by Alpha Tech Consultants,
aimed to:
• Evaluate the current cybersecurity and incident response setup
• Identify compliance gaps with RAI’s Cybersecurity Framework
• Recommend improvements in data protection, network security, and continuity
planning
This assessment supports Monarch Bank’s broader goal of achieving cyber resilience,
protecting customer data, and maintaining smooth operations across its national and
international branches.
5. Terms and Scope of Assignment
Monarch Bank Ltd. engaged Alpha Tech Consultants to carry out a thorough review
of its cybersecurity policies, procedures, and technical controls. This assignment was
overseen by CTO Mr. Arjun Desai and the IT Sub-Committee, in line with guidelines
from the Reserve Authority of India (RAI).
The main goal was to assess the bank’s cybersecurity readiness, identify gaps, and
recommend improvements to strengthen cyber resilience and ensure compliance with the
RAI Cybersecurity/Resilience Framework.
9|P a ge
The scope of the assessment covered the following areas:
1. Access Controls
o Review of user access management for staff and third parties
o Assessment of identity and access controls, including MFA and privileged
access
2. IT Infrastructure
o Evaluation of data centers, networks, firewall, and cloud systems
o Check of business continuity and disaster recovery setups
3. Physical Security
o Review of physical safeguards for IT assets
o Checks on environmental controls, visitor logs, and access restrictions
4. Security Policies
o Evaluation of cybersecurity and data privacy policies
5. Risk Governance
o Review of roles and responsibilities for cybersecurity oversight
o Assessment of risk identification, evaluation, and mitigation processes
6. Incident Management
o Examination of breach detection, response, and reporting procedures
o Review of escalation protocols to senior management
7. Password Policies
o Review of password complexity, rotation, reuse rules, and storage
o Evaluation of system controls enforcing secure password practices
8. Email Security
o Assessment of email protection tools, DLP measures, and encryption
o Review of employee awareness around phishing and email fraud
This audit aimed not only to identify weaknesses but also to offer practical
recommendations to boost security, reduce risk, and comply with RAI regulations.
10 | P a g e
6. Logistic arrangements required
To ensure smooth and timely execution of the cybersecurity audit, Monarch Bank Ltd.
will provide necessary logistical support, technical resources, and personnel coordination
throughout the assignment. Given the audit's wide scope across various departments and IT
environments, the following arrangements are essential:
A. Appointment of Designated Coordinators :
Monarch Bank will appoint two key personnel to coordinate the audit process:
1. Senior IT Officer – A qualified IT officer will act as the primary technical liaison for
Alpha Tech Consultants. This person will facilitate access to systems, assist with
technical queries, and support the audit team during implementation.
2. Operations Head – This individual will handle all logistical and administrative
coordination, including scheduling meetings, managing interdepartmental interactions,
and supporting on-site operations.
Both coordinators are expected to remain accessible for queries and issue resolution until the
audit is completed.
B. IT Infrastructure and Technical Resources
The bank will provide the audit team with the following technical facilities to carry
out their assessment effectively:
• Computers and laptops with reliable internet access.
• Peripheral devices such as printers, scanners, and LCD projectors.
• Networking equipment including routers, switches, modems, hubs, and UPS systems.
• Secure access to external storage devices like encrypted pen drives or hard drives.
C. Systems and Application Access
For thorough review and testing, the audit team will be given:
• Role-based
• Individual User IDs and passwords for each audit member as per access control
policies.
• Access to cybersecurity logs and incident monitoring tools.
11 | P a g e
D. Documentation and Data Access
To support in-depth analysis and validation, the following documents and data
sources will be provided:
• Service Level Agreements (SLAs) with IT vendors and service partners.
• Exception and error reports from IT systems.
• Internal testing documentation, VAPT reports, and checklists.
• Risk registers, business impact analysis (BIA), and IT risk assessment reports, where
available.
E. Travel and Mobility Support
• The bank will arrange local travel between branches, regional offices, and data centers
as required.
• For outstation visits, including international sites if applicable, travel and
accommodation will be provided or reimbursed in accordance with the bank’s travel
and expense policy.
These logistical arrangements will support effective completion of the cybersecurity
audit within the agreed timeline and in line with RAI’s regulatory framework and Monarch
Bank’s governance standards.
12 | P a g e
7. Methodology and Strategy Adopted for Execution of Assignment
The cyber security audit for Monarch Bank Ltd. was conducted by Alpha Tech
Consultants using a structured, risk-based methodology in line with the Tier II control
standards mandated by the Financial Regulatory Council of India (FRCI). The audit
strategy prioritized both technological safeguards and procedural controls to evaluate the
bank’s resilience to cyber threats and compliance with sectoral guidelines.
A. Audit Methodology
The engagement was carried out through sequential phases as follows:
1. IT Asset Inventory
o Comprehensive mapping of Bank’s infrastructure, including core systems, end-
user devices etc.
o Categorization based on sensitivity & business criticality
2. Sectoral Threat Profiling
o Analysis of recent incidents and internal alerts in the banking segment to derive
relevant risk vectors.
3. Comprehensive Vulnerability Review
o Internal and external vulnerability scans targeting web portals, APIs, and back-
office systems.
4. Impact and Exposure Analysis
o Assess operational, regulatory, and reputational implications of identified risks.
o Risk quantification.
5. Risk Appetite Mapping
o Define tolerance thresholds.
B. Key Focus Areas
The audit placed emphasis on critical themes:
1. Segregation of Cyber vs IT Policies
• Reviewed distinct documentation for cyber threats, ensuring tailored controls for
threat detection, response, and recovery.
2. Security Awareness and Culture
• Assessed training effectiveness
3. Customer Data Security
13 | P a g e
• Reviewed encryption at rest and in transit, access logging, and data lifecycle
controls.
4. Incident Surveillance & Reporting
• Verified efficacy of SIEM tools and regulatory reporting pipelines to FRCI’s Cyber
Monitoring Division.
5. Email Protection Measures
• Inspected DMARC, SPF, and DKIM implementation for resilience against
spoofing.
6. Multi-Factor Authentication (MFA)
• Validated enforcement across banking platforms, admin portals, and remote access
tools.
7. Network & Device Security Audits
• Reviewed endpoint controls, firmware updates, and router/firewall rule sets.
8. Password Management Controls
• Benchmarked policy parameters against global standards for complexity, rotation,
and lockout.
9. Third-Party Risk Oversight
• Analysed vendor due diligence procedures, contract clauses, and SLA enforcement.
Change and Access Management
10. Data Loss Prevention Controls
• Assessed monitoring of outbound communications and USB usage.
11. Audit Trail and Incident Response
• Verified completeness and retention of logs; reviewed incident drill documentation.
C. Strategy Adopted
Nova Shield employed a hybrid model combining system audits and procedural walkthroughs.
Key activities included:
• Stakeholder Consultations: Interviews with business and technical leaders to validate
governance maturity.
• Documentation Analysis: Examination of internal controls, policy documents, and
risk assessments.
• Technical Testing: Vulnerability scans, endpoint configuration audits, and
infrastructure assessments.
• Compliance Benchmarking: Cross-reference with FRCI standards and global
frameworks.
14 | P a g e
• Risk Classification: Categorization of findings by criticality to drive targeted
mitigation.
• Continuous Collaboration: Ongoing coordination with Sterling Bank’s Technology
and Compliance leadership to ensure transparency and timely issue closure.
This strategy offered the bank a panoramic view of its cyber security capabilities and provided
actionable insights for fortification.
8. Documents Reviewed
The audit team reviewed the following document sets:
1. Cyber Risk Governance Documents
o Policy on cyber risk tolerance and associated risk register.
o Business Impact Assessments and mitigation roadmaps.
2. Internal Control Repository
o Security control maps aligned with risk.
o Records of testing, remediation logs, and encryption standards.
3. Third-Party & Vendor Oversight
o Inventories of IT service providers, with contractual security clauses and audit
reports.
4. Threat Intelligence Feeds
o Internal threat analysis reports and actionable use cases.
5. Cyber Resilience & Continuity
o Cyber Incident Response Plans and Disaster Recovery Protocols.
o Evidence of tabletop exercises and simulations.
15 | P a g e
9. References
1. FRCI Cyber Security Framework (2021 Update)
FRCI Circular No. FRCI/CYB/05/2021 – Prescribing mandatory cyber security
measures for banks. [Link]
2. FRCI Regulatory Portal
Official communications on compliance, advisories, and sectoral updates.
[Link]
3. CERT-IN Cyber Framework
National cyber incident response and security framework.
[Link]
4. KPMG Cyber Risk Reports
Insights on banking sector cyber trends and global benchmarking.
[Link]
10. Deliverables
The following outputs were submitted:
1. Preliminary Audit Report
o Initial findings, categorized risk exposures, and mitigation suggestions.
2. Final Audit Report
o Revised report with management feedback and actionable timelines.
3. Audit Checklist
o Detailed audit traceability matrix spanning controls, procedures, and
compliance items.
4. Methodology Documentation
o Full record of audit scope, techniques, standards referenced, and sampling
framework.
16 | P a g e
11. Findings and Recommendations
Issue Risk Observation Recommendation Management
Rating Response
Physical High Weak entry screening Deploy surveillance & Accepted
Access for sensitive zones. screening protocols at
Controls server rooms.
Sensitive Very No recipient validation Enforce end-to-end Accepted
Email High in email encryption with MFA
Controls communications. for emails.
File High Lack of watermarking Integrate DLP and Accepted
Handling or encryption for tagging policies.
Security internal documents.
Cyber Medium Absence of a cyber risk Procure cyber Accepted
Insurance transfer mechanism. insurance coverage.
Vendor Medium Cloud service Mandate compliance Accepted
Audit providers did not documentation from
Reports submit IS audit reports. vendors.
ATM Very No withdrawal Enforce dynamic Accepted
Software High restrictions based on withdrawal limits in
Control transaction profile. ATM software.
17 | P a g e
12. Summary/Conclusion
The cyber security audit of Sterling Cooperative Bank revealed systemic weaknesses across
technical and policy layers, with several vulnerabilities falling into high and very high-risk
categories. These pose serious concerns including data compromise, operational disruption,
and non-compliance with regulatory mandates.
Key takeaways:
• Immediate revision of cyber security policies in alignment with the FRCI framework.
• Urgent implementation of technical safeguards, including 2FA and email encryption.
• Integration of secure practices across third-party management and development
lifecycles.
• Regular cyber awareness programs tailored to evolving attack patterns.
• Adoption of a robust cyber insurance policy.
Regular audits and active Board oversight are essential to maintaining a secure, compliant, and
resilient banking environment.
THANK YOU !!
18 | P a g e