INFORMATION TECHNOLOGY POLICY
1. Preamble / Objective
Venus Barter Private Limited ("the Company") is committed to robust, secure, and efficient use of Information Technology (IT) to support its digital lending operations through the VMoney platform. This IT Policy is formulated in compliance with RBI's Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (2023–2024), Scale Based Regulation Directions, and other applicable guidelines.
The Policy aims to:
- Ensure IT governance aligned with business objectives
- Protect customer data, systems, and operations from cyber threats
- Manage IT risks effectively
- Maintain business continuity and operational resilience
- Comply with regulatory requirements for digital lending NBFCs
2. Scope
- All IT systems, applications (including VMoney app/website), infrastructure, data, and networks
- Employees, contractors, vendors, and third parties accessing Company IT resources
- All phases: acquisition, development, operations, maintenance, and disposal
3. IT Governance & Organizational Structure
- Board Oversight: The Board of Directors shall approve this Policy, review it annually, and oversee IT strategy, risks, and major incidents.
- IT Strategy Committee: (If applicable) chaired by a Director to review IT plans and initiatives.
- Chief Information Officer (CIO) / IT Head: Responsible for IT operations and implementation.
- Chief Information Security Officer (CISO): Responsible for cybersecurity (may be combined with CIO for smaller scale).
- Roles & Responsibilities: Clearly defined through a RACI matrix.
4. IT Risk Management & Controls
The Company conducts periodic IT risk assessments (at least annually or upon material changes) and implements controls based on risk levels, including:
- Access Controls: Role-based access, MFA, privileged access management
- Network Security: Firewalls, IDS/IPS, secure VPN
- Data Protection: Encryption, data classification, masking of sensitive data
- Application Security: Secure SDLC, code reviews, vulnerability scanning
- Endpoint Security: Anti-malware and EDR solutions
- Patch management, logging, and continuous monitoring
5. Information Security & Cybersecurity
- Board-approved Cyber Security Policy integrated into this Policy
- Regular VAPT exercises (at least bi-annually for critical systems)
- Incident Response Plan and Cyber Crisis Management Plan (CCMP)
- Reporting of material cyber incidents to RBI within prescribed timelines
- Annual employee cybersecurity awareness training
- Third-party/vendor cybersecurity risk management and audits
6. Business Continuity & Disaster Recovery (BCP-DR)
- BCP-DR plan tested at least annually
- Defined RTO & RPO for critical systems like loan origination and disbursement
- Daily/periodic data backups with offsite/cloud storage
- Alternate DR site commensurate with Company scale
7. IT Outsourcing & Third-Party Management
- Compliance with RBI outsourcing guidelines
- Board approval for material outsourcing with exit clauses and audits
- No outsourcing of core functions without regulatory approval
- Data stored in India with safeguards for any cross-border processing
8. IT Operations & Change Management
- Formal change and release management processes
- Immutable audit trails for critical transactions
- Regular internal and external system audits
9. Compliance & Assurance
- Annual independent IS Audit
- Compliance with DPDP Act 2023, IT Act 2000, RBI guidelines
- Periodic reporting of cyber incidents and audit findings to Board/RBI
10. Review & Approval
- This Policy shall be reviewed annually or upon significant regulatory changes, incidents, or business shifts.
- Approved by the Board of Directors.
- Any deviation requires documented approval with risk justification.