Which method to follow
The method that answers RBI's paragraph 30, the ones you set aside, and why.
Security architecture consulting in India
When you adopt new technology or overhaul existing systems, the Reserve Bank of India (RBI) says to follow a standard enterprise architecture planning methodology or framework, but names none. The Securities and Exchange Board of India (SEBI) leaves similar choices to your IT Committee. We help you decide, and record why and who approved it.
What we do
The method that answers RBI's paragraph 30, the ones you set aside, and why.
Reference designs you are already tied to, including any that came with a platform.
Four tests from the US National Institute of Standards and Technology (NIST), asked as plain questions.
Nobody is trusted by default. SEBI states it three ways; we reconcile them.
The survey of your assets, accounts, data flows and workflows that NIST puts before zero trust.
Which of the three Center for Internet Security (CIS) Implementation Groups, sorted by risk and resources, fits you, so a gap becomes a next step.
The clause that names no framework
Paragraph 30 of RBI's 2026 Directions for commercial banks reads: "The bank shall adopt a standard enterprise architecture planning methodology or framework while adopting new or emerging technologies, tools, or while revamping the existing technology stack."
SEBI reached the same place from the other side. Its Cybersecurity and Cyber Resilience Framework (CSCRF) prescribed four things, zero trust among them. A circular of 28 August 2025 turned them into decisions for your IT Committee. Either way, the decision record is yours.
NIST SP 800-207, section 7.3, makes "a survey of assets, subjects, data flows, and workflows" the enterprise's own first step. That includes administrator and developer accounts that in legacy architectures "may have blanket permission to access all enterprise resources", and unknown "shadow IT". SEBI's ID.AM (asset management) guidelines ("All REs (Mandatory)") already require that inventory, updated "within 3 working days" of a change, and an entity-wide network architecture diagram "including wired and wireless networks", read subject to the Principle of Exclusivity added on 28 August 2025, which limits the framework's scope to what is used exclusively for SEBI regulated activities.
NIST suggests starting with "a low-risk business process", with first policies run in reporting-only mode.
From SP 800-207, section 7.3.5:
We answer none of them on any vendor's behalf.
Rule 6(1) of the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), November 2025) sets a Data Fiduciary's minimum safeguards: encryption, obfuscation, masking or virtual tokens; access control; log visibility; backups; keeping logs and data "for a period of one year" unless another law says otherwise; Data Processor contract clauses; and other measures. Each describes how a system is built. Rule 1(4) starts Rule 6 "eighteen months after the date of publication of this Gazette". See which DPDP clauses have commenced.
Criteria that need no tooling
NIST SP 800-160 Vol. 1 Rev. 1 sets four tests that any protection mechanism must pass.
| Criterion | NIST's words | Question for your design |
|---|---|---|
| Non-bypassable | "The mechanism must not be circumventable" | Which paths go around it? Check break-glass accounts, admin consoles, direct database access and old scheduled jobs. |
| Evaluatable | Small and simple enough "to be assessed to produce adequate confidence" | Can anyone name the control objective it enforces and check it does so correctly? If not, it fails. |
| Always invoked | "The protection provided by a mechanism or feature that is not always invoked is not continuous." | Which environments, tenants or failure modes skip it? A rule checked in the user interface but not the API behind it is the classic case. |
| Tamper-proof | "cannot be modified in an unauthorized manner" | Who can change it or its policy, and who sees that change afterwards? |
Appendix D.3 of SP 800-160 (November 2022) lists five design alternatives "in order of decreasing effectiveness": design selection that eliminates the potential for loss; design alteration that reduces it; engineered features or devices; visibility and feedback; and signage, procedures, training and equipment, which NIST says should be avoided as the only means of reducing loss.
A boxed note on page 76 quotes a 2015 RAND Corporation report: "Poor systems security engineering is very difficult to mitigate by overlaying security controls, whereas security controls overlaid on a sound, secure design can be quite effective."
CIS Controls v8 and v8.1 hold 153 Safeguards in three Implementation Groups (IGs), and CIS says "Every enterprise should start with IG1", its "essential cyber hygiene". On the CIS Controls Navigator (10 September 2026), three of the eighteen Controls have no IG1 Safeguards, including Network Monitoring and Defense (0 of 11) and Application Software Security (0 of 14).
Safeguards 12.2, 3.7, 12.4 and 3.8 (secure network architecture, data classification, architecture diagrams, data flows) are IG2 and above, though SEBI's ID.AM asks every regulated entity for a network diagram and data flows. Safeguard 16.14, Conduct Threat Modeling, is IG3 only, so threat modeling is its own engagement.
How we work
Appendix H.4.3 of NIST SP 800-160 sets out four activities. None is running a tool.
We agree strategy, objectives and judging criteria, and list the reference architectures that already apply (AR-1, AR-1.2).
We draw up more than one option and say what each connects to outside your systems (AR-2). No alternative, no real review.
We weigh each option against the criteria and share findings and recommendations with your team (AR-3.3, AR-3.4).
We record each key decision and its reasons, get your approver's agreement, link each control to the requirement it answers so it can be traced, and support your architecture governance (AR-4).
Scope and limits
No audit under section 70B of the Information Technology Act, 2000, and no certificate or attestation. SecWiz is not a CERT-In empanelled auditing organization.
NIST rules out judging conformance against its thirty design principles, so you get findings, not a percentage.
SecWiz does not operate a security operations center (SOC). RBI's 2026 Directions place a commercial bank's required SOC in its own chief information security officer's (CISO) office, whoever staffs it.
A bounded engagement. Advisory work runs in business hours. Monitoring set-up, incident response and retainers are separate: see managed security services.
Related: threat modeling, security posture assessment, threat detection and SOC readiness, vCISO services, GRC and compliance and all defensive cybersecurity services.
FAQ
NIST names them in SP 800-160 Vol. 1 Rev. 1, Appendix H.4.3: findings and recommendations (AR-3.3), agreement on the security aspects of the architecture (AR-4.1), a record of key decisions and the rationale (AR-4.2), traceability (AR-4.3), showing which requirement each control answers, and baseline artifacts (AR-4.4). No score, maturity level or percentage is on the list.
Some of it, eventually: NIST's zero trust planning guide, CSWP 20 of 6 May 2022, says some changes "may involve the purchase and deployment of new infrastructure". But the first work is produced, not bought: the survey NIST SP 800-207 leaves with you, the inventory and network diagram SEBI already requires, the trade-offs RBI wants written down, and the 56 of 153 CIS Safeguards in IG1. Your own people can start all four.
Three SEBI texts bear on it, and they differ. PR.AA (identity and access) Standard 4 of the CSCRF says "follow Zero Trust Model", with no definition. A PR.AA guideline, applicability "MIIs and Qualified REs (Mandatory)" (market infrastructure institutions and qualified regulated entities), denies access to critical systems by default. SEBI's 28 August 2025 circular replaced it with suggested strategies approved by the IT Committee. The framework's 205 pages never cite NIST SP 800-207, so you reconcile from SEBI's own words. NIST calls its own seven tenets "the ideal goal", adding that not all may be fully implemented.
No, and the refusal is NIST's. SP 800-160 Vol. 1 Rev. 1 says Appendix E's thirty principles should not be "used as a basis for making judgments on conformance", and that they may conflict. NIST's criteria are the four in Table 3, which give findings, not a rating.
RBI names none; choosing and recording is the work. As checked on 10 September 2026, access differs: NIST SP 800-160, SP 800-207 and CSWP 20 are direct PDF downloads from nvlpubs.nist.gov; the TOGAF Standard (an enterprise architecture framework) redirects to an Open Group login; the white papers index of SABSA (a security architecture method) is "restricted to members only", though ten named documents are free on request. Internal use of SABSA is "Free to use with brief copyright citation", but training on it needs the SABSA Institute's "prior written consent".
RBI has issued separate sets since 31 July 2026; check paragraph 3 of yours. The commercial banks set covers banking companies, corresponding new banks and the State Bank of India as the Banking Regulation Act, 1949 defines them, but not local area banks. Small finance banks, payments banks, Credit Information Companies, the five All India Financial Institutions and non-banking financial companies (NBFCs) have their own sets; the NBFC set puts the architecture duty in Chapter V, which covers only the Top, Upper and Middle Layers, not Core Investment Companies. Foreign banks in branch mode take paragraph 4's comply-or-explain route, where a deviation is "subject to examination and acceptance by RBI of a reasonably justifiable explanation". RBI's circular DoS.CO.PPG.66/11.01.005/2026-27 of the same date lists the 2016 Cyber Security Framework in Banks and the 2023 IT Governance Directions among the circulars it repealed.
No on both counts. This is advisory work: no audit under section 70B of the Information Technology Act, no certificate or attestation, and SecWiz is not a CERT-In empanelled auditing organization. Where a regulator requires one, the work goes to a firm that holds the empanelment. You get evidence and a decision record for your own named body to approve; the obligation stays with you.
Not in this engagement: it is bounded advisory work in business hours, with no monitoring. SecWiz does not operate a security operations center. Where a managed security retainer includes security monitoring, its coverage hours and escalation path are agreed in writing; see managed security services. The duty stays with you: RBI's paragraph 143 says a bank "shall set up a CSOC to ensure continuous surveillance", paragraph 28(4) places the SOC in the bank's own CISO office, and Rule 6(1)(c) of the DPDP Rules, 2025 puts log visibility on the Data Fiduciary.
Let's talk
Send the rule that binds you, the decision it forces and the limits that will settle it, and we scope against those. We reply within one working day.