Our adherence to SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) for Regulated Entities.
InvestValue Capital is committed to protecting client information, systems, databases, and networks from emerging cyber threats — safeguarding their Confidentiality, Integrity and Availability (CIA) in line with SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) for Regulated Entities.
As a SEBI-registered Portfolio Manager, InvestValue Capital Pvt. Ltd. is a Regulated Entity (RE) under the CSCRF and follows its graded, risk-based approach to cybersecurity and cyber resilience.
Under the framework's AUM-based categorization, InvestValue Capital is classified as a Self-certification RE, and complies with the controls and reporting obligations applicable to that category.
Controls and practices we maintain as a Self-certification Regulated Entity under the CSCRF.
A board-approved cybersecurity policy covering essential areas, reviewed periodically.
Cyber risk assessments conducted annually to identify, evaluate, and treat risks.
Vulnerability Assessment & Penetration Testing carried out annually as per SEBI scope.
Annual compliance self-certification (Annexure-P), signed by management and submitted to SEBI.
Security Operations Center coverage for monitoring and threat detection.
A documented Incident Response Plan, developed and reviewed annually, aligned with CERT-In.
Cybersecurity awareness training conducted for staff on an annual basis.
Security best practices adopted, drawing on ISO 27001 principles.
Data classification, need-based access, and backup & recovery controls.
Compliance with the CSCRF is reviewed and approved by the management of InvestValue Capital. Designated personnel are responsible for the cybersecurity function, supported by our Compliance Officer, with periodic review of user access rights and privileged-user activities.