UPSC Prelims Practice Questions — SEBI unveils index for market infrastructure institutions

Q1. Consider the following statements regarding the IT Resilience Index (ITRI) for market infrastructure institutions and the measures that preceded it: 1. Unlike the Annual System Audit of market infrastructure institutions, which SEBI mandated through a circular issued in January 2020, the ITRI score is arrived at on a half-yearly basis. 2. The ITRI framework was first placed in the public domain as a consultation paper in March 2026 and was introduced in final form in August 2026. 3. The introduction of the ITRI supersedes the Cybersecurity and Cyber Resilience Framework issued in August 2024, which now stands withdrawn for market infrastructure institutions. Which of the statements given above is/are correct?

  1. Unlike the Annual System Audit of market infrastructure institutions, which SEBI mandated through a circular issued in January 2020, the ITRI score is arrived at on a half-yearly basis.
  2. The ITRI framework was first placed in the public domain as a consultation paper in March 2026 and was introduced in final form in August 2026.
  3. The introduction of the ITRI supersedes the Cybersecurity and Cyber Resilience Framework issued in August 2024, which now stands withdrawn for market infrastructure institutions.
  • A. 1 only
  • B. 2 and 3 only
  • C. 1 and 2 only
  • D. 1, 2 and 3

Q2. A standardised scorecard called the IT Resilience Index, used to assess the robustness of the information technology systems of stock exchanges, depositories and clearing corporations in India, has been introduced by which one of the following?

  • A. The Reserve Bank of India, acting under the Payment and Settlement Systems Act, 2007
  • B. The International Financial Services Centres Authority, acting under the IFSCA Act, 2019
  • C. The Securities and Exchange Board of India, acting under the SEBI Act, 1992
  • D. The Ministry of Electronics and Information Technology, Government of India

Q3. The registration and functioning of NSDL and CDSL is principally governed by which one of the following?

  • A. The Securities Contracts (Regulation) (Stock Exchanges and Clearing Corporations) Regulations, 2018
  • B. The SEBI (Custodian) Regulations, 1996, read with the Securities Contracts (Regulation) Act, 1956
  • C. The SEBI (Intermediaries) Regulations, 2008, read with the Companies Act, 2013
  • D. The Depositories Act, 1996, read with the SEBI (Depositories and Participants) Regulations, 2018

Q4. Which one of the following statements about the Securities Contracts (Regulation) (Stock Exchanges and Clearing Corporations) Regulations, 2018 is correct?

  • A. They require every recognised stock exchange to itself carry out the clearing and settlement of the trades executed on it
  • B. They require clearing and settlement to be carried out by an entity legally separate from the stock exchange whose trades it settles
  • C. They bar a recognised stock exchange from holding any shareholding in the entity that settles its trades, which must have wholly independent promoters
  • D. They designate NSDL and CDSL as the settlement entities for trades executed in the equity segment of recognised stock exchanges

Q5. Under the ITRI framework, a comparative analysis of the scores of two consecutive half-years, together with the corrective actions proposed, is to be placed before which one of the following?

  • A. The Audit Committee of the institution concerned and the Reserve Bank of India
  • B. The Risk Management Committee of the institution concerned and SEBI's Technical Advisory Committee
  • C. The Standing Committee on Technology of the institution concerned and its governing board
  • D. The Regulatory Oversight Committee of the institution concerned and the Ministry of Finance

Q6. The IT Resilience Index is computed on a 100-point scale using a uniform set of nine parameters, each with a fixed weightage. With reference to this, consider the following parameter–weightage pairs: 1. Availability — 20 points 2. Business continuity — 10 points 3. Cost efficiency — 5 points 4. Scalability — 5 points Which of the above is/are NOT correctly matched?

  1. Availability — 20 points
  2. Business continuity — 10 points
  3. Cost efficiency — 5 points
  4. Scalability — 5 points
  • A. 1 and 3
  • B. 3 only
  • C. 2 and 4
  • D. 3 and 4

Q7. Consider the following statements regarding the Early Warning System required of market infrastructure institutions under SEBI's IT resilience framework: 1. It is intended to flag deterioration in the index parameters before it results in performance issues, system slowness or other disruptions, rather than to document incidents after they have occurred. 2. It is to be operationalised, along with real-time monitoring of service delivery, by 28 February 2027. 3. Like the index score itself, it is to be generated once every half-year, within 60 days of the close of that half-year. Which of the statements given above is/are correct?

  1. It is intended to flag deterioration in the index parameters before it results in performance issues, system slowness or other disruptions, rather than to document incidents after they have occurred.
  2. It is to be operationalised, along with real-time monitoring of service delivery, by 28 February 2027.
  3. Like the index score itself, it is to be generated once every half-year, within 60 days of the close of that half-year.
  • A. 1 only
  • B. 1 and 2 only
  • C. 2 and 3 only
  • D. 1, 2 and 3

Q8. Consider the following items in relation to what market infrastructure institutions are required to have in place by 28 February 2027 under SEBI's IT resilience framework: 1. An Early Warning System to detect deterioration in the resilience index parameters 2. Real-time monitoring of service delivery 3. A beta version of the resilience index, to be run for the first time only after that date 4. The half-yearly index computation, the first of which is to be for the half-year ended 30 September 2026 Which of the above is/are correctly identified?

  1. An Early Warning System to detect deterioration in the resilience index parameters
  2. Real-time monitoring of service delivery
  3. A beta version of the resilience index, to be run for the first time only after that date
  4. The half-yearly index computation, the first of which is to be for the half-year ended 30 September 2026
  • A. 1 and 2
  • B. 2 and 3
  • C. 1, 2 and 4
  • D. 3 and 4

Q9. Consider the following statements about the evolution of SEBI's technology oversight of market infrastructure institutions: 1. The requirement of an annual system audit for market infrastructure institutions was introduced by a SEBI circular in January 2020. 2. The Cybersecurity and Cyber Resilience Framework issued by SEBI in August 2024 applies exclusively to market infrastructure institutions. 3. SEBI's consultation paper proposing the IT Resilience Index was issued in August 2023, and dedicated cyber security and cyber resilience guidelines for market infrastructure institutions followed in March 2026. Which of the statements given above is/are correct?

  1. The requirement of an annual system audit for market infrastructure institutions was introduced by a SEBI circular in January 2020.
  2. The Cybersecurity and Cyber Resilience Framework issued by SEBI in August 2024 applies exclusively to market infrastructure institutions.
  3. SEBI's consultation paper proposing the IT Resilience Index was issued in August 2023, and dedicated cyber security and cyber resilience guidelines for market infrastructure institutions followed in March 2026.
  • A. 1 only
  • B. 1 and 2 only
  • C. 2 and 3 only
  • D. 1 and 3 only

Q10. The Cybersecurity and Cyber Resilience Framework (CSCRF) notified by SEBI in August 2024 is best described as which one of the following?

  • A. A set of norms confined to stock brokers and depository participants, leaving market infrastructure institutions to be governed by the 2023 guidelines alone
  • B. A regulation notified under the SEBI Act that replaced the existing requirement of a periodic system audit for regulated entities
  • C. A voluntary code of practice for exchanges whose observance is examined only when their recognition falls due for renewal
  • D. A consolidated framework on cyber security and cyber resilience applicable to SEBI Regulated Entities generally, and not confined to any one class of them

Q11. Consider the following statements about the manner in which the IT Resilience Index was put in place by SEBI: 1. It was brought into effect through a SEBI circular, and not through an amendment to the Securities Contracts (Regulation) (Stock Exchanges and Clearing Corporations) Regulations, 2018. 2. A beta version of the framework had already been implemented by the market infrastructure institutions before its formal introduction. 3. The framework was finalised directly, without any prior stage of public consultation on a draft. 4. The score of each institution is to be published by SEBI on its website every quarter as a public ranking of market infrastructure institutions. Which of the above is/are correctly identified?

  1. It was brought into effect through a SEBI circular, and not through an amendment to the Securities Contracts (Regulation) (Stock Exchanges and Clearing Corporations) Regulations, 2018.
  2. A beta version of the framework had already been implemented by the market infrastructure institutions before its formal introduction.
  3. The framework was finalised directly, without any prior stage of public consultation on a draft.
  4. The score of each institution is to be published by SEBI on its website every quarter as a public ranking of market infrastructure institutions.
  • A. 1 and 2
  • B. 2 and 3
  • C. 1, 2 and 4
  • D. 3 and 4