{
 "framework": "CORF",
 "title": "Cyber and Operational Resilience Framework",
 "issuer": "Central Bank of Kuwait",
 "version": "1.0",
 "issued": "2025-12-03",
 "baselines": [
  {
   "code": "CRB",
   "name": "Cyber Resilience Baselines",
   "domains": [
    {
     "domain": 1,
     "section": "4",
     "name": "Governance, Risk, and Compliance",
     "subdomains": [
      {
       "num": "4.1",
       "name": "Cyber Resilience Governance and Oversight",
       "areas": [
        {
         "num": "4.1.1",
         "name": "Board of Directors",
         "controls": [
          {
           "id": "4.1.1.1",
           "text": "The Board of Directors (hereinafter referred as, the Board) of Regulated Entities shall be the approving authority for the cybersecurity strategy, and shall provide authorization for the cyber resilience policy.",
           "key": "CRB:4.1.1.1"
          },
          {
           "id": "4.1.1.2",
           "text": "The Board may delegate certain responsibilities to relevant committees or independent functions, however, the Board shall retain ultimate accountability for the Entity’s overall cyber resilience and shall be reviewed at least annually as part of its formal meetings.",
           "key": "CRB:4.1.1.2"
          },
          {
           "id": "4.1.1.3",
           "text": "The Board shall be accountable, including approving cyber risk appetite and tolerance levels, and ensuring strategic oversight of evolving cybersecurity trends and threats.",
           "key": "CRB:4.1.1.3"
          },
          {
           "id": "4.1.1.4",
           "text": "The Board shall ensure the allocation of adequate cybersecurity budget and resources.",
           "key": "CRB:4.1.1.4"
          },
          {
           "id": "4.1.1.5",
           "text": "The Board shall receive regular updates from the Cybersecurity Steering Committee on the overall status of the cybersecurity program, as well as additional updates as needed on emerging threats or significant changes in the risk landscape. Additionally, the Board shall be informed and kept updated on any legal or regulatory implications of cyber risks.",
           "key": "CRB:4.1.1.5"
          }
         ]
        },
        {
         "num": "4.1.2",
         "name": "Cybersecurity Steering Committee",
         "controls": [
          {
           "id": "4.1.2.1",
           "text": "The Cybersecurity Steering Committee established with the participation of: a) the head of the Information Security function; b) executives and Senior Managers from all relevant departments/ functions (i.e.,CxOs, relevant business functions, and compliance);",
           "key": "CRB:4.1.2.1"
          },
          {
           "id": "4.1.2.2",
           "text": "The Cybersecurity Steering Committee shall be chaired by a designated individual with relevant expertise and sufficient cybersecurity knowledge.",
           "key": "CRB:4.1.2.2"
          },
          {
           "id": "4.1.2.3",
           "text": "The committee shall develop a charter that is approved by the Board. The charter shall include, at a minimum: a) the committee’s objective; b) the committee members; and c) the frequency and quorum of meetings, with meetings held at least four (4) times a year.",
           "key": "CRB:4.1.2.3"
          },
          {
           "id": "4.1.2.4",
           "text": "The Board may delegate specific cybersecurity-related responsibilities to this Cybersecurity Steering Committee, which shall be established and mandated by the Board. These responsibilities shall be limited to advisory, oversight, and some operational coordination functions. This committee shall not have the authority to approve strategic decisions, such as the cybersecurity strategy or risk appetite.",
           "key": "CRB:4.1.2.4"
          },
          {
           "id": "4.1.2.5",
           "text": "The Cybersecurity Steering Committee shall: a) review and endorse the cybersecurity strategy and policy; b) recommend the Entity’s cyber risk appetite and oversee the alignment of the cybersecurity program, strategy, and policy with the overall business objectives; c) review alignment of the cyber risk tolerance levels with the approved cyber risk appetite; d) monitor the effectiveness of the cybersecurity program, including Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and resources allocation; e) oversee cyber incident response readiness, post-incident reviews, and the effectiveness of the awareness program; and f) stay updated on emerging cyber threats, regulatory changes, and ensure compliance.",
           "key": "CRB:4.1.2.5"
          }
         ]
        },
        {
         "num": "4.1.3",
         "name": "Executive/ Senior Management",
         "controls": [
          {
           "id": "4.1.3.1",
           "text": "Executive/ Senior Management shall be the approving authority of cyber resilience policy and cybersecurity initiatives supporting the strategy approved by the Board.",
           "key": "CRB:4.1.3.1"
          },
          {
           "id": "4.1.3.2",
           "text": "Executive/ Senior Management, including CEO and other C-level executives, shall support the effective execution of cybersecurity strategy.",
           "key": "CRB:4.1.3.2"
          },
          {
           "id": "4.1.3.3",
           "text": "Executive/ Senior Management shall be responsible for implementing risk management strategies, ensuring active alignment with the approved cyber risk appetite and tolerance levels, and continuously adapting the Entity’s cybersecurity posture to evolving trends and threats.",
           "key": "CRB:4.1.3.3"
          },
          {
           "id": "4.1.3.4",
           "text": "Executive/ Senior Management shall allocate proper cybersecurity budget, define, and assign roles and responsibilities with relevant expertise and in alignment with CORF requirements, and continually promote a cybersecurity culture throughout the Regulated Entity.",
           "key": "CRB:4.1.3.4"
          },
          {
           "id": "4.1.3.5",
           "text": "Executive/ Senior Management shall approve the size and resources of the Information Security function.",
           "key": "CRB:4.1.3.5"
          },
          {
           "id": "4.1.3.6",
           "text": "Executive/ Senior Management shall ensure the alignment and implementation of cybersecurity policies and standards, developed by the Information Security function, across all business functions.",
           "key": "CRB:4.1.3.6"
          },
          {
           "id": "4.1.3.7",
           "text": "Executive/ Senior Management shall also ensure proper segregation between information security and IT Operations by assigning appropriate oversight authority to the Information Security Function.",
           "key": "CRB:4.1.3.7"
          }
         ]
        },
        {
         "num": "4.1.4",
         "name": "Information Security Function",
         "controls": [
          {
           "id": "4.1.4.1",
           "text": "Regulated Entities shall establish an Information Security function independent from Information Technology operations, empowered by the Board, with oversight from the Cybersecurity Steering Committee, and support from Executive/Senior Management. This independent function shall be headed by a designated Information Security professional and shall have necessary skills, knowledge, and competency.",
           "key": "CRB:4.1.4.1"
          },
          {
           "id": "4.1.4.2",
           "text": "The size of the Information Security function shall be determined based on the complexity, nature of business, technology assets, and complexity of operations.",
           "key": "CRB:4.1.4.2"
          },
          {
           "id": "4.1.4.3",
           "text": "The Information Security Function shall have the authority to oversee and provide independent assurance on the management and effectiveness of key operational security activities, including the Security Operations Center (SOC), cyber threat intelligence, vulnerability management, and incident management processes.",
           "key": "CRB:4.1.4.3"
          },
          {
           "id": "4.1.4.4",
           "text": "The head of the Information Security function shall be responsible for defining and reviewing the cybersecurity strategy.",
           "key": "CRB:4.1.4.4"
          },
          {
           "id": "4.1.4.5",
           "text": "The Information Security function shall define the cyber risk tolerance levels based on the approved risk appetite, ensuring alignment with the organizational objectives, regulatory requirements, and operational capabilities.",
           "key": "CRB:4.1.4.5"
          },
          {
           "id": "4.1.4.6",
           "text": "The Information Security function shall set the policies and standards for the governance, implementation, operation, monitoring, and response of cybersecurity controls in alignment with Regulated Entity’s strategy, risk appetite, and risk tolerance levels.",
           "key": "CRB:4.1.4.6"
          },
          {
           "id": "4.1.4.7",
           "text": "The Information Security function shall assess the adequacy of security controls to mitigate cyber risks, and would approve/ ensure approvals of any exceptions taking into consideration the compliance with the applicable regulatory guidance and the entity’s risk appetite. The Information Security function shall ensure that cybersecurity awareness and training programs are effectively provided/ delivered to all employees, contractors, and relevant third-party vendors.",
           "key": "CRB:4.1.4.7"
          },
          {
           "id": "4.1.4.8",
           "text": "The Information Security function shall update the Cybersecurity Steering Committee, at least quarterly, and whenever there are any changes or emerging risks that require attention, about the overall status of their cybersecurity program.",
           "key": "CRB:4.1.4.8"
          }
         ]
        },
        {
         "num": "4.1.5",
         "name": "Cybersecurity Strategy",
         "controls": [
          {
           "id": "4.1.5.1",
           "text": "The cybersecurity strategy shall be defined, approved, implemented, and reviewed at least annually, where: a) the cybersecurity strategy shall undergo a formal and documented review on annual basis. b) the cybersecurity strategy shall also be subject to change-driven reviews triggered by significant internal or external factors that require revisions. These factors may include, but not limited to: i. major changes in the operating environment (e.g., business expansion, merger and acquisitions, technological advancement). ii. new or updated regulatory, legal, or sectoral requirements. iii. significant shifts in the cyber threats landscape or newly identified risks. c) the head of the Information Security function of the Regulated Entity shall present and obtain approval on the defined cybersecurity strategy and roadmap from the Board or the corresponding function/ committee as defined in the organization’s structure, annually or following any change-driven revisions.",
           "key": "CRB:4.1.5.1"
          },
          {
           "id": "4.1.5.2",
           "text": "Regulated Entity’s cybersecurity strategy shall: a) define the desired cybersecurity maturity level and include clear cybersecurity objectives aligned with organizational goals and business objectives; b) align with the current deployed technology environment and future technology-related initiatives; c) Details into cyber initiatives / programs / projects that will enable the successful achievement of the desired cybersecurity capabilities; d) mandate compliance with applicable regulatory, legal and business requirements; and e) define the thresholds for cyber KPIs and KRIs, along with the hierarchy for reporting.",
           "key": "CRB:4.1.5.2"
          },
          {
           "id": "4.1.5.3",
           "text": "Regulated Entities shall identify the responsibility and accountability for strategy implementation and monitoring.",
           "key": "CRB:4.1.5.3"
          }
         ]
        },
        {
         "num": "4.1.6",
         "name": "Cyber Resilience Policy",
         "controls": [
          {
           "id": "4.1.6.1",
           "text": "The cyber resilience policy shall be defined, approved, implemented, communicated, enforced, and made accessible to all employees, contractors, and relevant third-party vendors.",
           "key": "CRB:4.1.6.1"
          },
          {
           "id": "4.1.6.2",
           "text": "The cyber resilience policy shall be reviewed at least annually or when warranted by changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "CRB:4.1.6.2"
          },
          {
           "id": "4.1.6.3",
           "text": "The cyber resilience policy shall: a) define cybersecurity objectives and scope, Executive/ Senior Management’s commitment, cybersecurity roles and responsibilities, enforcement mechanisms, and deterrents for non-compliance; b) incorporate relevant international best practices, frameworks, and standards; c) include domains in alignment with the Regulated Entity’s business objectives, technology assets, and relevant organizational and regulatory policies; and d) consider applicable legal, regulatory, and business requirements.",
           "key": "CRB:4.1.6.3"
          },
          {
           "id": "4.1.6.4",
           "text": "Departmental policies from other functions (such as HR, IT, Risk Management, and Procurement) shall align with the cyber resilience policy, with Executive/Senior Management ensuring this alignment.",
           "key": "CRB:4.1.6.4"
          },
          {
           "id": "4.1.6.5",
           "text": "Regulated Entities shall ensure that supporting procedures, processes, and guidelines are established to enable the implementation of the policy.",
           "key": "CRB:4.1.6.5"
          },
          {
           "id": "4.1.6.6",
           "text": "Regulated Entities shall ensure that all employees, contractors and relevant third-party vendors are responsible for complying with the organizational cyber resilience policy, as well as related standards and procedures.",
           "key": "CRB:4.1.6.6"
          },
          {
           "id": "4.1.6.7",
           "text": "The cyber resilience policy shall be approved by the Executive/Senior Management and authorized by the Board to ensure alignment with the Entity’s overall objectives and the proper management of cyber risks.",
           "key": "CRB:4.1.6.7"
          }
         ]
        }
       ]
      },
      {
       "num": "4.2",
       "name": "Cybersecurity Risk Management",
       "areas": [
        {
         "num": "4.2.1",
         "name": "Cybersecurity Risk Management Methodology",
         "controls": [
          {
           "id": "4.2.1.1",
           "text": "The cybersecurity risk management methodology shall be defined, and implemented by the Information Security function, in collaboration with relevant teams such as IT, Risk Management, Compliance, and Internal Audit. The methodology shall be approved by the Executive/ Senior Management.",
           "key": "CRB:4.2.1.1"
          },
          {
           "id": "4.2.1.2",
           "text": "The cybersecurity risk management methodology shall be reviewed by the Information Security function on annual basis to ensure continued relevance and effectiveness.",
           "key": "CRB:4.2.1.2"
          },
          {
           "id": "4.2.1.3",
           "text": "Information Security function shall regularly communicate the cybersecurity risk management methodology, at least annually, to all relevant business and technology owners, and annually conduct awareness programs to ensure proper understanding and execution of risk assessments and management across the Entity.",
           "key": "CRB:4.2.1.3"
          },
          {
           "id": "4.2.1.4",
           "text": "Cybersecurity risk management shall be integrated and incorporated with the broader enterprise-wide risk management strategy, by ensuring alignment of cybersecurity risk appetite and response measures with those defined and established at the enterprise level.",
           "key": "CRB:4.2.1.4"
          },
          {
           "id": "4.2.1.5",
           "text": "The Regulated Entities shall ensure that: a) the cybersecurity risk management methodology is based on international best practices, frameworks, and latest standards such as ISO 31000, ISO 27005, ISO 27001, NIST 800-39 and ISF Standard of Good Practice; b) scope, periodicity, and execution responsibility for risk assessments and management are defined; c) risk appetite and tolerance levels are specified and determined based on the organizational priorities and objectives; and d) processes and templates for risk identification, assessment, treatment, and overall monitoring and reporting are specified and documented within a centralized risk register to ensure a unified and comprehensive approach.",
           "key": "CRB:4.2.1.5"
          }
         ]
        },
        {
         "num": "4.2.2",
         "name": "Cybersecurity Risk Identification and Assessment",
         "controls": [
          {
           "id": "4.2.2.1",
           "text": "The risk identification exercise shall consider both internal and external threats and vulnerabilities, as well as the risks impacting the basic principles set out in the Baselines.",
           "key": "CRB:4.2.2.1"
          },
          {
           "id": "4.2.2.2",
           "text": "The Regulated Entity shall take into account of the following during risk assessment: a) regulatory and legal requirements as applicable; b) technology assets and their criticality; c) connections with external networks; d) customer delivery channels; e) application interfaces; f) threat scenarios and actors (both internal and external); g) vulnerabilities stemming from governance, processes, design, infrastructure, or human factors; and h) active threat intelligence sources.",
           "key": "CRB:4.2.2.2"
          },
          {
           "id": "4.2.2.3",
           "text": "The identified cybersecurity risks, including threats, vulnerabilities, and controls, shall be documented in a centralized risk register.",
           "key": "CRB:4.2.2.3"
          },
          {
           "id": "4.2.2.4",
           "text": "Risks shall be evaluated on the basis of severity, impact to business and operations, and likelihood of their occurrence. The actual residual risk value for each identified risk shall be calculated and included in the risk register.",
           "key": "CRB:4.2.2.4"
          },
          {
           "id": "4.2.2.5",
           "text": "The risk assessment outcomes shall be reported to, discussed with, and agreed upon with the respective Business and Technology risk owners within the Regulated Entity. The relevant business owner(s) (i.e., risk owner(s)) within the Regulated Entity shall accept and endorse the risk assessment results, in alignment with the Entity’s risk appetite and tolerance levels.",
           "key": "CRB:4.2.2.5"
          },
          {
           "id": "4.2.2.6",
           "text": "The risk assessment shall be conducted annually, or whenever: a) new products and technologies are introduced; b) there is a significant change in technology, business, or operations-related processes; c) new material risks are detected by the Regulated Entity or reported by threat intelligence, indicating new or emerging risks; d) new third-party agreements are signed, taking into consideration the nature and criticality of the service being outsourced, regardless of whether the services are deemed critical or not. All third-party agreements, including non-critical ones, shall be subject to a cybersecurity risk assessment to ensure alignment with the Entity’s cybersecurity requirements.",
           "key": "CRB:4.2.2.6"
          }
         ]
        },
        {
         "num": "4.2.3",
         "name": "Cybersecurity Risk Treatment and Monitoring",
         "controls": [
          {
           "id": "4.2.3.1",
           "text": "Regulated Entities shall ensure that risks documented in the risk register translate into risk treatment plans that correspond to and address the risks identified in the risk register.",
           "key": "CRB:4.2.3.1"
          },
          {
           "id": "4.2.3.2",
           "text": "Risk treatment shall be categorized (e.g., risk acceptance, risk avoidance, risk mitigation, and risk transfer.), tracked, and managed. In case of risk acceptance, avoidance, or transfer, the justification for the chosen treatment shall be documented, approved, and in line with the Regulated Entity’s risk management methodology. The documentation should ensure transparency and clarity for decision-makers, ensuring the reasoning for each treatment decision is formally outlined and established.",
           "key": "CRB:4.2.3.2"
          },
          {
           "id": "4.2.3.3",
           "text": "A risk monitoring process shall be implemented to: a) track compliance with the defined risk treatment plans; b) ensure effectiveness of risk mitigation controls; and c) ensure prioritization, effective management, and monitoring of key risks, based on their potential impact and likelihood.",
           "key": "CRB:4.2.3.3"
          },
          {
           "id": "4.2.3.4",
           "text": "The head of Information Security function shall update the Cybersecurity Steering Committee on a quarterly basis regarding the current status of identified risks, treatment plans, and any changes in the risk profile. Additionally, emergent risks shall be flagged and reported promptly, ensuring that adjustments can be made to the risk treatment plans where necessary.",
           "key": "CRB:4.2.3.4"
          }
         ]
        },
        {
         "num": "4.2.4",
         "name": "Cyber Insurance",
         "controls": [
          {
           "id": "4.2.4.1",
           "text": "Regulated Entities shall document an evaluation of their need for cyber insurance coverage, including rationale for adopting or not adopting such coverage, based on the organizational risk appetite, as a risk transfer mechanism for certain types of cyber risk.",
           "key": "CRB:4.2.4.1"
          },
          {
           "id": "4.2.4.2",
           "text": "Regulated Entities shall ensure in the event of adopting cyber insurance, that any cyber insurance policy adopted provides coverage for a broad range of losses, including, but not limited to, ransomware incidents, cost of data breaches, third-party liabilities.",
           "key": "CRB:4.2.4.2"
          },
          {
           "id": "4.2.4.3",
           "text": "Regulated Entities shall conduct due diligence on chosen cyber insurance policies, to ensure the exclusions and limitations which may impact the insurance payout(s).",
           "key": "CRB:4.2.4.3"
          }
         ]
        },
        {
         "num": "4.2.5",
         "name": "Cybersecurity in Project Management",
         "controls": [
          {
           "id": "4.2.5.1",
           "text": "Cybersecurity requirements shall be incorporated into the Regulated Entities’ project management methodology, to ensure that cybersecurity risks are identified and addressed.",
           "key": "CRB:4.2.5.1"
          },
          {
           "id": "4.2.5.2",
           "text": "The Regulated Entities’ project management methodology shall consider that: a) cybersecurity objectives are included in the project objectives; b) the cybersecurity function is involved at all stages of the project; c) a risk assessment is performed at the onset of the project to identify the cybersecurity risks and to ensure that appropriate cybersecurity requirements are addressed either by existing cybersecurity controls or developed to treat the identified risks; d) cybersecurity risks are documented and tracked in a centralized project risk register; e) responsibilities for cybersecurity are defined and responsible stakeholders are identified; and f) a cybersecurity review is performed by an independent internal party or external third- party.",
           "key": "CRB:4.2.5.2"
          }
         ]
        }
       ]
      },
      {
       "num": "4.3",
       "name": "Compliance",
       "areas": [
        {
         "num": "4.3.1",
         "name": "Regulatory, Statutory, and Standards Compliance",
         "controls": [
          {
           "id": "4.3.1.1",
           "text": "Regulated Entities shall identify, document, and demonstrate compliance to applicable legal, regulatory, and compliance requirements, such as: a) CBK requirements, instructions, laws, and regulations, including -but not limited to-: i. CBK Law 32; ii. Law 20/2014, E-Transaction Law; iii. CCTV Law No 61/2015; iv. E-Crime Law No 60/2015; v. Instructions for Regulation of the Electronic payment of Funds; vi. Instructions of Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT); vii. Open Banking (OB) Framework; and viii. Cyber and Operational Resilience Framework for all Local Banks and Financial Institutions; and ix. Other relevant requirements, instructions, regulations issued by CBK. b) Communication and Information Technology Regulatory Authority (CITRA) laws and regulations; and c) National Cybersecurity Center (NCSC) Decisions.",
           "key": "CRB:4.3.1.1"
          },
          {
           "id": "4.3.1.2",
           "text": "Regulated Entities shall comply with latest version of the applicable best practices and standards such as: a) Payment Cards Industry Data Security Standard (PCI DSS); b) PCI PIN Transaction Security (PCI PTS); c) PCI Software Security Framework (PCI SSF) d) EMV (Europay, MasterCard, and VISA) Technical Standard; e) SWIFT Customer Security Program (SWIFT CSP); and f) International Organization of Standardization (e.g., ISO 27001, ISO 22301, ISO 31000).",
           "key": "CRB:4.3.1.2"
          },
          {
           "id": "4.3.1.3",
           "text": "Regulated Entities shall obtain and maintain certifications for ISO 27001, ISO 22301 and PCI DSS, complete the attestation for SWIFT Customer Security Controls Framework (SWIFT CSCF), and shall provide attestation of compliance to CBK upon request or at regular intervals in line with the specific requirements of the relevant standards.",
           "key": "CRB:4.3.1.3"
          },
          {
           "id": "4.3.1.4",
           "text": "Regulated Entities shall maintain a compliance register documenting all applicable compliance requirements. Any changes to these requirements shall be identified, assessed, implemented, and appropriately reflected in the register, which shall be reviewed and updated regularly, at least annually.",
           "key": "CRB:4.3.1.4"
          }
         ]
        }
       ]
      },
      {
       "num": "4.4",
       "name": "Independent Audit",
       "areas": [
        {
         "num": "4.4.1",
         "name": "Audit Function of Regulated Entity",
         "controls": [
          {
           "id": "4.4.1.1",
           "text": "The audit function shall ensure that independent audits are conducted to evaluate the implementation and effectiveness of the Information Security Management System and cybersecurity controls.",
           "key": "CRB:4.4.1.1"
          }
         ]
        },
        {
         "num": "4.4.2",
         "name": "Audit Planning and Execution",
         "controls": [
          {
           "id": "4.4.2.1",
           "text": "An audit charter, based on generally accepted auditing standards and the cyber and operational resilience framework, shall be defined, approved, implemented, and reviewed annually. The audit charter shall specify the purpose, mandate, responsibility, and accountability of management with respect to the audit.",
           "key": "CRB:4.4.2.1"
          },
          {
           "id": "4.4.2.2",
           "text": "An audit plan shall be defined and approved by the Board.",
           "key": "CRB:4.4.2.2"
          },
          {
           "id": "4.4.2.3",
           "text": "Regulated Entities shall ensure that risk areas, defined in this framework, are audited on regular basis, using a risk-based approach to classify risk areas as per internal business requirements and defined methodologies. The classification of risk areas may consider the criticality of assets, the likelihood of threat occurrence, and the potential impact of a compromise or failure: a) high-risk areas involve critical assets or processes, face frequent or significant threats, and/or would result in severe consequences if compromised. These areas shall be audited at least annually; and b) medium- and low-risk areas may have lower criticality, fewer threats, and/or less severe impact. These areas shall be audited at least once in two years.",
           "key": "CRB:4.4.2.3"
          }
         ]
        },
        {
         "num": "4.4.3",
         "name": "Independent Third-Party Audits",
         "controls": [
          {
           "id": "4.4.3.1",
           "text": "Cybersecurity audits to assess compliance against the CBK CORF shall be performed by independent and competent third-party auditor approved by CBK.",
           "key": "CRB:4.4.3.1"
          },
          {
           "id": "4.4.3.2",
           "text": "The third-party auditors shall: a) possess relevant certifications such as Certified Information Systems Auditor (CISA), ISO 27001 Lead Auditor, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or equivalent qualifications; and b) have a minimum of five (5) years of experience auditing information security, cyber security, cyber resilience, and/or business continuity in banking and financial institutions (at least one (1) team member of the audit team). The third-parties entrusted to perform independent audits shall be changed at least once every two years.",
           "key": "CRB:4.4.3.2"
          }
         ]
        },
        {
         "num": "4.4.4",
         "name": "Independent Audit Reporting",
         "controls": [
          {
           "id": "4.4.4.1",
           "text": "The Board shall be provided with periodic feedback regarding the comprehensiveness and effectiveness of the cyber resilience policy and its implementation. Audit findings, with focus on high-risk areas and corrective actions, shall be reported quarterly.",
           "key": "CRB:4.4.4.1"
          },
          {
           "id": "4.4.4.2",
           "text": "Regulated Entities shall track and monitor independent audit findings and publish an assessment and compliance dashboard to the Board on a quarterly basis.",
           "key": "CRB:4.4.4.2"
          }
         ]
        }
       ]
      },
      {
       "num": "4.5",
       "name": "Workforce Management",
       "areas": [
        {
         "num": "4.5.1",
         "name": "Personnel Security",
         "controls": [
          {
           "id": "4.5.1.1",
           "text": "Perform sufficient background screenings in line with relevant laws, regulations, and organizational requirements prior to onboarding/hiring employees.",
           "key": "CRB:4.5.1.1"
          },
          {
           "id": "4.5.1.2",
           "text": "Ensure that appropriate confidentiality or Non-Disclosure Agreements (NDAs) are signed by the employees, contractors, and third-party vendors before onboarding or engaging in any activities for the Entity.",
           "key": "CRB:4.5.1.2"
          },
          {
           "id": "4.5.1.3",
           "text": "Ensure that all employees, contractors, and third-party vendors formally acknowledge their commitment to adhere to information security policies, procedures, and guidelines.",
           "key": "CRB:4.5.1.3"
          },
          {
           "id": "4.5.1.4",
           "text": "Ensure a formal disciplinary process is defined, documented, and implemented to cover violations of code of conduct and/or internal policies and standards.",
           "key": "CRB:4.5.1.4"
          },
          {
           "id": "4.5.1.5",
           "text": "Ensure that upon termination, all technology and data assets allocated to employees, contractors, and third-party vendors are returned, and all granted access privileges are promptly revoked.",
           "key": "CRB:4.5.1.5"
          }
         ]
        },
        {
         "num": "4.5.2",
         "name": "Training and Awareness",
         "controls": [
          {
           "id": "4.5.2.1",
           "text": "A security awareness and training program shall be established for all employees, contractors, and relevant third-party vendor staff.",
           "key": "CRB:4.5.2.1"
          },
          {
           "id": "4.5.2.2",
           "text": "The security awareness and training program shall be conducted upon hire and at least annually, covering topics such as information security policies, information security roles and responsibilities, relevant procedures, latest cybersecurity threats in the banking and financial sector.",
           "key": "CRB:4.5.2.2"
          },
          {
           "id": "4.5.2.3",
           "text": "Customized role-based security trainings shall be conducted at least annually, ensuring relevance to specific job functions and responsibilities.",
           "key": "CRB:4.5.2.3"
          },
          {
           "id": "4.5.2.4",
           "text": "Specialized awareness programs for the Board and Executive/ Senior Management shall be delivered at least annually, to ensure they understand their roles in developing a cybersecurity culture.",
           "key": "CRB:4.5.2.4"
          },
          {
           "id": "4.5.2.5",
           "text": "All employees, contractors, and relevant third-party staff shall formally acknowledge their awareness, understanding, and compliance with cybersecurity policies, at least annually.",
           "key": "CRB:4.5.2.5"
          },
          {
           "id": "4.5.2.6",
           "text": "Regulated Entities shall conduct customer security awareness campaigns, at least quarterly, addressing potential cybersecurity threats and risks, including phishing, brand misuse, and fraud, and promote practices for safe and secure use of financial services. These campaigns shall be delivered through multiple effective communication channels, such as social media platforms, in-app messages, SMS, emails, and other effective channels.",
           "key": "CRB:4.5.2.6"
          },
          {
           "id": "4.5.2.7",
           "text": "Customers shall be encouraged to report phishing emails or phishing websites or unusual behavior observed through appropriate channels identified by the Regulated Entity.",
           "key": "CRB:4.5.2.7"
          },
          {
           "id": "4.5.2.8",
           "text": "Regulated Entities shall assess and monitor the effectiveness of the security awareness and training programs through knowledge assessments and simulated social engineering attacks (e.g., mock phishing attacks/phishing simulations).",
           "key": "CRB:4.5.2.8"
          },
          {
           "id": "4.5.2.9",
           "text": "Regulated Entities shall retain relevant documented information as evidence of all conducted security awareness and training programs, including attendance records and assessment results.",
           "key": "CRB:4.5.2.9"
          },
          {
           "id": "4.5.2.10",
           "text": "Regulated Entities shall continuously review the content of the security awareness and training programs, incorporating feedback from participants and adjustments based on the evolving threat landscape.",
           "key": "CRB:4.5.2.10"
          }
         ]
        },
        {
         "num": "4.5.3",
         "name": "Talent Management",
         "controls": [
          {
           "id": "4.5.3.1",
           "text": "A comprehensive professional cyber training and certification plan shall be defined, approved, implemented, and reviewed annually. This plan shall identify the professional certifications and training courses that staff employed by Regulated Entities shall pursue in order to continuously develop their cyber skills and capabilities.",
           "key": "CRB:4.5.3.1"
          },
          {
           "id": "4.5.3.2",
           "text": "Regulated Entities shall provide specialist skills-related training for staff in the relevant business functions in line with their job descriptions, such as: a) key/critical roles within the organization; b) information security, cyber security, cyber resilience, cyber security operations, cyber risk management, and internal audit staff; c) staff involved in developing and maintaining information/technology assets; and d) staff involved in executing risk assessments.",
           "key": "CRB:4.5.3.2"
          },
          {
           "id": "4.5.3.3",
           "text": "Regulated Entities shall conduct systematic workforce planning to identify and document current and future cybersecurity staffing needs, skill gaps, and resource allocation to meet organizational goals.",
           "key": "CRB:4.5.3.3"
          },
          {
           "id": "4.5.3.4",
           "text": "Regulated Entities shall define clear career pathways for information security, cyber security, cyber resilience, cyber operations, cyber risk management, and internal audit roles, including role progression, leadership development opportunities, and mentorship initiatives, to encourage retention and professional growth.",
           "key": "CRB:4.5.3.4"
          },
          {
           "id": "4.5.3.5",
           "text": "Regulated Entities shall implement retention strategies, such as competitive compensation, flexible working arrangements, career advancement opportunities, and employee recognition programs, to maintain skilled workforce.",
           "key": "CRB:4.5.3.5"
          },
          {
           "id": "4.5.3.6",
           "text": "Cross-training and rotational assignments shall be implemented to broaden staff expertise and ensure workforce resilience.",
           "key": "CRB:4.5.3.6"
          },
          {
           "id": "4.5.3.7",
           "text": "Contingency plans for critical roles pertaining to the implementation and monitoring of this framework shall be developed, including knowledge transfer mechanisms and backup personnel for continuity.",
           "key": "CRB:4.5.3.7"
          },
          {
           "id": "4.5.3.8",
           "text": "Metrics shall be established and monitored to assess the effectiveness of talent management programs, including training completion rates, certifications achieved, employee satisfaction scores, and retention statistics. These metrics shall be reported on quarterly basis to Executive/Senior Management to ensure continuous improvement.",
           "key": "CRB:4.5.3.8"
          },
          {
           "id": "4.5.3.9",
           "text": "A comprehensive annual review of talent management programs shall be conducted, including trend analysis, workforce planning recommendations, and evaluation of program effectiveness. The outcomes of this review and recommendations shall be presented to the Board for strategic oversight and to better refine workforce strategies.",
           "key": "CRB:4.5.3.9"
          },
          {
           "id": "4.5.3.10",
           "text": "Regulated Entities shall foster a culture of continuous learning and innovation by providing access to learning platforms, industry conferences, and knowledge-sharing forums to ensure cybersecurity staff remain up-to-date on the evolution of the field of cyber security, cyber resilience, threat landscape, technologies, etc.",
           "key": "CRB:4.5.3.10"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 2,
     "section": "5",
     "name": "Technology and Operations",
     "subdomains": [
      {
       "num": "5.1",
       "name": "Security Architecture Design",
       "areas": [
        {
         "num": "5.1.1",
         "name": "Formalization and Governance",
         "controls": [
          {
           "id": "5.1.1.1",
           "text": "Security architecture design shall be defined, approved by relevant stakeholders (such as IT, Information Security, Risk Management, and relevant Business Units) and implemented.",
           "key": "CRB:5.1.1.1"
          },
          {
           "id": "5.1.1.2",
           "text": "Reviews of the security architecture design shall be performed at least annually, and whenever changes to the environment or business requirements arise considering inputs from IT and information security functions, threat intelligence, incident lessons, and vulnerability assessments.",
           "key": "CRB:5.1.1.2"
          }
         ]
        },
        {
         "num": "5.1.2",
         "name": "Security Architecture Core Principles",
         "controls": [
          {
           "id": "5.1.2.1",
           "text": "The security architecture shall protect the confidentiality, integrity and availability of Regulated Entities information and be designed to: a) avoid disruption to service and maintain operational continuity; b) minimize attack surface to reduce exposure to potential threats; c) implement zero-trust principles, to limit implicit trust between systems and users; and d) reduce the impact of cybersecurity incidents on the Entity, by enabling effective detection of the adversaries, timely identification of threats, and proactive incident response mechanisms.",
           "key": "CRB:5.1.2.1"
          }
         ]
        },
        {
         "num": "5.1.3",
         "name": "Security-by-Design Considerations",
         "controls": [
          {
           "id": "5.1.3.1",
           "text": "The security architecture across all environments (e.g., on-premises, cloud, hybrid environments, etc.) shall be based on ‘zero-trust’ and 'secure-by-design' principles, and consider: a) assuming no implicit trust and verifying all actions based on the identity, context, and identified / associated risk; b) applying continuous verification of user identity and access, through evaluating user behavior, access patterns and other associated attributes across a variety of environments, e.g., federated cloud environments, on-premises networks, etc.; c) micro-segregation of networks (e.g., trusted, untrusted, wired, wireless, production, test, payment systems, general IT systems, web, app, DB, administration etc.,) based on criticality, access and integration requirements; d) protection of sensitive data at rest, in use and in transit from unauthorized disclosure, alteration, malicious attacks; e) principles of multi-layer defense in depth security, least privilege and segregation of duties to ensure users only have access to needed resources; f) logging, monitoring, and reporting requirements to establish continuous verification; g) limiting internet access from users, systems and devices unless there is a valid business justification / need; h) business continuity and disaster recovery arrangements; and i) specific security considerations which are relevant and important to meet business objectives.",
           "key": "CRB:5.1.3.1"
          }
         ]
        }
       ]
      },
      {
       "num": "5.2",
       "name": "Asset Management",
       "areas": [
        {
         "num": "5.2.1",
         "name": "Asset Management Governance",
         "controls": [
          {
           "id": "5.2.1.1",
           "text": "Asset management and classification process shall be defined, approved, implemented, monitored, periodically reviewed and updated -at least annually- to secure assets throughout their lifecycle.",
           "key": "CRB:5.2.1.1"
          },
          {
           "id": "5.2.1.2",
           "text": "Reviews shall also be triggered whenever there are changes in the business, technology landscape, regulations, or asset inventory.",
           "key": "CRB:5.2.1.2"
          },
          {
           "id": "5.2.1.3",
           "text": "The process shall define the roles of Asset Owner, Custodian, and intended users. It shall include controls for identification, protection, and monitoring of information assets.",
           "key": "CRB:5.2.1.3"
          },
          {
           "id": "5.2.1.4",
           "text": "All assets shall have a designated Business Owner (Asset/Information Owner) responsible for creating and maintaining the inventory.",
           "key": "CRB:5.2.1.4"
          },
          {
           "id": "5.2.1.5",
           "text": "Each IT asset shall have a designated System Owner, acting as the Data Custodian, responsible for maintaining and supporting the assets under their responsibility.",
           "key": "CRB:5.2.1.5"
          }
         ]
        },
        {
         "num": "5.2.2",
         "name": "Assets Identification",
         "controls": [
          {
           "id": "5.2.2.1",
           "text": "All information and IT assets shall be identified, documented, and maintained in a comprehensive asset inventory list that includes a complete record of all assets, including those owned or leased, located at third-party sites, or operating on the Entity’s premises.",
           "key": "CRB:5.2.2.1"
          },
          {
           "id": "5.2.2.2",
           "text": "The asset inventory list shall contain, at a minimum, the asset name, description, owner, custodian, classification, and End-of-life/end-of-support information.",
           "key": "CRB:5.2.2.2"
          },
          {
           "id": "5.2.2.3",
           "text": "Endpoints (e.g., PCs, laptops) shall be included in the asset inventory list, but their classification and criticality shall be determined and managed dynamically based on the user activities and data they handle.",
           "key": "CRB:5.2.2.3"
          },
          {
           "id": "5.2.2.4",
           "text": "The inventory shall track key lifecycle events, such as acquisition, movement, modification, and decommissioning to maintain inventory accuracy.",
           "key": "CRB:5.2.2.4"
          },
          {
           "id": "5.2.2.5",
           "text": "The asset inventory list shall be reviewed and updated at least quarterly, or as needed following a business, technological, or regulatory change, to ensure accuracy and reflect any change in a timely manner.",
           "key": "CRB:5.2.2.5"
          },
          {
           "id": "5.2.2.6",
           "text": "Regulated Entities shall identify business functions, supporting information assets, and processes and conduct risk assessment to understand their value and importance to organization.",
           "key": "CRB:5.2.2.6"
          }
         ]
        },
        {
         "num": "5.2.3",
         "name": "Assets Classification, Labelling, and Handling",
         "controls": [
          {
           "id": "5.2.3.1",
           "text": "Assets shall be classified using a risk-based approach in accordance with their value, importance, criticality, and legal or regulatory requirements.",
           "key": "CRB:5.2.3.1"
          },
          {
           "id": "5.2.3.2",
           "text": "Information asset labeling and handling guidelines shall be defined for each asset classification level. These guidelines shall be reviewed and updated at least annually to reflect any changes in classification regulations.",
           "key": "CRB:5.2.3.2"
          },
          {
           "id": "5.2.3.3",
           "text": "All information assets shall be labelled as per the labeling guidelines.",
           "key": "CRB:5.2.3.3"
          }
         ]
        },
        {
         "num": "5.2.4",
         "name": "Acquisition, Acceptable Use, and Disposal of Assets",
         "controls": [
          {
           "id": "5.2.4.1",
           "text": "The acquisition of information assets shall be consistent with the Regulated Entity's procurement process, licensing agreements, and shall comply with the security architecture and policies.",
           "key": "CRB:5.2.4.1"
          },
          {
           "id": "5.2.4.2",
           "text": "A policy for acceptable use of information assets shall be defined, approved, implemented, and reviewed annually. Reviews shall incorporate any business, regulatory, or technological changes.",
           "key": "CRB:5.2.4.2"
          },
          {
           "id": "5.2.4.3",
           "text": "All assets shall be securely disposed when no longer required, in accordance with relevant regulations, industry requirements and standards, contractual agreements, and internal policies of the Regulated Entities.",
           "key": "CRB:5.2.4.3"
          },
          {
           "id": "5.2.4.4",
           "text": "Procedures for the sanitization and destruction of information assets shall be defined, approved, implemented, and reviewed on an annual basis. This shall be in line with information classification and security requirements.",
           "key": "CRB:5.2.4.4"
          },
          {
           "id": "5.2.4.5",
           "text": "Disposal of sensitive information residing on information assets shall be executed by appropriate techniques that render the information to be non-retrievable (e.g. secure erase, secure wiping, double crosscut, shredding, crypto-shredding, etc.).",
           "key": "CRB:5.2.4.5"
          },
          {
           "id": "5.2.4.6",
           "text": "Disposal activities shall be documented for compliance and audit purposes.",
           "key": "CRB:5.2.4.6"
          }
         ]
        },
        {
         "num": "5.2.5",
         "name": "Detection and Monitoring of Unauthorized Assets",
         "controls": [
          {
           "id": "5.2.5.1",
           "text": "A process shall be defined and implemented to detect, prevent, and manage the use of unauthorized, unmanaged or rogue assets. The process shall be reviewed annually and incorporate enhancements based on monitoring results and emerging risks.",
           "key": "CRB:5.2.5.1"
          },
          {
           "id": "5.2.5.2",
           "text": "Monitoring tools and processes shall be utilized to identify unapproved devices or assets connected to the organization’s environment.",
           "key": "CRB:5.2.5.2"
          }
         ]
        }
       ]
      },
      {
       "num": "5.3",
       "name": "Infrastructure and Network Security",
       "areas": [
        {
         "num": "5.3.1",
         "name": "Security Configuration Standards",
         "controls": [
          {
           "id": "5.3.1.1",
           "text": "Security configuration standards shall be defined, approved, implemented, monitored, and reviewed and updated at least annually to ensure they remain effective, relevant, and aligned with evolving threats, covering all technology assets used within the enterprise.",
           "key": "CRB:5.3.1.1"
          },
          {
           "id": "5.3.1.2",
           "text": "Security configuration standards shall be based on global best practices (such as NIST, Center for Internet Security (CIS) benchmarks), Guidelines issued by Original Equipment Manufacturers (OEMs), and internal policies and best practices of the Regulated Entity.",
           "key": "CRB:5.3.1.2"
          },
          {
           "id": "5.3.1.3",
           "text": "Security configuration standards shall, at a minimum, include the following: a) installing only approved and supported version of software; b) installing minimum components or services necessary to meet the requirements; c) applying up-to-date security updates, including firmware patches for hardware devices; d) protecting data in line with asset management and information classification requirements; e) disabling or restricting access to weak or unnecessary services and ports; f) changing default passwords, and removing or disabling unneeded accounts; g) configuring access control based on need-to-know and need-to-have principles; h) removing local administrator privileges from end-users devices; i) disabling weak or insecure protocols and algorithms and ensuring that only latest and industry-supported algorithms are used; j) setting security measures to lock or terminate sessions (e.g., logout, logoff, close the application page, or application timeout) after a predefined period of inactivity and conditions; k) proactive measures to protect against malicious software, ransomware, data loss, Denial-of-Service (DoS) attacks, advanced threats etc.; l) synchronizing system clocks with central-clock; and m) enabling logging and monitoring.",
           "key": "CRB:5.3.1.3"
          },
          {
           "id": "5.3.1.4",
           "text": "Quarterly periodic checks shall be conducted to ensure compliance against security configuration standards, ensuring continuous monitoring.",
           "key": "CRB:5.3.1.4"
          },
          {
           "id": "5.3.1.5",
           "text": "New technology deployments shall be configured as per configuration standards, and testing shall be performed prior to go live to confirm the compliance.",
           "key": "CRB:5.3.1.5"
          }
         ]
        },
        {
         "num": "5.3.2",
         "name": "Network Security",
         "controls": [
          {
           "id": "5.3.2.1",
           "text": "The network architecture shall be documented, approved, implemented, periodically reviewed at least annually, even if no changes occur, and updated whenever there are significant changes to the architecture take place, such as major deployments or upgrades.",
           "key": "CRB:5.3.2.1"
          },
          {
           "id": "5.3.2.2",
           "text": "Networks shall be protected through appropriate configuration and implementation of security solutions (e.g. router, firewall, Intrusion Prevention System (IPS), Intrusion Detection System (IDS), proxy, Advanced Persistent Threat (APT) protections, email/Internet filtering, Virtual Private Networks (VPNs) etc.) to protect against and detect cyber threats.",
           "key": "CRB:5.3.2.2"
          },
          {
           "id": "5.3.2.3",
           "text": "The network shall be segregated into production, testing, and development zones with distinct established network security policies for each zone, based on its criticality, purpose, and risk exposure.",
           "key": "CRB:5.3.2.3"
          },
          {
           "id": "5.3.2.4",
           "text": "DMZs shall be implemented to host publicly accessible services, limiting inbound traffic to specific IPs, protocols, and ports.",
           "key": "CRB:5.3.2.4"
          },
          {
           "id": "5.3.2.5",
           "text": "All external connections to enterprise’s internal network shall be authenticated and encrypted.",
           "key": "CRB:5.3.2.5"
          },
          {
           "id": "5.3.2.6",
           "text": "Logging of network devices shall be enabled to capture changes made to network configurations and security events.",
           "key": "CRB:5.3.2.6"
          },
          {
           "id": "5.3.2.7",
           "text": "All wireless access points or base stations that are connected to the enterprise network shall be registered, approved, and securely configured.",
           "key": "CRB:5.3.2.7"
          },
          {
           "id": "5.3.2.8",
           "text": "Network shall be continuously monitored to detect unauthorized or rogue devices connected to the network. Any such devices shall be immediately isolated or deactivated upon detection.",
           "key": "CRB:5.3.2.8"
          }
         ]
        },
        {
         "num": "5.3.3",
         "name": "Network Connections and Application Interfaces",
         "controls": [
          {
           "id": "5.3.3.1",
           "text": "Security standards for network connections and application interfaces shall be defined, approved, implemented, reviewed at least annually, and updated.",
           "key": "CRB:5.3.3.1"
          },
          {
           "id": "5.3.3.2",
           "text": "Network connections, application interfaces, and data flows shall be documented and maintained for internal and external connections to the enterprise network, whether on- premises or on the cloud.",
           "key": "CRB:5.3.3.2"
          },
          {
           "id": "5.3.3.3",
           "text": "The security configuration standards shall include requirements related to network encryption, authentication, session management, session time-outs, access governance, data security, etc.",
           "key": "CRB:5.3.3.3"
          },
          {
           "id": "5.3.3.4",
           "text": "The network connections and application interfaces shall be tested on an annual basis or following a significant change, to ensure compliance with security configuration standards periodically.",
           "key": "CRB:5.3.3.4"
          }
         ]
        }
       ]
      },
      {
       "num": "5.4",
       "name": "Endpoint and Device Security",
       "areas": [
        {
         "num": "5.4.1",
         "name": "Portable Device Security",
         "controls": [
          {
           "id": "5.4.1.1",
           "text": "A policy for portable device security shall be defined, approved, implemented, monitored, and reviewed periodically on annual basis, and updated.",
           "key": "CRB:5.4.1.1"
          },
          {
           "id": "5.4.1.2",
           "text": "Portable devices shall be permitted to connect to the enterprise network only after necessary authorization and security validation.",
           "key": "CRB:5.4.1.2"
          },
          {
           "id": "5.4.1.3",
           "text": "Regulated Entities portable device policy shall include Acceptable Use Policy (AUP) to define rules for personal and work-related use.",
           "key": "CRB:5.4.1.3"
          },
          {
           "id": "5.4.1.4",
           "text": "Security configuration standards shall be implemented on the portable device prior to allotting them to users and / or allowing them to connect to the enterprise network.",
           "key": "CRB:5.4.1.4"
          },
          {
           "id": "5.4.1.5",
           "text": "All portable devices shall be tagged and assigned to a unique employee, contractor, or third- party vendor staff, and their identity shall be logged and tracked in a centralized inventory.",
           "key": "CRB:5.4.1.5"
          },
          {
           "id": "5.4.1.6",
           "text": "All portable devices that are connected to the enterprise network shall be continuously monitored, to detect unauthorized access or malicious behavior.",
           "key": "CRB:5.4.1.6"
          },
          {
           "id": "5.4.1.7",
           "text": "Lost, rooted, and jailbroken devices shall be blocked from accessing enterprise resources.",
           "key": "CRB:5.4.1.7"
          },
          {
           "id": "5.4.1.8",
           "text": "For devices owned by the Regulated Entity, the portable computing devices of terminated or departing employees, contractor, or third-party vendor staff shall be returned, and all data residing on these devices shall be securely erased or backed up as necessary.",
           "key": "CRB:5.4.1.8"
          },
          {
           "id": "5.4.1.9",
           "text": "For devices owned by the employee (i.e., BYOD), the data of the Regulated Entity residing on these portable computing devices shall be securely backed up and stored in the Entity’s systems or secure repositories, and subsequently removed from the employee’s device, when no longer required (e.g., upon termination of employment or when storage on the employee’s device is no longer necessary).",
           "key": "CRB:5.4.1.9"
          },
          {
           "id": "5.4.1.10",
           "text": "When devices are provisioned or re-provisioned to new users, the security configuration standards shall be re-installed before handover to the users.",
           "key": "CRB:5.4.1.10"
          },
          {
           "id": "5.4.1.11",
           "text": "Regulated Entities shall secure important records stored on portable devices by ensuring that: a) installed applications are pre-approved by the Regulated Entity; b) only authorized software are installed; and c) endpoint encryption or containerization is implemented for data protection.",
           "key": "CRB:5.4.1.11"
          },
          {
           "id": "5.4.1.12",
           "text": "Regulated Entities shall set a maximum number of devices to be connected to entities network per employee based on business need, to control access and manage risks.",
           "key": "CRB:5.4.1.12"
          },
          {
           "id": "5.4.1.13",
           "text": "All portable devices connected to the enterprise network shall support full disk encryption (e.g., BitLocker for Windows and FileVault for macOS) and pre-boot authentication to prevent unauthorized access.",
           "key": "CRB:5.4.1.13"
          },
          {
           "id": "5.4.1.14",
           "text": "Portable devices shall support remote wipe functionality to allow secure data erasure in case of loss or theft.",
           "key": "CRB:5.4.1.14"
          },
          {
           "id": "5.4.1.15",
           "text": "Portable devices shall be configured with automatic lock and inactivity timeouts after predefined period to prevent unauthorized access.",
           "key": "CRB:5.4.1.15"
          },
          {
           "id": "5.4.1.16",
           "text": "A centralized Mobile Device Management (MDM) platform shall be deployed to monitor and track the usage, configurations, and compliance of all mobile devices connected to the Enterprise network.",
           "key": "CRB:5.4.1.16"
          },
          {
           "id": "5.4.1.17",
           "text": "For employee-owned devices, the Regulated Entity shall implement security controls, including Mobile Device Management (MDM) tools, to enforce policies and prevent data leakage. Corporate data shall be isolated from personal data using containerization or other secure means.",
           "key": "CRB:5.4.1.17"
          },
          {
           "id": "5.4.1.18",
           "text": "Endpoint protection tools (e.g., anti-virus and anti-malware), shall be installed on all portable devices to detect and prevent malicious software.",
           "key": "CRB:5.4.1.18"
          },
          {
           "id": "5.4.1.19",
           "text": "Personal firewalls shall be deployed on all end-user platforms (e.g., Windows, macOS, and mobile devices), with rules aligned with the Entity’s network and data protection policies.",
           "key": "CRB:5.4.1.19"
          }
         ]
        },
        {
         "num": "5.4.2",
         "name": "Removable Media",
         "controls": [
          {
           "id": "5.4.2.1",
           "text": "Procedures shall be implemented to manage removable media in accordance with the information asset classification scheme.",
           "key": "CRB:5.4.2.1"
          },
          {
           "id": "5.4.2.2",
           "text": "By default, usage of removable media shall be blocked, unless a strong business justification is in place and proper approvals for such usage is obtained from Information Security function. All granted exceptions shall be logged and monitored.",
           "key": "CRB:5.4.2.2"
          },
          {
           "id": "5.4.2.3",
           "text": "Removable media shall be securely wiped/sanitized after usage to ensure data is unrecoverable.",
           "key": "CRB:5.4.2.3"
          },
          {
           "id": "5.4.2.4",
           "text": "Removable media shall be inspected in an isolated environment and scanned against malware prior to processing any of its content in the Entity’s environment.",
           "key": "CRB:5.4.2.4"
          },
          {
           "id": "5.4.2.5",
           "text": "Media containing sensitive information shall be protected during transportation to prevent unauthorized access, tampering, misuse, or corruption.",
           "key": "CRB:5.4.2.5"
          },
          {
           "id": "5.4.2.6",
           "text": "Backup media and removable media storing classified data shall be encrypted and handled properly as per the defined asset handling guidelines.",
           "key": "CRB:5.4.2.6"
          },
          {
           "id": "5.4.2.7",
           "text": "Removable media that is no longer needed shall be securely disposed and destructed following the Regulated Entity’s relevant policies and procedures.",
           "key": "CRB:5.4.2.7"
          }
         ]
        }
       ]
      },
      {
       "num": "5.5",
       "name": "Email Security",
       "areas": [
        {
         "num": "5.5.1",
         "name": "Email Usage",
         "controls": [
          {
           "id": "5.5.1.1",
           "text": "Email usage guidelines shall be documented, approved, implemented, and reviewed at least annually. The guidelines shall include: a) granting email access in accordance with access management policy and procedures; b) safe practices for sending/ receiving emails; c) acceptable use of emails and email system; d) handling attachments, links within email, spam email etc.; e) protection, detection, and monitoring of content circulated in emails; and f) email data retention in accordance with data protection and privacy policy and procedures.",
           "key": "CRB:5.5.1.1"
          },
          {
           "id": "5.5.1.2",
           "text": "Controls to protect and secure email and messaging systems from security risks (such as spam, malicious links/ attachments, email phishing) shall be implemented.",
           "key": "CRB:5.5.1.2"
          },
          {
           "id": "5.5.1.3",
           "text": "Employees, contractors, and third-party vendor staff shall use email communication in adherence to data privacy and data security requirements of the regulated entity.",
           "key": "CRB:5.5.1.3"
          }
         ]
        },
        {
         "num": "5.5.2",
         "name": "Email Security and Risk Mitigation",
         "controls": [
          {
           "id": "5.5.2.1",
           "text": "Appropriate security measures (such as digital signatures and encryption) shall be implemented to protect the confidentiality and integrity of information being communicated through emails.",
           "key": "CRB:5.5.2.1"
          },
          {
           "id": "5.5.2.2",
           "text": "Email filtering and anti-phishing tools shall be deployed to detect and prevent malicious emails.",
           "key": "CRB:5.5.2.2"
          },
          {
           "id": "5.5.2.3",
           "text": "Mechanisms to authenticate email communications and ensure their integrity, reducing phishing risks and preventing email spoofing shall be implemented (e.g., Domain-based Message Authentication, Reporting, and Conformance (DMARC), Sender Policy Framework (SPF), and DomainKeys Identified Mail (DKIM),etc.)",
           "key": "CRB:5.5.2.3"
          },
          {
           "id": "5.5.2.4",
           "text": "Regulated Entities shall implement solutions to monitor, detect, and prevent unauthorized transmission of sensitive data through emails, such as Data Loss Prevention (DLP) solutions.",
           "key": "CRB:5.5.2.4"
          }
         ]
        }
       ]
      },
      {
       "num": "5.6",
       "name": "Identity and Access Management",
       "areas": [
        {
         "num": "5.6.1",
         "name": "Identity and Access Control Management",
         "controls": [
          {
           "id": "5.6.1.1",
           "text": "Access management policy shall be defined, approved, implemented, and reviewed at least annually. The policy shall be based on business and information security requirements and shall leverage the basic cybersecurity principles defined in this document. The policy shall explicitly reflect zero-trust principles, including identity-based access controls, continuous verification, least privilege enforcement, and strong authentication.",
           "key": "CRB:5.6.1.1"
          },
          {
           "id": "5.6.1.2",
           "text": "Access management policy shall, at a minimum, include the following: a) user registration, modification, and revocation for regular and privileged access; b) logging and monitoring of access management activities; c) access review; d) dynamic, context-aware access controls based on real-time and risk-based mechanisms; and e) safe and secure use, management, protection, and disposal of credentials.",
           "key": "CRB:5.6.1.2"
          },
          {
           "id": "5.6.1.3",
           "text": "An authorization process shall be established and a record of all privileges allocated shall be maintained.",
           "key": "CRB:5.6.1.3"
          },
          {
           "id": "5.6.1.4",
           "text": "Access and privileges shall be granted to all users strictly on a need-to-know and least privilege basis in line with the access management policy, and after the authorization process is complete.",
           "key": "CRB:5.6.1.4"
          },
          {
           "id": "5.6.1.5",
           "text": "Privileged access shall be granted and managed through a Just-In-Time (JIT) approach, ensuring that privileged rights are provided only when required and for the minimum necessary duration, after the authorization process is complete.",
           "key": "CRB:5.6.1.5"
          },
          {
           "id": "5.6.1.6",
           "text": "Segregation of duties controls shall be integrated into the user registration, modification and revocation process.",
           "key": "CRB:5.6.1.6"
          },
          {
           "id": "5.6.1.7",
           "text": "Unique IDs shall be assigned to each user, system, service, and application, according to a standard naming convention.",
           "key": "CRB:5.6.1.7"
          },
          {
           "id": "5.6.1.8",
           "text": "Generic or Group IDs shall be permitted based on a review and validation of business or operational reasons, and prior approval shall be necessary for creation and usage of such IDs. These Generic and Group IDs shall be reviewed at least twice a year to ensure necessity and proper use. Ownership and accountability of Group IDs shall be formally determined and defined.",
           "key": "CRB:5.6.1.8"
          },
          {
           "id": "5.6.1.9",
           "text": "Authentication information of users shall be stored and transmitted in a secure manner, leveraging proper cryptographic mechanisms.",
           "key": "CRB:5.6.1.9"
          },
          {
           "id": "5.6.1.10",
           "text": "Strong authentication mechanisms, such as passwordless authentication (e.g., device-based authentication) and biometrics, shall be prioritized for critical systems in alignment with zero- trust principles, with continuous verification of user and device trust levels.",
           "key": "CRB:5.6.1.10"
          },
          {
           "id": "5.6.1.11",
           "text": "Concurrent logins shall be monitored and prevented for critical systems and applications, unless explicitly required for operational continuity or due to vendor-imposed technical limitations from the vendor. Any such exceptions shall be handled following the Exceptions Management policy and procedures of the Regulated Entity.",
           "key": "CRB:5.6.1.11"
          },
          {
           "id": "5.6.1.12",
           "text": "Appropriate audit records of all access management activities and user access shall be logged, monitored, and reviewed at least monthly for privileged access and critical systems, with automated alerts to detect suspicious activities in a timely manner. Broader reviews shall be conducted on quarterly basis for all access logs.",
           "key": "CRB:5.6.1.12"
          },
          {
           "id": "5.6.1.13",
           "text": "Regulated Entities shall conduct access control review at least annually for normal user accounts and quarterly for privileged and third-party vendor accounts, or immediately following any change in personnel, roles, or responsibilities. All inactive accounts and redundant access rights shall be identified and disabled/deleted.",
           "key": "CRB:5.6.1.13"
          },
          {
           "id": "5.6.1.14",
           "text": "Inactive accounts shall be automatically identified after (30) days and disabled after (90) days of inactivity, unless justified and approved through Regulated Entities’s documented processes.",
           "key": "CRB:5.6.1.14"
          },
          {
           "id": "5.6.1.15",
           "text": "Users shall activate a password protected screensaver or logoff the application when leaving workstation unattended.",
           "key": "CRB:5.6.1.15"
          },
          {
           "id": "5.6.1.16",
           "text": "Proper identity security solutions, such as Privileged Access Management (PAM) solutions, shall be implemented to manage, monitor, and control privileged access to systems. The solution shall incorporate real-time monitoring and session management controls, ensuring least privilege and continuous verification.",
           "key": "CRB:5.6.1.16"
          },
          {
           "id": "5.6.1.17",
           "text": "Behavioral analytics tools (e.g., User and Entities Behavior Analytics (UEBA)) shall be employed to monitor user activities for anomalies and trigger automated responses to potential security incidents, such as adaptive access restrictions, escalated authentication requirements, or session timeouts.",
           "key": "CRB:5.6.1.17"
          }
         ]
        },
        {
         "num": "5.6.2",
         "name": "Remote Access Management",
         "controls": [
          {
           "id": "5.6.2.1",
           "text": "The Regulated Entities shall establish, implement, and maintain a remote access policy that defines how remote access is granted, managed, monitored, and secured.",
           "key": "CRB:5.6.2.1"
          },
          {
           "id": "5.6.2.2",
           "text": "All remote access granted to users shall be subject to validation of business or operational reasons, approved by relevant stakeholders after due risk assessment, and limited to a defined time period. Zero trust principles shall be applied while granting remote access.",
           "key": "CRB:5.6.2.2"
          },
          {
           "id": "5.6.2.3",
           "text": "Multi-factor authentication shall be implemented for all remote access users, including contractors and third-party vendors. Additional verification steps (e.g., re-authentication, step-up authentication) shall be required as risk-based access controls, based on dynamic parameters (e.g., the user’s location, device health, and unusual behavior), to continuously verify access.",
           "key": "CRB:5.6.2.3"
          },
          {
           "id": "5.6.2.4",
           "text": "Context-aware controls (e.g., device details, behavior analysis, geolocation) shall be leveraged to govern access dynamically based on risk.",
           "key": "CRB:5.6.2.4"
          },
          {
           "id": "5.6.2.5",
           "text": "Entity-owned devices shall be prioritized for remote access usage, with zero-trust principles consistently applied to both entity and personal devices (BYOD).",
           "key": "CRB:5.6.2.5"
          },
          {
           "id": "5.6.2.6",
           "text": "Devices used for remote access shall be patched and up-to-date. Unpatched devices shall be quarantined or remediated.",
           "key": "CRB:5.6.2.6"
          },
          {
           "id": "5.6.2.7",
           "text": "Remote sessions by external third-party vendors shall be time-limited based on business needs, recorded, and monitored.",
           "key": "CRB:5.6.2.7"
          },
          {
           "id": "5.6.2.8",
           "text": "All access and activities performed using remote access shall be logged and monitored.",
           "key": "CRB:5.6.2.8"
          },
          {
           "id": "5.6.2.9",
           "text": "Direct remote access to internal production systems shall not be permitted. Access to production environments shall only be allowed through approved mechanisms and controls.",
           "key": "CRB:5.6.2.9"
          },
          {
           "id": "5.6.2.10",
           "text": "All remote access communication and sessions shall be encrypted end-to-end using latest security protocols (e.g., VPN, mTLS).",
           "key": "CRB:5.6.2.10"
          },
          {
           "id": "5.6.2.11",
           "text": "Inactive or idle remote sessions shall be automatically terminated after a defined period. This period shall be determined based on the criticality of the system and exchanged data.",
           "key": "CRB:5.6.2.11"
          }
         ]
        },
        {
         "num": "5.6.3",
         "name": "Password Management",
         "controls": [
          {
           "id": "5.6.3.1",
           "text": "A comprehensive password management policy shall be documented, approved, implemented and reviewed at least annually or following a significant security incident.",
           "key": "CRB:5.6.3.1"
          },
          {
           "id": "5.6.3.2",
           "text": "The password policy shall include requirements for password history, account lockout, maximum password age, minimum password length, prohibited password lists, and include secure log-on procedures.",
           "key": "CRB:5.6.3.2"
          },
          {
           "id": "5.6.3.3",
           "text": "Passwords shall: a) be at least twelve (12) or more characters in length; b) include letters, numbers, and special characters; c) not contain easily guessable information, such as usernames or birth dates; and d) be checked against a database of compromised, weak, or commonly used passwords during creation.",
           "key": "CRB:5.6.3.3"
          },
          {
           "id": "5.6.3.4",
           "text": "Multi-Factor Authentication (MFA), such as One-Time Password (OTP), token-based authentication, certificate-based authentication, or biometric methods (e.g., fingerprint or facial recognition), shall be required for all users. Regulated Entities shall prioritize passwordless authentication mechanisms.",
           "key": "CRB:5.6.3.4"
          },
          {
           "id": "5.6.3.5",
           "text": "All systems default, vendor-supplied, and publicly documented accounts passwords (including service accounts) shall be changed prior to deployment and configured to meet the Entities’ password policy.",
           "key": "CRB:5.6.3.5"
          },
          {
           "id": "5.6.3.6",
           "text": "Passwords shall be communicated and reset in a secure manner to ensure access by the intended user, with default passwords replaced immediately by the user upon first use.",
           "key": "CRB:5.6.3.6"
          },
          {
           "id": "5.6.3.7",
           "text": "Passwords shall be stored securely using cryptographic hashing algorithms (e.g., PBKDF2) with salting.",
           "key": "CRB:5.6.3.7"
          }
         ]
        }
       ]
      },
      {
       "num": "5.7",
       "name": "Cryptography",
       "areas": [
        {
         "num": "5.7.1",
         "name": "Cryptographic Controls and Key Management",
         "controls": [
          {
           "id": "5.7.1.1",
           "text": "A cryptographic policy shall be documented, approved, implemented, reviewed on annual basis, and updated. The policy shall include organization specific principles and acceptable use of cryptographic controls and consider industry standards, best practices, and any legal and regulatory requirements.",
           "key": "CRB:5.7.1.1"
          },
          {
           "id": "5.7.1.2",
           "text": "Procedures shall be established to protect the cryptography technology setup. The procedures shall consider: a) selection and implementation of cryptographic control requirements (e.g., strength, length, method) in accordance with data privacy and protection policies, regulatory obligations, and industry best practices; b) cryptographic key management, such as secure generation, rotation, distribution, storage, archival, retrieval, usage, backup, recovery, destruction, purging of revoked keys etc.; and c) usage of MFA and combination keys / split knowledge / dual control requirement for login into the key store.",
           "key": "CRB:5.7.1.2"
          },
          {
           "id": "5.7.1.3",
           "text": "The key length used for encryption shall be as per the latest globally acceptable industry best practices, and reviewed at least annually for adequacy or whenever vulnerabilities or new recommendations are identified.",
           "key": "CRB:5.7.1.3"
          },
          {
           "id": "5.7.1.4",
           "text": "Regulated Entities shall use appropriate encryption techniques to secure sensitive data within system logs, configuration files, databases, networks, applications, backups, and other information assets as applicable. These techniques shall be applied consistently across on- premises and cloud installations.",
           "key": "CRB:5.7.1.4"
          },
          {
           "id": "5.7.1.5",
           "text": "Key-encrypting keys shall be stored separately from data-encrypting keys, and encrypted data sets shall not share the same storage location as their respective encryption keys.",
           "key": "CRB:5.7.1.5"
          },
          {
           "id": "5.7.1.6",
           "text": "Encryption keys shall be reviewed periodically and rotate when suspected of a compromise to limit the data exposure.",
           "key": "CRB:5.7.1.6"
          }
         ]
        }
       ]
      },
      {
       "num": "5.8",
       "name": "Application Security and Secure SDLC",
       "areas": [
        {
         "num": "5.8.1",
         "name": "Secure Software Development Lifecycle (SDLC)",
         "controls": [
          {
           "id": "5.8.1.1",
           "text": "Secure Software Lifecycle management process shall be defined, approved, implemented, monitored, reviewed annually, and updated.",
           "key": "CRB:5.8.1.1"
          },
          {
           "id": "5.8.1.2",
           "text": "Security and privacy design principles and classification requirements shall be incorporated and taken into consideration while designing new application or outlined in the agreement with the entity supplying Commercial Off-the-Shelf (COTS) applications. All enhancements to the in-house applications or commercial off the shelf applications shall follow the same process.",
           "key": "CRB:5.8.1.2"
          },
          {
           "id": "5.8.1.3",
           "text": "The regulated entity shall ensure that all software, whether developed internally or acquired externally, is accompanied by an up-to-date Software Bill of Materials (SBOM), including those provided by third-party suppliers.",
           "key": "CRB:5.8.1.3"
          },
          {
           "id": "5.8.1.4",
           "text": "Secure design reviews shall be conducted at the architecture and design phases.",
           "key": "CRB:5.8.1.4"
          },
          {
           "id": "5.8.1.5",
           "text": "The information security team shall be involved to ensure that security requirements are addressed during all phases of software lifecycle management (design, development, testing, implementation, maintenance, disposal, etc.).",
           "key": "CRB:5.8.1.5"
          },
          {
           "id": "5.8.1.6",
           "text": "A DevSecOps approach shall be followed to integrate security into the development and operations workflows.",
           "key": "CRB:5.8.1.6"
          },
          {
           "id": "5.8.1.7",
           "text": "Secure coding practices shall be adopted as per organizational requirements and global best practices (e.g., Open Worldwide Application Security Project (OWASP) Secure Coding Practices) to ensure common coding vulnerabilities (e.g. Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses list) are addressed during development and appropriate protective, detective, corrective, and recovery control measures are implemented.",
           "key": "CRB:5.8.1.7"
          },
          {
           "id": "5.8.1.8",
           "text": "Segregation of duties shall be implemented by restricting access to production, testing, and development environments.",
           "key": "CRB:5.8.1.8"
          },
          {
           "id": "5.8.1.9",
           "text": "Access to the program source code for in-house developed applications shall be restricted, monitored, and logged. For COTS applications, access to source code shall be governed by storing the code on-premise or strict contractual terms or escrow arrangements.",
           "key": "CRB:5.8.1.9"
          },
          {
           "id": "5.8.1.10",
           "text": "For critical applications, access to source code shall be managed by: a) storing the code on premises; or b) through an escrow arrangement; or c) strict contractual terms with application/service provider.",
           "key": "CRB:5.8.1.10"
          },
          {
           "id": "5.8.1.11",
           "text": "Version control mechanisms shall be employed to track code changes and ensure integrity.",
           "key": "CRB:5.8.1.11"
          }
         ]
        },
        {
         "num": "5.8.2",
         "name": "Application Security",
         "controls": [
          {
           "id": "5.8.2.1",
           "text": "Either a security assessment certificate or equivalent evidence shall be obtained, or a vulnerability assessment or equivalent testing shall be conducted for COTS products to ensure that the applications are tested and identified vulnerabilities are remediated.",
           "key": "CRB:5.8.2.1"
          },
          {
           "id": "5.8.2.2",
           "text": "All applications, regardless their type, shall undergo comprehensive security assessments, including vulnerability assessments and penetration testing, on periodic basis.",
           "key": "CRB:5.8.2.2"
          },
          {
           "id": "5.8.2.3",
           "text": "Application and/or systems shall display generic error messages by considering, at a minimum, below principles: a) use custom error pages; b) authentication failure responses do not indicate which part of the authentication data was Incorrect; and c) do not disclose or display sensitive information in error responses, including system details, session identifiers, or account information, etc.",
           "key": "CRB:5.8.2.3"
          },
          {
           "id": "5.8.2.4",
           "text": "Error logs shall be reviewed daily for critical systems and at least monthly for other systems to detect any abnormal behavior and potential attacks.",
           "key": "CRB:5.8.2.4"
          }
         ]
        },
        {
         "num": "5.8.3",
         "name": "Application Programming Interface (API) Security",
         "controls": [
          {
           "id": "5.8.3.1",
           "text": "APIs shall be designed and developed following secure coding practices (e.g., OWASP API Security Top 10) to prevent vulnerabilities such as broken authentication, data exposure, and lack of rate limiting. Furthermore, disable unused HTTP methods and decommission outdated versions.",
           "key": "CRB:5.8.3.1"
          },
          {
           "id": "5.8.3.2",
           "text": "Regulated Entities shall maintain the inventory of API usage.",
           "key": "CRB:5.8.3.2"
          },
          {
           "id": "5.8.3.3",
           "text": "APIs shall enforce strong authentication mechanisms (e.g., OAuth 2.0, API Keys, mTLS) and implement Role-Based Access Controls (RBAC) to ensure only authorized users and applications can access them.",
           "key": "CRB:5.8.3.3"
          },
          {
           "id": "5.8.3.4",
           "text": "All inputs to APIs shall be validated to prevent injection attacks, and output data shall be properly encoded to mitigate potential risks.",
           "key": "CRB:5.8.3.4"
          },
          {
           "id": "5.8.3.5",
           "text": "Rate limiting and throttling mechanisms shall be implemented to protect APIs against Denial of Service (DoS) attacks and abuse.",
           "key": "CRB:5.8.3.5"
          },
          {
           "id": "5.8.3.6",
           "text": "API traffic shall be encrypted using industry-standard algorithms to ensure the confidentiality and integrity of data in transit.",
           "key": "CRB:5.8.3.6"
          },
          {
           "id": "5.8.3.7",
           "text": "API gateways shall be employed to enforce security policies, manage traffic, and monitor API usage. APIs shall be registered and managed through the gateway to centralize security enforcement.",
           "key": "CRB:5.8.3.7"
          },
          {
           "id": "5.8.3.8",
           "text": "APIs shall undergo security assessments on periodic basis and after major changes, including but not limited to (e.g., functional testing, penetration testing, fuzzing, application security testing (DAST/SAST), runtime testing, and security misconfiguration testing).",
           "key": "CRB:5.8.3.8"
          },
          {
           "id": "5.8.3.9",
           "text": "All API activities, including authentication attempts, data access, and errors, shall be logged and monitored for anomalies and suspicious activities.",
           "key": "CRB:5.8.3.9"
          },
          {
           "id": "5.8.3.10",
           "text": "Regulated Entities shall define and document a lifecycle management process for APIs, including secure deprecation and retirement practices, to prevent vulnerabilities in unused or legacy APIs.",
           "key": "CRB:5.8.3.10"
          },
          {
           "id": "5.8.3.11",
           "text": "APIs shall handle errors securely to avoid exposing sensitive information (e.g., stack traces, database errors) in error responses or messages.",
           "key": "CRB:5.8.3.11"
          },
          {
           "id": "5.8.3.12",
           "text": "For third-party APIs, the Entities shall assess their security posture, ensuring compliance with contractual obligations and industry standards.",
           "key": "CRB:5.8.3.12"
          }
         ]
        }
       ]
      },
      {
       "num": "5.9",
       "name": "Change and Release Management",
       "areas": [
        {
         "num": "5.9.1",
         "name": "Change and Release Management Process",
         "controls": [
          {
           "id": "5.9.1.1",
           "text": "A change and release management process shall be defined, approved, implemented, monitored, reviewed annually, and updated.",
           "key": "CRB:5.9.1.1"
          },
          {
           "id": "5.9.1.2",
           "text": "The change and release management process shall ensure appropriate consideration of defined security controls in complete cycle of change, configuration, and release management.",
           "key": "CRB:5.9.1.2"
          },
          {
           "id": "5.9.1.3",
           "text": "Regulated Entities shall classify the changes based on priority, complexity, and nature of change and ensure that risks are identified, assessed, and addressed.",
           "key": "CRB:5.9.1.3"
          },
          {
           "id": "5.9.1.4",
           "text": "Appropriate documentation, testing, and approvals shall be in place before change is implemented in production. The documentation of the major changes shall include at a minimum: a) a detailed description of the proposed change; b) an impact assessment on core business services and customers; c) risk analysis; and d) mitigation strategies.",
           "key": "CRB:5.9.1.4"
          },
          {
           "id": "5.9.1.5",
           "text": "All changes shall be reviewed and approved to ensure consistent adherence to applicable policies and procedures.",
           "key": "CRB:5.9.1.5"
          },
          {
           "id": "5.9.1.6",
           "text": "Testing shall be planned, executed, and documented to validate expected outcome. Testing shall consider the following: a) user acceptance testing (to validate functionality); b) stress testing, exception handling, and integrity of application interfaces; c) security testing for user management, application and infrastructure security, source code reviews (as applicable), penetration testing, and vulnerability assessment; and d) audit trails.",
           "key": "CRB:5.9.1.6"
          },
          {
           "id": "5.9.1.7",
           "text": "Appropriate fallback procedures shall be in place in case of recovering from unsuccessful changes and unforeseen events.",
           "key": "CRB:5.9.1.7"
          },
          {
           "id": "5.9.1.8",
           "text": "Regulated Entities shall seek approval from CBK for changes which have a major impact on the Regulated Entity core business services and/or affecting customers.",
           "key": "CRB:5.9.1.8"
          },
          {
           "id": "5.9.1.9",
           "text": "Regulated Entities shall submit a formal approval request to CBK for any major change in advance of the intended implementation date, following CBK’s defined timelines and instructions in this regard. The approval request shall include a detailed description of the proposed change, an impact assessment on core business services and customers, risk analysis, and mitigation strategies. If CBK requested additional information, the Regulated Entity shall respond promptly to ensure timely processing of the request.",
           "key": "CRB:5.9.1.9"
          }
         ]
        }
       ]
      },
      {
       "num": "5.10",
       "name": "Capacity Management",
       "areas": [
        {
         "num": "5.10.1",
         "name": "Capacity and Performance Management",
         "controls": [
          {
           "id": "5.10.1.1",
           "text": "A capacity management process shall be documented, approved, implemented, and reviewed at least annually.",
           "key": "CRB:5.10.1.1"
          },
          {
           "id": "5.10.1.2",
           "text": "Regulated Entities shall define appropriate thresholds for capacity monitoring based on system criticality and consider current utilization, future requirements, current system performance, service unavailability etc. and implement measures to address them.",
           "key": "CRB:5.10.1.2"
          },
          {
           "id": "5.10.1.3",
           "text": "The defined thresholds shall be reviewed on quarterly basis or following major incidents, upgrades, or changes to ensure continued relevance and alignment with business needs.",
           "key": "CRB:5.10.1.3"
          },
          {
           "id": "5.10.1.4",
           "text": "Continuous monitoring, measurement, and analysis shall be performed to track asset-level performance, including CPU usage, latencies and response time, storage utilization, throughputs, as well as downtimes and causes of unavailability. Real-time alerts and dashboards shall be utilized to provide early warnings on capacity issues.",
           "key": "CRB:5.10.1.4"
          },
          {
           "id": "5.10.1.5",
           "text": "Regulated Entities shall implement proactive measures to address capacity risks and bottlenecks, by having proper capacity planning ensuring required resources are sufficient to meet current and future business needs in a cost-effective, scalable, and secure manner. Capacity planning shall be conducted on an annual basis and reviewed quarterly and as needed based on changes to business forecasts, infrastructure, or emerging risks.",
           "key": "CRB:5.10.1.5"
          },
          {
           "id": "5.10.1.6",
           "text": "Capacity testing, such as stress testing, shall be performed during system deployments, upgrades, or significant changes to validate resource adequacy.",
           "key": "CRB:5.10.1.6"
          }
         ]
        }
       ]
      },
      {
       "num": "5.11",
       "name": "Data Protection and Privacy",
       "areas": [
        {
         "num": "5.11.1",
         "name": "Data Protection",
         "controls": [
          {
           "id": "5.11.1.1",
           "text": "A Data Protection policy and supporting procedures for the identification and protection of important records shall be documented, approved, implemented, and reviewed on an annual basis.",
           "key": "CRB:5.11.1.1"
          },
          {
           "id": "5.11.1.2",
           "text": "The policy and procedures shall include specifications for processing, storage, retention and disposal of classified data and information in accordance with: a) regulatory and legal requirements; and b) local and cross-border business requirements.",
           "key": "CRB:5.11.1.2"
          },
          {
           "id": "5.11.1.3",
           "text": "Security controls shall be implemented to protect confidentiality, integrity, and availability of classified data and information while at rest, in transit, and during processing or use.",
           "key": "CRB:5.11.1.3"
          },
          {
           "id": "5.11.1.4",
           "text": "Encryption techniques used to protect classified data and information shall be in accordance with the approved cryptography policy of the Regulated Entities, which shall be in line with industry best practices.",
           "key": "CRB:5.11.1.4"
          },
          {
           "id": "5.11.1.5",
           "text": "Data security and privacy measures, including but not limited to access controls, encryption, and monitoring, shall be apply to data shared with supply chain vendors.",
           "key": "CRB:5.11.1.5"
          },
          {
           "id": "5.11.1.6",
           "text": "Data privacy and protection requirements shall be communicated to and strictly adhered to by third-party vendors, specified within the outsourcing agreement.",
           "key": "CRB:5.11.1.6"
          }
         ]
        },
        {
         "num": "5.11.2",
         "name": "Data Privacy",
         "controls": [
          {
           "id": "5.11.2.1",
           "text": "A data privacy policy shall be documented, approved, implemented, and reviewed annually to align with legal, regulatory, and industry requirements.",
           "key": "CRB:5.11.2.1"
          },
          {
           "id": "5.11.2.2",
           "text": "Regulated Entities shall include privacy-by-design as a core component of the data protection strategy, to ensure that data privacy requirements are embedded into all systems and technologies from the onset of the system / technology life cycle. The following privacy-by- design principles should be taken into consideration: a) proactive not reactive; Preventative not remedial: Privacy should be integrated into the design from the onset to prevent privacy breaches in a proactive manner. b) privacy as the default setting: Personal data should be automatically protected in any system without requiring any additional actions to be taken by the concerned users to protect their privacy. c) privacy embedded into design: Privacy should be a core consideration in system design and architecture. d) full functionality - Positive-sum, not Zero-sum: Privacy should accommodate all valid interest and objectives without sacrificing elements such as usability, efficiency or functionality. e) end-to-end security - Lifecycle protection: Data should be protected at all stages of the lifecycle from collection through to deletion, including secure storage, transmission and eventual destruction. f) visibility and transparency - Keep it open: Systems and processes shall be transparent to ensure authorized users have visibility on how their data is handled. g) respect for user privacy - Keep it user-centric: The privacy interests of users should be prioritized by the system, including providing user-friendly options to select and manage privacy preferences.",
           "key": "CRB:5.11.2.2"
          },
          {
           "id": "5.11.2.3",
           "text": "The following privacy principles concerning personal data shall be included in the policy: a) Lawfulness, Fairness, and Transparency: Personal data shall be processed lawfully, fairly, and in a transparent manner in relation to the data subject; b) Purpose Limitation: Personal data shall be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archival purposes shall not be considered to be incompatible with the initial purposes; c) Data Minimization: Personal data collected shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed; d) Accuracy: Personal data shall be accurate and, where necessary, kept up to date; steps shall be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay; e) Storage Limitation: Personal data shall be kept in a form, which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods if it will be processed solely for archiving purposes to safeguard the rights and freedoms of the data subject. Data retention periods shall be in compliance with CBK relevant instructions, laws, and regulations.; f) Consent: Personal data shall be collected with explicit consent of the data subject, ensuring that such consent is freely-given, specific, informed, unambiguous and affirmative. Consent should be separate from other terms and conditions and not used as a precondition of signing up to or accessing services, unless necessary for the service itself. Data subjects shall have the ability to withdraw consent at any time; g) Right to be Forgotten: Data subjects shall have the right to request erasure of their personal data when it is no longer processed, no longer necessary in relation to the original purposes for which it was collected or otherwise processed, consent is withdrawn, or the personal data does not comply with legal and regulatory requirements; and h) Integrity and Confidentiality: Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing, and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.",
           "key": "CRB:5.11.2.3"
          },
          {
           "id": "5.11.2.4",
           "text": "The Regulated Entities shall promptly notify CBK upon the discovery of a personal data breach, without delay and in accordance with the timelines defined in CBK Operational Resilience Baselines.",
           "key": "CRB:5.11.2.4"
          },
          {
           "id": "5.11.2.5",
           "text": "The Regulated Entities shall notify the data subject in case of a personal data breach, without undue delay, if the breach is likely to result in a high risk to the data subject’s rights and freedoms, enabling the data subject to take necessary precautions.",
           "key": "CRB:5.11.2.5"
          },
          {
           "id": "5.11.2.6",
           "text": "A Privacy Impact Assessment (PIA) shall be conducted every two years or whenever significant changes occur in the environment to identify potential personal data at risk and ascertain that appropriate technical measures are in place to protect such information. PIAs shall be reviewed on annual basis.",
           "key": "CRB:5.11.2.6"
          },
          {
           "id": "5.11.2.7",
           "text": "Data protection requirements shall be communicated to, and enforced within outsourcing agreements. The Regulated Entities shall ensure that third-parties adhere strictly to the data privacy and protection requirements and policies.",
           "key": "CRB:5.11.2.7"
          }
         ]
        }
       ]
      },
      {
       "num": "5.12",
       "name": "Logging, Monitoring, and Security Incident Management",
       "areas": [
        {
         "num": "5.12.1",
         "name": "Logging and Monitoring",
         "controls": [
          {
           "id": "5.12.1.1",
           "text": "A policy for logging and monitoring shall be defined, approved, implemented, and reviewed annually. The policy shall include requirements of log types, content, protection, retention, archival, monitoring, and secure destruction.",
           "key": "CRB:5.12.1.1"
          },
          {
           "id": "5.12.1.2",
           "text": "Logs shall be enabled on all critical technology assets on-premises and in cloud.",
           "key": "CRB:5.12.1.2"
          },
          {
           "id": "5.12.1.3",
           "text": "The granularity level of logging shall be based on the classification of the data and risk assessment. At a minimum, the logs shall contain the following information: a) user ID (who); b) timestamp (i.e., date and time) (when); c) source of activity, such as location, IP address, service etc. (from where); d) details of event such as log-on, log-off (what); e) details of successful and unsuccessful system access attempts; f) details of successful and unsuccessful resource access attempts; and g) details of successful and unsuccessful configuration or settings change access attempts.",
           "key": "CRB:5.12.1.3"
          },
          {
           "id": "5.12.1.4",
           "text": "Relevant log sources and logs received shall be monitored, correlated, and protected against unauthorized tampering.",
           "key": "CRB:5.12.1.4"
          },
          {
           "id": "5.12.1.5",
           "text": "Regulated Entities shall implement adequate technologies, i.e., security information and event management (SIEM) tools, to monitor and log security events, including correlation of events and identification of anomalies and security incidents for further investigation.",
           "key": "CRB:5.12.1.5"
          },
          {
           "id": "5.12.1.6",
           "text": "Automated systems should be used to categorize and prioritize incidents based on the severity of the identified threat, using AI-based risk assessment algorithms.",
           "key": "CRB:5.12.1.6"
          }
         ]
        },
        {
         "num": "5.12.2",
         "name": "Detection and Analysis",
         "controls": [
          {
           "id": "5.12.2.1",
           "text": "A security information and event management process to identify, track, and monitor events, issues, and incidents shall be documented, approved, implemented, and reviewed annually. The process shall include criteria for: a) Classification and categorization of events and incidents; b) assigning ownership; c) assessing whether they constitute security breach; d) assessing the severity and criticality of the incident; and e) sharing of incident information and associated threat intelligence.",
           "key": "CRB:5.12.2.1"
          },
          {
           "id": "5.12.2.2",
           "text": "Regulated Entities shall establish and maintain a structured threat hunting process to proactively identify unknown, emerging, or ongoing unresolved threats within the environment.",
           "key": "CRB:5.12.2.2"
          },
          {
           "id": "5.12.2.3",
           "text": "Indicators of Compromise (IoCs) shall be continuously monitored using automated detection techniques and rapidly reported for investigation.",
           "key": "CRB:5.12.2.3"
          },
          {
           "id": "5.12.2.4",
           "text": "Incidents shall be validated by correlating evidence obtained through different sources and logs (e.g., firewall logs and source IP addresses, application logs and usernames).",
           "key": "CRB:5.12.2.4"
          }
         ]
        },
        {
         "num": "5.12.3",
         "name": "Response and Recovery",
         "controls": [
          {
           "id": "5.12.3.1",
           "text": "An Incident Response Team (IRT) or equivalent group shall be formed by Regulated Entities to respond to security incidents. The IRT shall be available 24/7 to respond to information security incidents or events.",
           "key": "CRB:5.12.3.1"
          },
          {
           "id": "5.12.3.2",
           "text": "A documented security incident response plan shall be prepared and made readily accessible to limit or mitigate the impact of security incidents.",
           "key": "CRB:5.12.3.2"
          },
          {
           "id": "5.12.3.3",
           "text": "Incident response playbooks shall be automated to enable timely management and containment of security incidents with minimal human intervention.",
           "key": "CRB:5.12.3.3"
          },
          {
           "id": "5.12.3.4",
           "text": "A summary of incidents shall be reported to Board and Executive/Senior Management on a quarterly basis or more frequently based on the severity and impact of the incident.",
           "key": "CRB:5.12.3.4"
          },
          {
           "id": "5.12.3.5",
           "text": "All reported security incidents shall be tracked, logged, analyzed, and remediated. Remediation strategy shall be implemented in a manner that is consistent with the nature and severity of the incident.",
           "key": "CRB:5.12.3.5"
          }
         ]
        },
        {
         "num": "5.12.4",
         "name": "Forensics and Evidence Collection",
         "controls": [
          {
           "id": "5.12.4.1",
           "text": "Forensic procedures shall be established, maintained, and reviewed annually to ensure readiness for evidence collection, preservation, and analysis.",
           "key": "CRB:5.12.4.1"
          },
          {
           "id": "5.12.4.2",
           "text": "The forensic procedures shall define roles, responsibilities, and escalation paths to ensure forensic activities are effectively coordinated.",
           "key": "CRB:5.12.4.2"
          },
          {
           "id": "5.12.4.3",
           "text": "The procedures shall mandate and define the appropriate use of forensic tools and techniques to collect, retain, and archive evidence in a way that maintains its integrity for legal or investigative purposes.",
           "key": "CRB:5.12.4.3"
          },
          {
           "id": "5.12.4.4",
           "text": "The procedures shall specify when and how authorization and approval is required from management, law enforcement, or regulator to initiate forensic activities, ensuring compliance with operational, legal, and regulatory mandates.",
           "key": "CRB:5.12.4.4"
          },
          {
           "id": "5.12.4.5",
           "text": "Communication protocols with law enforcement and regulators shall be formally documented in the forensic procedures, including clearly defined Point of Contact (POC), to ensure timely coordination and reporting of incidents, in compliance with confidentiality, privacy, and regulatory requirements.",
           "key": "CRB:5.12.4.5"
          },
          {
           "id": "5.12.4.6",
           "text": "Regulated Entities shall ensure that the personnel involved in forensic investigations are trained and certified in relevant forensic tools and techniques.",
           "key": "CRB:5.12.4.6"
          },
          {
           "id": "5.12.4.7",
           "text": "Chain of custody shall be maintained for all evidence collected, with documented transfers, dates, and individuals involved.",
           "key": "CRB:5.12.4.7"
          },
          {
           "id": "5.12.4.8",
           "text": "Evidence shall be protected with Cryptographic Hash Functions (CHF) (e.g., SHA-256, SHA- 512) to ensure it is not tampered. Verification of integrity shall take a place before and after any forensic task.",
           "key": "CRB:5.12.4.8"
          },
          {
           "id": "5.12.4.9",
           "text": "Every forensic task shall be logged and documented, including at a minimum: a) tools and techniques used, with version numbers and configurations; b) time-stamped activities from the start to the conclusion of each forensic task; and c) observations or anomalies detected during the investigation.",
           "key": "CRB:5.12.4.9"
          },
          {
           "id": "5.12.4.10",
           "text": "Regulated Entities shall establish Digital Forensics and Incident Response (DFIR) capabilities through either establishing internal 24/7 cyber incident responders or external cyber incident response retainers such as forensic experts or forensic service providers, to enable smooth cooperation during investigations. DFIR shall include: a) define roles, responsibilities, scope of collaboration, confidentiality obligations, data sharing protocols, and timelines for joint activities; b) ensure compliance with legal, regulatory, and privacy requirements, especially for cross-boarder investigations; and c) Service Level Agreements (SLAs).",
           "key": "CRB:5.12.4.10"
          }
         ]
        }
       ]
      },
      {
       "num": "5.13",
       "name": "Cybersecurity Testing and Threat Management",
       "areas": [
        {
         "num": "5.13.1",
         "name": "Vulnerability Management",
         "controls": [
          {
           "id": "5.13.1.1",
           "text": "A vulnerability management process shall be defined, approved, implemented, monitored, measured, reviewed annually and updated. The process shall include vulnerability discovery, classification, prioritization, and treatment.",
           "key": "CRB:5.13.1.1"
          },
          {
           "id": "5.13.1.2",
           "text": "Vulnerability assessments (e.g., missing security updates, missing baseline configuration, application security testing, penetration testing, and code reviews) of network, systems, and applications shall be conducted on periodic basis or whenever significant changes occur to the environment, to identify the existence of vulnerabilities and classify them based on their impact.",
           "key": "CRB:5.13.1.2"
          },
          {
           "id": "5.13.1.3",
           "text": "Timelines or matrices for addressing vulnerabilities shall be defined based on the type of test conducted, criticality of the asset, severity of the vulnerability, and associated risk level.",
           "key": "CRB:5.13.1.3"
          },
          {
           "id": "5.13.1.4",
           "text": "Regulated Entities shall receive notifications from external threat intelligence feeds and other trusted information sources about latest vulnerabilities. The Entities shall follow a formal risk-based approach for prioritizing and treating the vulnerabilities identified and notifications received in line with the risk management process.",
           "key": "CRB:5.13.1.4"
          },
          {
           "id": "5.13.1.5",
           "text": "Regulated Entities shall conduct validation after remediating the vulnerabilities to assess and confirm whether the gaps addressed are in line with documented risk mitigation decisions.",
           "key": "CRB:5.13.1.5"
          },
          {
           "id": "5.13.1.6",
           "text": "Regulated Entities shall use external attack surface management to discover, monitor and address vulnerabilities within the public facing assets.",
           "key": "CRB:5.13.1.6"
          },
          {
           "id": "5.13.1.7",
           "text": "The findings of vulnerability assessments shall be documented and reported for initiating remediation activities and tracked till closure.",
           "key": "CRB:5.13.1.7"
          },
          {
           "id": "5.13.1.8",
           "text": "The information security function shall update the Board and Executive/Senior Management on quarterly basis or more frequently, as required, about the effectiveness of vulnerability management process, including key metrics and unresolved issues.",
           "key": "CRB:5.13.1.8"
          }
         ]
        },
        {
         "num": "5.13.2",
         "name": "Security Patch Management",
         "controls": [
          {
           "id": "5.13.2.1",
           "text": "Security patch management process shall be defined, approved, implemented, and reviewed annually. The effectiveness of the process shall be continuously monitored and measured using relevant metrics (e.g., patching timelines, coverage).",
           "key": "CRB:5.13.2.1"
          },
          {
           "id": "5.13.2.2",
           "text": "Regulated Entities shall define a risk-based patching schedule (e.g. monthly, quarterly, etc.,) based on both the criticality of the asset and the severity of the vulnerability.",
           "key": "CRB:5.13.2.2"
          },
          {
           "id": "5.13.2.3",
           "text": "Emergency patches shall be deployed immediately within an escalated timeframe to address actively exploited vulnerabilities.",
           "key": "CRB:5.13.2.3"
          },
          {
           "id": "5.13.2.4",
           "text": "Exceptions or delays in patch deployments shall be formally justified, documented, approved by relevant stakeholders, and report to Executive/ Senior Management. Red Teaming and Adversarial Simulations",
           "key": "CRB:5.13.2.4"
          },
          {
           "id": "5.13.2.5",
           "text": "Red teaming exercises shall simulate real-world adversarial Tactics, Techniques, and Procedures (TTPs) to assess the resilience of critical systems, applications, processes, and people against cyber threats.",
           "key": "CRB:5.13.2.5"
          },
          {
           "id": "5.13.2.6",
           "text": "Threat intelligence shall be incorporated into red teaming exercises to ensure scenarios reflect real-world adversary TTPs and emerging threats.",
           "key": "CRB:5.13.2.6"
          },
          {
           "id": "5.13.2.7",
           "text": "Red teaming exercises shall be conducted at least once a year or as required based on changes to the threat landscape, critical systems, or regulatory requirements. Clear objectives, scope, and success criteria shall be defined for each exercise.",
           "key": "CRB:5.13.2.7"
          },
          {
           "id": "5.13.2.8",
           "text": "Regulated Entities shall engage a dedicated qualified team with specialized expertise to conduct red teaming exercises.",
           "key": "CRB:5.13.2.8"
          },
          {
           "id": "5.13.2.9",
           "text": "Red teaming exercises shall be performed without prior knowledge of other teams such as cyber monitoring, incident response and asset owners to maintain scenario realism.",
           "key": "CRB:5.13.2.9"
          },
          {
           "id": "5.13.2.10",
           "text": "Findings from red teaming exercises, including identified vulnerabilities, gaps, and areas for improvement, shall be documented and reported to Executive/ Senior Management and relevant stakeholders for review and action.",
           "key": "CRB:5.13.2.10"
          },
          {
           "id": "5.13.2.11",
           "text": "Regulated Entities shall define and implement a remediation plan with clear timelines address the identified findings. Progress on remediation actions shall be tracked to closure.",
           "key": "CRB:5.13.2.11"
          }
         ]
        }
       ]
      },
      {
       "num": "5.14",
       "name": "Physical and Environmental Security",
       "areas": [
        {
         "num": "5.14.1",
         "name": "Physical and Environmental Security Controls",
         "controls": [
          {
           "id": "5.14.1.1",
           "text": "Physical and environmental security policy shall be documented, approved, implemented, reviewed annually and updated.",
           "key": "CRB:5.14.1.1"
          },
          {
           "id": "5.14.1.2",
           "text": "Physical security perimeters or zones shall be identified, protected by appropriate physical and logical security controls, and monitored in line with the physical and environmental security policy.",
           "key": "CRB:5.14.1.2"
          },
          {
           "id": "5.14.1.3",
           "text": "An approved list of individuals with authorized physical access to a restricted areas shall be maintained and reviewed on a quarterly basis.",
           "key": "CRB:5.14.1.3"
          },
          {
           "id": "5.14.1.4",
           "text": "All access points shall be controlled to prevent unauthorized entry to restricted or secure areas (such as core data center where servers and network equipment are located). Additionally, Regulated Entities shall consider isolating loading, storage, or delivery areas from secure areas.",
           "key": "CRB:5.14.1.4"
          },
          {
           "id": "5.14.1.5",
           "text": "Regulated Entities shall comply with health and safety guidelines for facilities.",
           "key": "CRB:5.14.1.5"
          },
          {
           "id": "5.14.1.6",
           "text": "Security measures and policies shall be consistently applied to on-site and off-site equipment.",
           "key": "CRB:5.14.1.6"
          },
          {
           "id": "5.14.1.7",
           "text": "Access to restricted/secured areas shall be monitored using Closed Circuit television (CCTV) in accordance with CCTV Law No 61-2015.",
           "key": "CRB:5.14.1.7"
          },
          {
           "id": "5.14.1.8",
           "text": "Environmental considerations shall be incorporated into the design and construction of facilities. All IT enabled environmental solutions (e.g., HVAC Systems, Building Management Solutions etc.) need to adhere to applicable controls in this document.",
           "key": "CRB:5.14.1.8"
          },
          {
           "id": "5.14.1.9",
           "text": "Restricted or secure areas shall have measures (e.g., temperature and humidity controls, fire extinguishers, smoke detectors, sprinklers, water leakage detection mechanisms, etc.) to detect and protect against environmental hazards.",
           "key": "CRB:5.14.1.9"
          },
          {
           "id": "5.14.1.10",
           "text": "Restricted or secure areas shall have functional power backup systems to address partial or complete electrical failure.",
           "key": "CRB:5.14.1.10"
          },
          {
           "id": "5.14.1.11",
           "text": "The implemented physical and environmental controls shall be appropriately and periodically tested, at least quarterly. Preventive maintenance shall be conducted to ensure performance as per intended purpose and specifications.",
           "key": "CRB:5.14.1.11"
          },
          {
           "id": "5.14.1.12",
           "text": "Evacuation plans shall be established and communicated to all employees and third-party vendors, and periodic evacuation drills shall be conducted, at least semi-annually. The logs of evacuation drills shall be maintained and necessary corrective and improvements initiatives shall be undertaken.",
           "key": "CRB:5.14.1.12"
          }
         ]
        },
        {
         "num": "5.14.2",
         "name": "Connected Devices (IoT/OT) Security",
         "controls": [
          {
           "id": "5.14.2.1",
           "text": "IoT/OT networks (e.g., CCTV systems, Building Management Systems (BMS)) shall be segregated from IT networks using proper network segmentation and firewalls to prevent unauthorized access or lateral movement.",
           "key": "CRB:5.14.2.1"
          },
          {
           "id": "5.14.2.2",
           "text": "All IoT/OT devices connected to the network shall be identified, inventoried, and categorized based on their criticality. This inventory shall be reviewed and updated on semi-annual basis or as changes to the network occur.",
           "key": "CRB:5.14.2.2"
          },
          {
           "id": "5.14.2.3",
           "text": "IoT/OT devices and their associated networks shall be subject to security assessments, including quarterly vulnerability assessments and annual penetration testing. More frequent assessments shall be considered for critical systems based on the evolving threat landscape or regulatory requirements.",
           "key": "CRB:5.14.2.3"
          },
          {
           "id": "5.14.2.4",
           "text": "Access to IoT/OT devices shall be restricted to authorized personnel, and logical access controls (e.g., strong password, MFA) shall be implemented. Access logs shall be monitored and reviewed at least monthly to identify any suspicious behavior.",
           "key": "CRB:5.14.2.4"
          }
         ]
        }
       ]
      },
      {
       "num": "5.15",
       "name": "Cyber Threat Intelligence",
       "areas": [
        {
         "num": "5.15.1",
         "name": "Cyber Threat Intelligence (CTI) Management",
         "controls": [
          {
           "id": "5.15.1.1",
           "text": "A process for identification, analysis, prioritization, sharing and management of cyber threats shall be documented, approved, implemented, and reviewed annually.",
           "key": "CRB:5.15.1.1"
          },
          {
           "id": "5.15.1.2",
           "text": "Intelligence from trusted, identified internal and external sources shall be collected, disseminated promptly to relevant stakeholders, and processed consistently and in a timely manner.",
           "key": "CRB:5.15.1.2"
          },
          {
           "id": "5.15.1.3",
           "text": "Intelligence shall cover tactical, operational, and strategic levels to ensure appropriate actions across different functions within the Regulated Entities.",
           "key": "CRB:5.15.1.3"
          },
          {
           "id": "5.15.1.4",
           "text": "Regulated Entities shall implement a Threat Intelligence Platform (TIP) to aggregate and analyze threat intelligence feeds from multiple sources. The TIP shall: a) centralize threat intelligence feeds for consistent management and enrichment; b) provide custom scoring and prioritization based on the relevance of threats to the organization; The TIP shall be integrated with the relevant cyber detection and response tools (e.g., SIEM, SOAR, EDR) to operationalize intelligence in an effective way. This integration shall: a) enable automated enrichment of security events with threat intelligence; b) trigger real-time alerts and playbook-driven responses for high-classified incidents; and c) correlate threat intelligence with internal alerts for more accurate and effective detection and response.",
           "key": "CRB:5.15.1.4"
          }
         ]
        },
        {
         "num": "5.15.2",
         "name": "CTI Collaboration and Continuous Improvement",
         "controls": [
          {
           "id": "5.15.2.1",
           "text": "Threat intelligence shall drive proactive risk mitigation activities, such as vulnerability management, patch management, and system hardening.",
           "key": "CRB:5.15.2.1"
          },
          {
           "id": "5.15.2.2",
           "text": "Cyber threats and insights shall be communicated to Executive/ Senior management and relevant stakeholders on a timely and need-to-know basis.",
           "key": "CRB:5.15.2.2"
          },
          {
           "id": "5.15.2.3",
           "text": "Regulated Entities shall identify applicable threats and undertake necessary actions to protect their technology assets as per the incident management process. All such actions shall be documented, monitored, and tracked.",
           "key": "CRB:5.15.2.3"
          },
          {
           "id": "5.15.2.4",
           "text": "Regulated Entities shall review and improve their threat intelligence management capabilities on an ongoing basis, with a focus on lessons learnt from incidents, feedback from read teaming and other testing exercises, and evolving threat landscapes and new intelligence sources.",
           "key": "CRB:5.15.2.4"
          },
          {
           "id": "5.15.2.5",
           "text": "Regulated Entities shall define within the cyber threat intelligence process the requirements to continually with the CBK to: a) consume threat intelligence provided by CBK; b) share the identified threat intelligence (internal and external) to the banking and financial sector community and management; and c) proactively participate in sectoral collaboration for remediation of threats.",
           "key": "CRB:5.15.2.5"
          }
         ]
        }
       ]
      },
      {
       "num": "5.16",
       "name": "Digital Risk Protection",
       "areas": [
        {
         "num": "5.16.1",
         "name": "Digital Risk and Brand Protection",
         "controls": [
          {
           "id": "5.16.1.1",
           "text": "A policy for protecting the Entity’s online presence shall be defined, approved, implemented, and reviewed annually. This policy shall align with the Regulated Entity’s incident management policy and procedures.",
           "key": "CRB:5.16.1.1"
          },
          {
           "id": "5.16.1.2",
           "text": "The policy shall include at a minimum, controls to monitor misuse of the brand, domain names, logos, initiatives related products and identity of key influential personnel of the regulated entity. The policy shall also contain appropriate measures to escalate and remediate identified brand abuse.",
           "key": "CRB:5.16.1.2"
          },
          {
           "id": "5.16.1.3",
           "text": "Regulated Entities shall establish processes and measures to monitor, identify, escalate, and address incidents of digital brand abuse and misuse across various channels, including websites, social media platforms, mobile app stores, and the deep/dark web. The process shall detect and respond to: a) brand abuse, misrepresentation, and fraudulent activities (e.g., malicious domains, fake social media accounts impersonating the Entities or key personnel, fake mobile applications, and phishing sites); b) targeted social engineering or phishing campaigns; c) web defacement or unauthorized content publication on public-facing systems; d) fake or misleading information about the organization circulating online; and e) data leaks or unauthorized disclosures of sensitive information.",
           "key": "CRB:5.16.1.3"
          },
          {
           "id": "5.16.1.4",
           "text": "The Regulated Entities shall use an appropriate brand protection solution to enable continuous monitoring and real-time detection of brand misuse and fraudulent activities across digital channels, facilitating swift response and ensuring proactive mitigation.",
           "key": "CRB:5.16.1.4"
          },
          {
           "id": "5.16.1.5",
           "text": "Collaboration with external parties, such as social media platforms, app stores, and domain registrars shall be established to promptly takedown and remove any fraudulent account, content, website, or applications.",
           "key": "CRB:5.16.1.5"
          },
          {
           "id": "5.16.1.6",
           "text": "All content for public facing systems shall be reviewed and approved by relevant internal functions before being published to ensure consistency with the brand policies and guidelines.",
           "key": "CRB:5.16.1.6"
          },
          {
           "id": "5.16.1.7",
           "text": "Training shall be provided to relevant employees to assist them in understanding reputation- related cyber risks and safe usage of social media.",
           "key": "CRB:5.16.1.7"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 3,
     "section": "6",
     "name": "Third-Party Risk Management and Supply Chain Management",
     "subdomains": [
      {
       "num": "6.1",
       "name": "Third-Party Risk Management (TPRM)",
       "areas": [
        {
         "num": "6.1.1",
         "name": "Third-Party Risk Management",
         "controls": [
          {
           "id": "6.1.1.1",
           "text": "A Third-Party Risk Management (TPRM) framework shall be defined, approved, communicated, and implemented. The framework and associated policies and processes shall be aligned with CBK requirements outlined in the CBK TPRM Baselines. The framework shall be reviewed by Risk Management, Information Security, and Audit functions of Regulated Entities on periodic basis, at least annually.",
           "key": "CRB:6.1.1.1"
          },
          {
           "id": "6.1.1.2",
           "text": "Regulated Entities shall seek approval from CBK before engaging in any significant Information Technology (IT) related third-party agreements.",
           "key": "CRB:6.1.1.2"
          },
          {
           "id": "6.1.1.3",
           "text": "Proper due diligence shall be conducted during the third-party vendor selection process to assess the vendor’s suitability. The due diligence shall cover the following: a) experience and capability of the third-party vendor; b) financial strength and stability of the third-party vendor; c) internal control environment of the third-party vendor (SOC1/2, SSAE16/18 …etc. can be considered); d) cybersecurity practices of third-party vendor implemented to mitigate risks, such as incident management, data protection, and access controls; e) BCP and DR arrangements of the third-party vendor; and f) ability to comply with applicable laws, regulations, and industry standards (Attestation of compliance can be considered).",
           "key": "CRB:6.1.1.3"
          },
          {
           "id": "6.1.1.4",
           "text": "Risk assessments shall be conducted for all IT third-party services as part of the Regulated Entity’s Third-Party Risk Management (TPRM) framework and as per the risk management process prior to engagement.",
           "key": "CRB:6.1.1.4"
          },
          {
           "id": "6.1.1.5",
           "text": "Regulated Entities shall have written agreements for all IT related third-party arrangements that include minimum cybersecurity requirements and define the scope and governance of the third-party service. The agreements shall include: a) scope of services and service level requirements; b) roles and responsibilities with respect to implementation of security requirements; c) confidentiality and security of information shared and non-disclosure requirements; d) operations and risk management requirements; e) business continuity and crisis management requirements; f) subcontracting and further outsourcing of services; g) right to audit and inspect; h) termination clause; and i) requirements for notifications and disclosures of cyber incidents, data breach, or any other security events.",
           "key": "CRB:6.1.1.5"
          },
          {
           "id": "6.1.1.6",
           "text": "Regulated Entities shall maintain an accurate and up-to-date register of all third-party agreements.",
           "key": "CRB:6.1.1.6"
          },
          {
           "id": "6.1.1.7",
           "text": "Regulated Entities shall perform assessment of third-party vendors to ensure the adequacy of implemented and to be implemented controls to address necessary security requirements as per the third-party agreement. Such assessments shall be conducted annually for significant outsourcing arrangements and on a similar or less frequent basis for other arrangements, or whenever a change occur to ensure ongoing compliance.",
           "key": "CRB:6.1.1.7"
          },
          {
           "id": "6.1.1.8",
           "text": "Existing third-party agreements that are already in place shall also be subject to risk assessments, and any identified gaps shall be addressed promptly through control updates, process improvements, or contractual amendments.",
           "key": "CRB:6.1.1.8"
          },
          {
           "id": "6.1.1.9",
           "text": "Regulated Entities shall implement processes to continuously monitor the activities of third- party vendors. The following areas shall be reviewed as part of the monitoring process: a) ongoing compliance with security and data protection requirements; b) confidentiality and security of information shared; and c) business continuity and disaster recovery arrangements.",
           "key": "CRB:6.1.1.9"
          },
          {
           "id": "6.1.1.10",
           "text": "Regulated Entities shall record risks and issues identified during the monitoring process and track the same to mitigation and closure.",
           "key": "CRB:6.1.1.10"
          },
          {
           "id": "6.1.1.11",
           "text": "Security requirements within third-party agreements shall be reviewed and updated annually or upon significant changes in services provided by third-party vendors.",
           "key": "CRB:6.1.1.11"
          },
          {
           "id": "6.1.1.12",
           "text": "Regulated Entities shall ensure secure disposal of information assets that were exchanged during the execution of third-party agreement, in compliance with data privacy laws, regulatory requirements, and internal policies.",
           "key": "CRB:6.1.1.12"
          }
         ]
        }
       ]
      },
      {
       "num": "6.2",
       "name": "Supply Chain Management",
       "areas": [
        {
         "num": "6.2.1",
         "name": "Supply Chain Risk Management",
         "controls": [
          {
           "id": "6.2.1.1",
           "text": "Regulated Entities shall identify suppliers and dependencies to determine points of failures and integrate supply chain risks into the risk management framework.",
           "key": "CRB:6.2.1.1"
          },
          {
           "id": "6.2.1.2",
           "text": "Regulated Entities shall reduce reliance on single-source suppliers by developing alternative sourcing strategies and establishing backup arrangements to ensure services and business continuity.",
           "key": "CRB:6.2.1.2"
          },
          {
           "id": "6.2.1.3",
           "text": "Regulated Entities shall implement real-time monitoring tools and leverage threat intelligence to detect issues and manage emerging risks across the supply chain in a timely manner.",
           "key": "CRB:6.2.1.3"
          },
          {
           "id": "6.2.1.4",
           "text": "Regulated Entities shall segment suppliers based on their risk level and criticality to apply enhanced controls for high-risk third-party vendors and suppliers.",
           "key": "CRB:6.2.1.4"
          },
          {
           "id": "6.2.1.5",
           "text": "Regulated Entities shall ensure that suppliers extend security requirements and obligations to sub-contractors and fourth parties to maintain consistent security across all tiers of the supply chain.",
           "key": "CRB:6.2.1.5"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 4,
     "section": "7",
     "name": "Emerging Technologies",
     "subdomains": [
      {
       "num": "7.1",
       "name": "Advanced Technologies Security",
       "areas": [
        {
         "num": "7.1.1",
         "name": "General Security Requirements",
         "controls": [
          {
           "id": "7.1.1.1",
           "text": "A policy for adopting new advanced/emerging technologies shall be defined, approved, implemented and reviewed periodically.",
           "key": "CRB:7.1.1.1"
          },
          {
           "id": "7.1.1.2",
           "text": "Regulated Entities shall seek approval from CBK when adopting new and emerging technologies. Regulated Entities shall submit an approval request to CBK, at least one month prior to go-live, outlining the technologies considered, the application of the technology, the risk assessment results along with the corresponding risk response details, as well as any relevant information to support the adoption of new and emerging technologies.",
           "key": "CRB:7.1.1.2"
          },
          {
           "id": "7.1.1.3",
           "text": "Regulated Entities shall integrate considerations related to emerging technologies into their existing risk management frameworks, by using threat modeling to identify potential vulnerabilities associated with these technologies (i.e., data breaches, DLT vulnerabilities, adversarial AI attacks, etc.).",
           "key": "CRB:7.1.1.3"
          },
          {
           "id": "7.1.1.4",
           "text": "Regulated Entities shall conduct risk assessment for adopting new technologies, identify controls required to secure the new and emerging technologies and mitigate the identified risks as per the entity's risk management process.",
           "key": "CRB:7.1.1.4"
          },
          {
           "id": "7.1.1.5",
           "text": "Regulated Entities shall establish secure coding practices to be adopted when developing or implementing systems leveraging the capabilities of emerging technologies (i.e., AI, ML, blockchain, etc.) to ensure security principles are built-in.",
           "key": "CRB:7.1.1.5"
          },
          {
           "id": "7.1.1.6",
           "text": "Regulated Entities shall ensure that sufficient tests are carried to ensure that new technology meets the requirements and addresses the identified risks. This includes but is not limited to: a) sandbox testing, to simulate potential attacks on applications prior to deployment; b) periodic internal security testing and vulnerability assessments of systems built on emerging technologies; c) regular security audits and third-party reviews of applications built on emerging technologies.",
           "key": "CRB:7.1.1.6"
          },
          {
           "id": "7.1.1.7",
           "text": "Regulated Entities shall provide appropriate awareness towards customers regarding the use of emerging technologies within relevant products / services offered by the Regulated Entities.",
           "key": "CRB:7.1.1.7"
          }
         ]
        },
        {
         "num": "7.1.2",
         "name": "Artificial Intelligence (AI) and Machine Learning (ML) Security",
         "controls": [
          {
           "id": "7.1.2.1",
           "text": "Regulated Entities shall ensure that AI and ML models are protected against tampering, poisoning, or manipulation during their training, validation, and deployment stages.",
           "key": "CRB:7.1.2.1"
          },
          {
           "id": "7.1.2.2",
           "text": "Regulated Entities shall implement adequate defenses against adversarial attacks (e.g., evasion, data poisoning, inference attacks) targeting AI models. Industry best practices such as OWASP Top 10 LLM applications should be utilized to address security issues in AI applications.",
           "key": "CRB:7.1.2.2"
          },
          {
           "id": "7.1.2.3",
           "text": "Regulated Entities shall ensure that data used for training and inference in AI models is protected in compliance with applicable data privacy regulations and governance frameworks.",
           "key": "CRB:7.1.2.3"
          },
          {
           "id": "7.1.2.4",
           "text": "Regulated Entities shall ensure that AI and ML models are explainable and auditable, specifically in cases where AI and ML models are involved in making high-impact decisions (i.e., fraud detection, credit risk scoring, etc.)",
           "key": "CRB:7.1.2.4"
          },
          {
           "id": "7.1.2.5",
           "text": "Regulated Entities shall continuously monitor AI and ML models for drift, reliability, traceability, and performance evaluation, as well as regular audits to ensure compliance with security requirements.",
           "key": "CRB:7.1.2.5"
          }
         ]
        },
        {
         "num": "7.1.3",
         "name": "Blockchain and Distributed Ledger Technology (DLT) Security",
         "controls": [
          {
           "id": "7.1.3.1",
           "text": "Regulated Entities shall ensure the security of the blockchain network, including consensus mechanisms, node communication and smart contract execution through the use of adequate encryption and secure algorithms.",
           "key": "CRB:7.1.3.1"
          },
          {
           "id": "7.1.3.2",
           "text": "Regulated Entities shall ensure that smart contracts deployed on blockchain networks undergo rigorous security audits to identify vulnerabilities and potential logic flaws.",
           "key": "CRB:7.1.3.2"
          },
          {
           "id": "7.1.3.3",
           "text": "Regulated Entities shall implement secure key management practices for public and private keys utilized in blockchain and DLT systems.",
           "key": "CRB:7.1.3.3"
          },
          {
           "id": "7.1.3.4",
           "text": "Regulated Entities shall ensure data integrity across distributed ledgers, through utilizing means such as hashing and digital signatures.",
           "key": "CRB:7.1.3.4"
          },
          {
           "id": "7.1.3.5",
           "text": "Regulated Entities shall establish adequate governance frameworks defining roles and responsibilities for maintaining blockchain networks.",
           "key": "CRB:7.1.3.5"
          }
         ]
        },
        {
         "num": "7.1.4",
         "name": "Other Emerging Technologies (Quantum Computing, 5G, etc.) Security",
         "controls": [
          {
           "id": "7.1.4.1",
           "text": "Regulated Entities shall start considering the implications of the threats which will eventually be posed by quantum computing, by starting to adopt quantum-resistant cryptographic algorithms.",
           "key": "CRB:7.1.4.1"
          },
          {
           "id": "7.1.4.2",
           "text": "Regulated Entities shall periodically assess cryptographic practices to ensure resistance to quantum computing capabilities.",
           "key": "CRB:7.1.4.2"
          },
          {
           "id": "7.1.4.3",
           "text": "Regulated Entities shall develop a quantum readiness strategy, prioritizing the transition to quantum-resistant cryptographic algorithms across all systems and processes, while also addressing broader risks posed by quantum computing. The strategy shall include timelines and milestones for cryptographic migration, assessment of critical systems and data at risk, third-party dependencies, and operational preparedness.",
           "key": "CRB:7.1.4.3"
          },
          {
           "id": "7.1.4.4",
           "text": "Regulated Entities shall test and validate quantum-resistant cryptographic algorithms in testing environments to ensure compatibility and performance prior to deployment.",
           "key": "CRB:7.1.4.4"
          },
          {
           "id": "7.1.4.5",
           "text": "Regulated Entities shall assess the risks associated with 5G networks, including focusing on vulnerabilities introduced by the expanded bandwidth, edge computing capabilities and low- latency communications.",
           "key": "CRB:7.1.4.5"
          },
          {
           "id": "7.1.4.6",
           "text": "Regulated Entities shall ensure that data transmitted over 5G networks shall be encrypted using end-to-end encryption protocols, focusing on the confidentiality and integrity of information.",
           "key": "CRB:7.1.4.6"
          }
         ]
        }
       ]
      },
      {
       "num": "7.2",
       "name": "Cloud Security",
       "areas": [
        {
         "num": "7.2.1",
         "name": "Cloud Governance",
         "controls": [
          {
           "id": "7.2.1.1",
           "text": "A policy covering security considerations for cloud services shall be defined, approved, implemented, communicated, periodically reviewed and updated.",
           "key": "CRB:7.2.1.1"
          },
          {
           "id": "7.2.1.2",
           "text": "The cloud security policy shall include: a) controls from technology and operations domain (as applicable) for each type of cloud service; b) management oversight and day-to-day operational responsibility and separation of roles; c) data security requirements considering characteristics such as multi-tenancy, data commingling and processing of data in multiple locations; and d) compliance with data residency requirements.",
           "key": "CRB:7.2.1.2"
          },
          {
           "id": "7.2.1.3",
           "text": "Regulated Entities shall seek approval from CBK at least one month prior to signing any cloud based outsourcing agreements, regarding the use of infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), and software-as-a-service (SaaS) products which directly or indirectly interact with systems involving sensitive data (i.e., customer, financial, transactional, legal, etc.). At a minimum, Regulated Entities shall submit the below information while seeking approval: a) scope of services to be outsourced; b) details of the risk assessment performed and the associated results; c) proposed date to start the engagement and overall engagement period; d) cloud service provider organization name and full address along with key contact details; e) location of data storage; f) operational support being provided by the cloud service provider; g) baseline security controls established by the cloud service provider; h) cloud service provider third-party audit reports; and i) proposed service level and operational level agreements.",
           "key": "CRB:7.2.1.3"
          },
          {
           "id": "7.2.1.4",
           "text": "Branches of foreign banks shall also obtain CBK approval if their use of cloud services, whether contracted directly by the local branch or indirectly through the group-level agreements, involves the processing or storage of sensitive data related to the branch and its customers.",
           "key": "CRB:7.2.1.4"
          }
         ]
        },
        {
         "num": "7.2.2",
         "name": "Cloud Risk Management",
         "controls": [
          {
           "id": "7.2.2.1",
           "text": "Prior to engaging with cloud service providers, Regulated Entities shall determine whether the use of cloud services is consistent with their risk appetite and business strategy and shall conduct information classification for the function or service to be outsourced to identify sensitive data at risk.",
           "key": "CRB:7.2.2.1"
          },
          {
           "id": "7.2.2.2",
           "text": "Regulated Entities shall perform risk assessment that considers the benefits and risks associated with using cloud services and establish mitigation measures, as necessary. The assessment shall consider at a minimum: a) potential impact of any disruption of the cloud service including impact on data availability; b) business continuity and disaster recovery arrangements; c) access management and segregation of responsibilities with respect to cloud services; d) location and data residency; e) business viability, dispute management and arbitration, reputation, experience, exit strategies and conflict of interest; f) sub-contractors (chain of contractors) engaged by cloud service providers; g) limitations to right to audit, right to conduct security assessments and right to inspect (onsite and offsite); and h) sole service providers risks (multiple agreements with same service provider).",
           "key": "CRB:7.2.2.2"
          }
         ]
        },
        {
         "num": "7.2.3",
         "name": "Cloud Providers Oversight and Agreements",
         "controls": [
          {
           "id": "7.2.3.1",
           "text": "Regulated Entities shall review the certifications and independent audits reports (e.g. ISO 27001 / 22301, SSAE16 Reports, Telecommunications Industry Association ANSI/TIA-942 Tier 3/ 4 DC certification, SOC1, SOC2, etc.) of security practices implemented by the cloud service provider.",
           "key": "CRB:7.2.3.1"
          },
          {
           "id": "7.2.3.2",
           "text": "Regulated Entities shall ensure adequate oversight of cloud service providers in order to effectively manage cloud security risks, as part of the overall governance and risk management process.",
           "key": "CRB:7.2.3.2"
          },
          {
           "id": "7.2.3.3",
           "text": "Regulated Entities shall ensure that cloud service providers use latest industry best practice (ISO 27001:2022, ISO 27017: 2015, ISO 27018:2019, NIST Guidelines for Media Sanitization - NIST 800-88) for permanent erasure of data that has been transferred or is no longer needed. Encryption keys shall be also securely destroyed. For storage that cannot be wiped, Regulated Entities shall ensure that cloud service providers uses a destruction process that destroys and renders the recovery of information impossible. Regulated Entities shall ask CSPs to provide Certificate of Destruction (CoD) as a proof of completion and compliance.",
           "key": "CRB:7.2.3.3"
          },
          {
           "id": "7.2.3.4",
           "text": "Regulated Entities shall ensure that a written agreement exist with cloud service providers that include the following requirements: a) scope of services, operational level agreements and clearly defined roles and responsibilities. b) cybersecurity regulatory and legal compliance; c) locations of data storage, business continuity and disaster recovery, data privacy, confidentiality and information sharing, access to data, encryption, data portability, and data retention; d) right to audit and inspect including rights to audit for CBK, or alternatively, the right to access independent third-party assessment reports (i.e., SOC1, SOC2, SOC3 reports, etc.); e) code of conduct and dispute management; f) incident management, crisis management and breach notification strategies; and g) secure termination of agreement.",
           "key": "CRB:7.2.3.4"
          }
         ]
        },
        {
         "num": "7.2.4",
         "name": "Cloud Security Architecture and Compliance",
         "controls": [
          {
           "id": "7.2.4.1",
           "text": "Regulated Entities shall ensure that cloud environments follow a security-first architecture approach, incorporating security principles such as least privilege, defense in depth, and zero trust. a) All cloud services and infrastructure shall be designed to isolate sensitive data and prevent unauthorized access through network segmentation, encryption, and multi- factor authentication (MFA). b) Cloud security architecture shall adhere to industry best practices and comply with relevant regulations and standards, such as ISO 27001:2022, NIST 800-53, and GDPR. c) Any change to the cloud security architecture shall be subject to a formal risk assessment and change management process before deployment.",
           "key": "CRB:7.2.4.1"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 5,
     "section": "8",
     "name": "Payments Security",
     "subdomains": [
      {
       "num": "8.1",
       "name": "Common Security Controls for Electronic Payment Systems",
       "areas": [
        {
         "num": "8.1.1",
         "name": "Policy and Governance",
         "controls": [
          {
           "id": "8.1.1.1",
           "text": "A policy for securing electronic payment systems shall be defined, approved by the board and/or executive/senior management, implemented, reviewed at least annually, and updated.",
           "key": "CRB:8.1.1.1"
          },
          {
           "id": "8.1.1.2",
           "text": "The electronic payment systems policy shall include: a) mechanisms to protect important records and payment infrastructure against unauthorized access and disclosure, misuse, damage, destruction, loss, theft, and manipulation; and b) controls to monitor and assess risks from external parties involved in the payment and settlement systems.",
           "key": "CRB:8.1.1.2"
          },
          {
           "id": "8.1.1.3",
           "text": "Regulated Entities shall conduct annual and ad-hoc independent security audits of the electronic payment systems in accordance with: a) the assessment procedures outlined in the Cybersecurity Testing and Threat Management Sub-Domain; and b) Requirements of industry standards (such as PCI-DSS, EMV) and best practices.",
           "key": "CRB:8.1.1.3"
          }
         ]
        },
        {
         "num": "8.1.2",
         "name": "Digital Onboarding",
         "controls": [
          {
           "id": "8.1.2.1",
           "text": "Regulated Entities shall implement robust identity verification mechanisms to validate customer identities, including government-issued IDs, biometric authentication, or digital ID systems.",
           "key": "CRB:8.1.2.1"
          },
          {
           "id": "8.1.2.2",
           "text": "Digital onboarding processes shall include mechanisms to validate identity documents by: a) verifying physical security measures (e.g., watermarks, holograms); b) comparing data extracted from barcodes and Machine-Readable Zones (MRZ) with Optical Character Recognition (OCR)-extracted data; and c) cross-validating personal details with authoritative sources (e.g., government databases).",
           "key": "CRB:8.1.2.2"
          },
          {
           "id": "8.1.2.3",
           "text": "Regulated Entities shall deploy a digital onboarding technology which shall support liveness detection mechanisms to verify the presence of a live person during onboarding. To ensure authenticity of the biometric data (e.g., face recognition, fingerprint and live selfie matching) shall be performed in alignment with industry standards and best practices (e.g., NIST Face Recognition Vendor Test (FRVT)).",
           "key": "CRB:8.1.2.3"
          },
          {
           "id": "8.1.2.4",
           "text": "Biometric deduplication mechanisms shall be implemented to ensure that customers can enroll only once, preventing duplicate enrollments.",
           "key": "CRB:8.1.2.4"
          },
          {
           "id": "8.1.2.5",
           "text": "Multi-Factor Authentication (MFA) shall be employed during the onboarding process to secure account creation and prevent unauthorized access, including secure methods such as biometrics, device-based authentication, or FIDO2.",
           "key": "CRB:8.1.2.5"
          },
          {
           "id": "8.1.2.6",
           "text": "Automated document verification systems shall validate uploaded documents (e.g., Civil ID, password, proof of address), ensuring data integrity and accuracy. Verified documents shall be securely stored, encrypted, and retained for compliance with legal and regulatory requirements.",
           "key": "CRB:8.1.2.6"
          },
          {
           "id": "8.1.2.7",
           "text": "Fraud detection and prevention systems leveraging advanced technologies (e.g., AI/ML models) shall be implemented to detect anomalies (e.g., synthetic identities, impersonation), and to minimize False Acceptance Rates (FAR) and False Positive Rates (FPR).",
           "key": "CRB:8.1.2.7"
          },
          {
           "id": "8.1.2.8",
           "text": "Location shall be captured during onboarding to be used for fraud detection and address verification.",
           "key": "CRB:8.1.2.8"
          },
          {
           "id": "8.1.2.9",
           "text": "Device geolocation, meta data elements and health checks shall be utilized during onboarding process, along with risk-based policies (e.g., device compliance, location anomalies, Secure Element ID (SEID), device type, source IP and prior fraud indicators) applied to identify potentially high-risk sign-ups or actions.",
           "key": "CRB:8.1.2.9"
          },
          {
           "id": "8.1.2.10",
           "text": "Red flag mechanisms shall be established for high-risk scenarios (e.g., duplicate document submissions, mismatched IP geolocations).",
           "key": "CRB:8.1.2.10"
          },
          {
           "id": "8.1.2.11",
           "text": "Notifications about onboarding activities (e.g., document submission, account creation) shall be sent in timely manner to customers to confirm legitimacy.",
           "key": "CRB:8.1.2.11"
          }
         ]
        },
        {
         "num": "8.1.3",
         "name": "Authentication and Access Management",
         "controls": [
          {
           "id": "8.1.3.1",
           "text": "Regulated Entities shall set the maximum of three failed log-in or authentication attempts after which access to electronic payments systems is (temporarily or permanently) blocked. Regulated Entities shall set procedure in place to re-activate blocked accesses. Reactivation shall be performed with enhanced due diligence and after verifying the identity of the user.",
           "key": "CRB:8.1.3.1"
          },
          {
           "id": "8.1.3.2",
           "text": "Regulated Entities shall ensure secure delivery of customer credentials (user ID, password, PIN), perform authentication of customers’ devices and ensure security of credentials and payment software (web and mobile applications, plugins etc.).",
           "key": "CRB:8.1.3.2"
          },
          {
           "id": "8.1.3.3",
           "text": "All devices used for accessing digital banking services and electronic payment systems shall be continuously verified for compliance with security policies, including OS version, patch levels, and device integrity (e.g., non-jailbroken, unrooted). Devices failing compliance shall have their access dynamically restricted or revoked until remediation is completed and compliance is restored.",
           "key": "CRB:8.1.3.3"
          },
          {
           "id": "8.1.3.4",
           "text": "Regulated Entities shall ensure that personal identity verification measures, such as the personal questions used by the customer service centers for verification of the customer’s identity, are neither generic, nor easy to obtain or repeated (such as banking relations, current balance, information not available on the card, personalized questions, and last transactions). Verification methods may include verification of a registered mobile number combined with a secure PIN, or voice biometrics.",
           "key": "CRB:8.1.3.4"
          },
          {
           "id": "8.1.3.5",
           "text": "Changes to customer sensitive information (such as mobile number and email address) through ATMs, Mobile Applications, Interactive Voice Response (IVR), or Online Banking shall be performed only after establishing authenticity of the customer using Multi Factor Authentication (MFA). In case of change of mobile number, the second factor for authentication shall be sent to the old number. If the old number is inactive or unavailable, alternative verification methods shall be employed, such as biometric authentication or identity verification using government-issued documents (e.g., Civil ID, passport) conducted in-person or at a branch or authorized self-service machine (e.g., Kiosk, ITM).",
           "key": "CRB:8.1.3.5"
          },
          {
           "id": "8.1.3.6",
           "text": "Regulated Entities shall enforce context-aware device re-authentication during changes to customer sensitive information to verify that the requesting device is authorized and uncompromised. Device re-authentication shall include verification of device health, geolocation, and behavior to detect any anomalies or unauthorized attempts.",
           "key": "CRB:8.1.3.6"
          }
         ]
        },
        {
         "num": "8.1.4",
         "name": "Transaction Security",
         "controls": [
          {
           "id": "8.1.4.1",
           "text": "Regulated Entities shall ensure the implementation of effective safeguards to minimize the risk of unauthorized fund transfer based on the channel, technology risks profile, or customer profile or segment.",
           "key": "CRB:8.1.4.1"
          },
          {
           "id": "8.1.4.2",
           "text": "All electronic payments shall have unique transaction reference numbers to enable traceability.",
           "key": "CRB:8.1.4.2"
          },
          {
           "id": "8.1.4.3",
           "text": "Transaction-related messages and notifications (e.g., transaction validation messages, payment confirmations or rejections, MFA messages, error messages, suspicious activity alerts, reminders or updates on transaction limits, etc.) shall not reveal sensitive details or information of the payment systems (infrastructure or application(s)).",
           "key": "CRB:8.1.4.3"
          },
          {
           "id": "8.1.4.4",
           "text": "Regulated Entities shall implement effective measures to notify customers on significant changes to payment profile. Such changes include: a) changes to pre-set values such as password and limits; b) creation of new account linkages; c) registration of new payees; and d) electronic remittances to beneficiaries.",
           "key": "CRB:8.1.4.4"
          },
          {
           "id": "8.1.4.5",
           "text": "Regulated Entities shall adopt secure and internationally recognized strong encryption algorithms for protection of sensitive information (such as login credentials, card information) at rest and in transit.",
           "key": "CRB:8.1.4.5"
          },
          {
           "id": "8.1.4.6",
           "text": "Effective controls shall be implemented to verify and reconcile the integrity of information processed by electronic payment systems (e.g. account balances after transaction updates shall be reconciled between different systems).",
           "key": "CRB:8.1.4.6"
          },
          {
           "id": "8.1.4.7",
           "text": "Effective controls shall be implemented to ensure mitigation of interconnectivity and communication-related risks (e.g., risks include Man-in-the-Middle (MitM) attack, authentication bypass, network sniffing, application-layer attacks, misconfigurations, unauthorized access, etc.).",
           "key": "CRB:8.1.4.7"
          },
          {
           "id": "8.1.4.8",
           "text": "Regulated Entities shall provide appropriate facilities for customers to block their payments cards via self-service options or through customer service centers.",
           "key": "CRB:8.1.4.8"
          }
         ]
        }
       ]
      },
      {
       "num": "8.2",
       "name": "Electronic Payment Transaction Monitoring",
       "areas": [
        {
         "num": "8.2.1",
         "name": "E-Payment Transactions Monitoring and Control",
         "controls": [
          {
           "id": "8.2.1.1",
           "text": "Regulated Entities shall foster a culture of continuous learning by providing access to learning platforms, industry conferences, and knowledge-sharing forums to ensure cybersecurity staff remain up-to-date with evolving threats and technologies.",
           "key": "CRB:8.2.1.1"
          },
          {
           "id": "8.2.1.2",
           "text": "The electronic payment transaction monitoring process shall consider the following risk factors: a) transaction limits (e.g., amount limits, number of transactions per day or session); b) known and emerging fraud scenarios; c) abnormal payment patterns in relation to the customer’s payment transaction history; d) customer transaction preferences and behavioral patterns; e) Geolocation-based risks based on the location of the payer and the payee at the time of the payment transaction; f) Unusual geographic shifts in IP addresses between consecutive transactions or logins that are unrealistic due to the time between events (i.e., occur within a short time period that makes legitimate physical travel impossible given the geographic distance); g) multiple failed authorization attempts; h) velocity checks (i.e., frequency and volume of transactions in a short period); i) changes to sensitive information of customers (e.g., contact details, linked accounts); j) changes in device details, including eSIM profiles, detected shortly before high-risk or suspicious transactions; k) critical data elements provided by third-party wallet providers (e.g., Apple Pay, Google Pay), including tokenized payment data, unique wallet identifiers, device scores, account scores, phone number scores, geolocation data, provisioning and onboarding metadata (e.g., Secure Element ID (SEID), device type, source IP, capture mode); l) device fingerprinting or recognition techniques to detect suspicious devices; and m) cross-channel monitoring (e.g., correlation of activities across online banking, mobile banking, and card transactions); n) Deep/Dark Web monitoring for leaked cards data issued by the Regulated Entity.",
           "key": "CRB:8.2.1.2"
          },
          {
           "id": "8.2.1.3",
           "text": "Unusual or suspicious transactions shall be automatically blocked or flagged for additional verification before processing. Such transactions shall be investigated and reported to customers (if necessary).",
           "key": "CRB:8.2.1.3"
          },
          {
           "id": "8.2.1.4",
           "text": "Regulated Entities shall notify customers through effective communication channels for all transactions performed on their accounts, including rejected transactions. Notifications shall include offline delivery mechanisms (e.g., SMS, phone calls), prioritized for high-risk or time- sensitive transactions or activities (e.g., unusual transactions involving large amounts or abnormal patterns, changes to sensitive customer information, multiple failed login or transaction authorization attempts).",
           "key": "CRB:8.2.1.4"
          },
          {
           "id": "8.2.1.5",
           "text": "Alerts and incident logs related to suspicious transactions shall be handled and managed in accordance with the Regulated Entities internal policies.",
           "key": "CRB:8.2.1.5"
          }
         ]
        },
        {
         "num": "8.2.2",
         "name": "Fraud Management",
         "controls": [
          {
           "id": "8.2.2.1",
           "text": "Regulated Entities shall establish and implement a risk-based fraud management framework, prioritizing detection and mitigation measures based on transaction type, customer risk profile, and payment channel.",
           "key": "CRB:8.2.2.1"
          },
          {
           "id": "8.2.2.2",
           "text": "Regulated Entities shall deploy fraud detection systems capable of analyzing transactions in real-time to identify and block fraudulent activities before completion.",
           "key": "CRB:8.2.2.2"
          },
          {
           "id": "8.2.2.3",
           "text": "Regulated Entities shall implement automated detection tools using AI or ML models to improve the detection of potential fraud attempts and continuously adapt to evolving risks.",
           "key": "CRB:8.2.2.3"
          },
          {
           "id": "8.2.2.4",
           "text": "Fraud response playbook shall be developed, including defined procedures for managing and handling fraud incidents. These playbooks shall cover examples of fraud scenarios such as account takeover through phishing, SIM-swapping, or eSIM-related fraud (e.g., cloning of eSIM, unauthorized activation); unauthorized payment transactions; social engineering schemes using AI chatbots or spoofed banking applications; digital payment fraud involving Quick Response (QR) code manipulation or fake merchant accounts; synthetic identity fraud involving the use of AI-generated identities; and deepfake-enabled fraud.",
           "key": "CRB:8.2.2.4"
          },
          {
           "id": "8.2.2.5",
           "text": "Fraud playbook shall be reviewed and updated at least annually, or more frequently as new fraud trends or regulatory requirements emerge, to ensure it remains effective and compliant.",
           "key": "CRB:8.2.2.5"
          },
          {
           "id": "8.2.2.6",
           "text": "Fraud risks arising from third-party service providers involved in payment processing, such as gateways and/or aggregators, shall be assessed and mitigated. This shall be part of the Entity’s risk assessment process.",
           "key": "CRB:8.2.2.6"
          },
          {
           "id": "8.2.2.7",
           "text": "Regulated Entities shall participate in industry-wide fraud threat intelligence sharing initiatives to remain informed about emerging fraud tactics and strengthen collaborative defenses, and improve sector-wide resilience.",
           "key": "CRB:8.2.2.7"
          }
         ]
        }
       ]
      },
      {
       "num": "8.3",
       "name": "Digital Banking Security",
       "areas": [
        {
         "num": "8.3.1",
         "name": "Online and Mobile Banking Security",
         "controls": [
          {
           "id": "8.3.1.1",
           "text": "Online banking systems and mobile banking applications shall be configured to ensure that: a) user sessions terminate automatically after a maximum of five minutes of inactivity and should be greyed-out or cleared from any sensitive information related to customer account being displayed; and b) concurrent sessions are disallowed.",
           "key": "CRB:8.3.1.1"
          },
          {
           "id": "8.3.1.2",
           "text": "Validity of One-Time Passwords (OTPs) is restricted to a maximum of two minutes. Regulated Entities shall enforce session revalidation mechanisms to ensure continuous validity of user sessions. Revalidation shall be triggered based on pre-defined intervals, changes in session context (e.g., IP address or geolocation anomalies, unusual session activity), or prolonged inactivity. Revalidation shall involve secure identity verification through MFA, biometrics, or other context-aware measures.",
           "key": "CRB:8.3.1.2"
          },
          {
           "id": "8.3.1.3",
           "text": "Regulated Entities shall establish reliable and effective authentication measures by implementing strong Multi-Factor Authentication (MFA) controls to secure access and out- of-band verification methods to authorize critical actions, such as account activation, financial transactions (e.g., fund transfers, bill payments), and beneficiary addition, using the following: a) OTP generated by third-party authenticator apps; b) In-app push notification with biometric or PIN approval (for mobile apps only); or c) Device-based authorization (e.g., FIDO2) tied to a registered mobile device (for mobile apps only).",
           "key": "CRB:8.3.1.3"
          },
          {
           "id": "8.3.1.4",
           "text": "Regulated Entities may adopt other secure and innovative OTP delivery technologies as they evolve and emerge, subject to prior evaluation and approval by CBK.",
           "key": "CRB:8.3.1.4"
          },
          {
           "id": "8.3.1.5",
           "text": "Regulated Entities shall obtain and document customer consent for their preferred OTP delivery method during the onboarding process or as part of profile updates. Customers shall be provided with the option to review and update their preferences at any time.",
           "key": "CRB:8.3.1.5"
          },
          {
           "id": "8.3.1.6",
           "text": "Online banking platforms shall implement anti-phishing controls to identify and validate the user (e.g., username), verify the authenticity of the application (e.g., pre- logon challenge questions, site key, multi-screen authentication, etc.), and authenticate the user with a password as part of the authentication process.",
           "key": "CRB:8.3.1.6"
          },
          {
           "id": "8.3.1.7",
           "text": "Regulated Entities shall implement controls to prevent installation and block usage of mobile banking applications on jail-broken or rooted devices.",
           "key": "CRB:8.3.1.7"
          },
          {
           "id": "8.3.1.8",
           "text": "Regulated Entities shall ensure that the mobile banking application encrypts all data stored, if any, locally by the application on the customer devices.",
           "key": "CRB:8.3.1.8"
          },
          {
           "id": "8.3.1.9",
           "text": "Regulated Entities shall ensure that the mobile banking application verifies the customer’s mobile number and employs device authentication mechanisms, such as device fingerprinting, certificate-based authentication, or other advanced device authentication methods for first-time use of applications.",
           "key": "CRB:8.3.1.9"
          },
          {
           "id": "8.3.1.10",
           "text": "Customers may be allowed to access mobile banking application from a limited number of validated devices, up to three. Regulated Entities may permit an increase in the number of allowed validated devices, up to six, provided that strong risk mitigation controls are in place (e.g., strong authentication mechanisms: MFA, biometric verification), device attestation, continuous monitoring and behavioral analysis, periodic revalidation of all registered devices.",
           "key": "CRB:8.3.1.10"
          },
          {
           "id": "8.3.1.11",
           "text": "Regulated Entities shall enforce periodic revalidation of all registered devices at least every six (6) months for high-risk accounts and annually for other accounts. The revalidation process shall include: a) Customer confirmation of each registered device through secure channels, such as in- app notifications, OTP-based authentication, or biometric authentication; b) Device attestation checks to verify the security posture of each device (e.g., non-rooted or -jailbroken status, updated OS, encryption enabled); and c) Automatic deregistration of devices that fail revalidation or remain unvalidated after a period of (30) days, or are deemed inactive for more than six (6) months. Notifications shall be sent to customers regarding any actions taken on unvalidated devices.",
           "key": "CRB:8.3.1.11"
          },
          {
           "id": "8.3.1.12",
           "text": "Customers shall have an option to deactivate any of the registered devices remotely through either the mobile banking application or online banking platform. Notifications shall be sent to customers for all device-related activities (i.e., new device registrations, validations, and deactivations).",
           "key": "CRB:8.3.1.12"
          },
          {
           "id": "8.3.1.13",
           "text": "The mobile banking application shall provide biometric authentication (e.g., fingerprint or facial recognition) as an option for user login, where supported.",
           "key": "CRB:8.3.1.13"
          },
          {
           "id": "8.3.1.14",
           "text": "Regulated Entities shall conduct periodic security assessments, to identify and remediate vulnerabilities associated with their online banking platforms and mobile banking applications, including vulnerability assessments and penetration testing.",
           "key": "CRB:8.3.1.14"
          },
          {
           "id": "8.3.1.15",
           "text": "The Regulated Entities shall ensure that appropriate procedures and security measures are in place to validate the identity of all users enrolled remotely or through non-face-to-face channels.",
           "key": "CRB:8.3.1.15"
          }
         ]
        },
        {
         "num": "8.3.2",
         "name": "Open Banking Security",
         "controls": [
          {
           "id": "8.3.2.1",
           "text": "Regulated Entities shall establish robust access control mechanisms to ensure that only authorized third-party providers (TPPs) can access customer data, and that customers have adequate control over the permissions granted to TPPs, in line with CBK Open Banking Framework.",
           "key": "CRB:8.3.2.1"
          },
          {
           "id": "8.3.2.2",
           "text": "Regulated Entities shall ensure that only essential customer data is shared with TPPs, and explicit consent shall be obtained from customers for data sharing.",
           "key": "CRB:8.3.2.2"
          },
          {
           "id": "8.3.2.3",
           "text": "Regulated Entities shall conduct thorough risk assessments of third-party providers (TPPs) prior to granting them access to customer data, to ensure that TPPs meet the required security standards.",
           "key": "CRB:8.3.2.3"
          },
          {
           "id": "8.3.2.4",
           "text": "Regulated Entities shall ensure that open banking Application Programming Interfaces (APIs) are developed, deployed and maintained with sufficient security measures focusing on input validation, secure communications and rate limiting, in line with CBK Open Banking Framework.",
           "key": "CRB:8.3.2.4"
          },
          {
           "id": "8.3.2.5",
           "text": "Regulated Entities shall ensure that real-time monitoring of open banking APIs is implemented, to detect and respond to any unauthorized access or unusual activity.",
           "key": "CRB:8.3.2.5"
          },
          {
           "id": "8.3.2.6",
           "text": "Regulated Entities shall ensure that open banking APIs and related infrastructure are resilient to operational failures, with adequate redundancy measures implemented to maintain service availability.",
           "key": "CRB:8.3.2.6"
          },
          {
           "id": "8.3.2.7",
           "text": "Regulated Entities shall periodically assess the security of open banking APIs, by conducting penetration testing and vulnerability assessments, to identify and mitigate any potential security risks.",
           "key": "CRB:8.3.2.7"
          },
          {
           "id": "8.3.2.8",
           "text": "Regulated Entities shall maintain detailed logs of all API access, consent transactions and data sharing events related to open banking systems. These logs should be sufficiently protected and be periodically reviewed as part of internal audits and regulatory inspections.",
           "key": "CRB:8.3.2.8"
          },
          {
           "id": "8.3.2.9",
           "text": "Regulated Entities shall provide customers with adequate awareness regarding open banking, including guidance on managing permissions and access, as well as recognizing potential fraud.",
           "key": "CRB:8.3.2.9"
          }
         ]
        },
        {
         "num": "8.3.3",
         "name": "Digital Wallets Security",
         "controls": [
          {
           "id": "8.3.3.1",
           "text": "Digital wallets shall enforce MFA for registration, first-time login, and critical actions, such as adding or modifying a payment method, changing account settings, managing authorized devices linked to the wallet, or making high-risk transactions.",
           "key": "CRB:8.3.3.1"
          },
          {
           "id": "8.3.3.2",
           "text": "Regulated Entities shall verify and register devices to access digital wallets through device- binding, ensuring that wallet access and transactions are restricted to a pre-authorized registered device.",
           "key": "CRB:8.3.3.2"
          },
          {
           "id": "8.3.3.3",
           "text": "Digital wallets shall block usage on jail-broken or rooted devices.",
           "key": "CRB:8.3.3.3"
          },
          {
           "id": "8.3.3.4",
           "text": "Tokenization shall be used for processing and storing payment data.",
           "key": "CRB:8.3.3.4"
          },
          {
           "id": "8.3.3.5",
           "text": "APIs and payment gateways used by digital wallets shall strictly adhere to secure development practices, and shall undergo periodic vulnerability assessments and penetration testing, following the defined intervals.",
           "key": "CRB:8.3.3.5"
          },
          {
           "id": "8.3.3.6",
           "text": "Regulated Entities shall ensure that customers can remotely disable digital wallets or unlink devices from the wallet in case of device theft, loss, or compromise.",
           "key": "CRB:8.3.3.6"
          }
         ]
        }
       ]
      },
      {
       "num": "8.4",
       "name": "Payment Card Data Security",
       "areas": [
        {
         "num": "8.4.1",
         "name": "Payment Card Data Protection",
         "controls": [
          {
           "id": "8.4.1.1",
           "text": "Regulated Entities shall ensure compliance to applicable regulations, industry standards, and best practices (e.g., PCI-DSS, PCI PTS, PCI SSF, EMV) for protecting payment card information and related systems.",
           "key": "CRB:8.4.1.1"
          },
          {
           "id": "8.4.1.2",
           "text": "Complete card number shall never be part of or included in any communication with the customers.",
           "key": "CRB:8.4.1.2"
          },
          {
           "id": "8.4.1.3",
           "text": "Card PIN generation shall be secured through strong cryptographic processes so as to restrict access to PIN only to the intended recipient.",
           "key": "CRB:8.4.1.3"
          },
          {
           "id": "8.4.1.4",
           "text": "Cardholder data shall be tokenized or encrypted at rest or in transit.",
           "key": "CRB:8.4.1.4"
          }
         ]
        }
       ]
      },
      {
       "num": "8.5",
       "name": "Security of Customer Self-Service Machines",
       "areas": [
        {
         "num": "8.5.1",
         "name": "Physical and Environmental Security of Customer Self-Service Machines",
         "controls": [
          {
           "id": "8.5.1.1",
           "text": "Regulated Entities shall implement physical security measures to protect customer self- service machines from theft, damage, tampering, etc.",
           "key": "CRB:8.5.1.1"
          },
          {
           "id": "8.5.1.2",
           "text": "Regulated Entities shall implement anti-skimming, tamper detection, and other security measures on Customer Self- Service Machines.",
           "key": "CRB:8.5.1.2"
          },
          {
           "id": "8.5.1.3",
           "text": "Regulated Entities shall undertake physical inspection of Customer Self Service Machines and their locations at least quarterly to verify the effectiveness of implemented security measures, identify security gaps, and ensure compliance.",
           "key": "CRB:8.5.1.3"
          }
         ]
        },
        {
         "num": "8.5.2",
         "name": "Transaction and Customer Data Security",
         "controls": [
          {
           "id": "8.5.2.1",
           "text": "Customer self-service machines shall authenticate customer transactions using a combination of card (e.g. debit card, credit card, tokenized card, civil ID) and PIN (static or one-time) numbers as applicable.",
           "key": "CRB:8.5.2.1"
          },
          {
           "id": "8.5.2.2",
           "text": "Segregation of duties controls shall be implemented for card processing, PIN generation, and delivery of the card and PIN to the customer. Regulated Entities shall ensure that the card is issued in an inactive state and the process is established for activation.",
           "key": "CRB:8.5.2.2"
          },
          {
           "id": "8.5.2.3",
           "text": "The Regulated Entities shall block the card upon three unsuccessful attempts of PIN usage and promptly notify the customer to prevent potential misuse. Requests for activation of such cards shall be undertaken with enhanced authentication and verification procedures, applying diligence through secure channels.",
           "key": "CRB:8.5.2.3"
          }
         ]
        }
       ]
      },
      {
       "num": "8.6",
       "name": "Contactless Payment Technology Security",
       "areas": [
        {
         "num": "8.6.1",
         "name": "Contactless Payment Security Controls",
         "controls": [
          {
           "id": "8.6.1.1",
           "text": "Regulated Entities shall conduct risk assessment to identify risks due to use of NFC-enabled cards, QR-based payments, and other contactless technologies and implement appropriate controls to mitigate identified risks.",
           "key": "CRB:8.6.1.1"
          },
          {
           "id": "8.6.1.2",
           "text": "Regulated Entities shall define and enforce appropriate limits on number and value of NFC transactions. Additional authentication (e.g., PIN, biometric) shall be required for transactions exceeding the defined limits.",
           "key": "CRB:8.6.1.2"
          },
          {
           "id": "8.6.1.3",
           "text": "Regulated Entities shall notify customers through effective communication channels in real- time for transactions performed using contactless technologies.",
           "key": "CRB:8.6.1.3"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 6,
     "section": "9",
     "name": "Operational Resilience",
     "subdomains": [
      {
       "num": "9.1",
       "name": "Business Continuity and Disaster Recovery (BC and DR)",
       "areas": [
        {
         "num": "9.1.1",
         "name": "Business Continuity and Disaster Recovery Planning and Management",
         "controls": [
          {
           "id": "9.1.1.1",
           "text": "Business Continuity, Disaster Recovery (BC/DR), Business Impact Analysis (BIA), Threat Risk Assessments (TRAs), Recovery processes and plans shall be documented, approved, implemented, reviewed and updated annually or upon significant changes.",
           "key": "CRB:9.1.1.1"
          },
          {
           "id": "9.1.1.2",
           "text": "Business Continuity Plans (BCPs) and Disaster Recovery Plans (DRPs) shall be established for individual business units, and integrated into the overall Entity-wide plans.",
           "key": "CRB:9.1.1.2"
          },
          {
           "id": "9.1.1.3",
           "text": "Regulated Entities shall define the Recovery Time Objectives (RTOs), Recovery Point Objectives (RPOs), and Maximum Tolerable Downtime (MTD) for critical systems and functions.",
           "key": "CRB:9.1.1.3"
          },
          {
           "id": "9.1.1.4",
           "text": "An alternate recovery site shall be identified for restoration of critical systems and business operations. This alternate site shall be geographically separate from the primary site.",
           "key": "CRB:9.1.1.4"
          },
          {
           "id": "9.1.1.5",
           "text": "Required work recovery procedures, recovery manuals, and contact lists (including names and phone numbers of the external service providers and relevant staff) shall be up-to-date and made available at the recovery site. These lists shall be reviewed and updated at least annually or more often as required.",
           "key": "CRB:9.1.1.5"
          },
          {
           "id": "9.1.1.6",
           "text": "Recovery strategies shall be defined and approved, entailing: a) activities to be performed during various crisis scenarios, including cyber attacks; b) technology or manual workarounds; c) roles and responsibilities; and d) communication channels and protocols for updating concerned stakeholders on an ongoing basis.",
           "key": "CRB:9.1.1.6"
          }
         ]
        },
        {
         "num": "9.1.2",
         "name": "Backup and Recovery Management",
         "controls": [
          {
           "id": "9.1.2.1",
           "text": "A backup strategy shall be defined, approved, implemented, reviewed and updated annually or upon significant changes. The strategy shall include: a) backup periodicity; b) secure storage and disposal mechanisms; and c) security measures to protect information and backup media, including from cyber incidents.",
           "key": "CRB:9.1.2.1"
          },
          {
           "id": "9.1.2.2",
           "text": "Information shall be backed up per the approved backup strategy, stored and retained according to the applicable regulatory requirements and laws.",
           "key": "CRB:9.1.2.2"
          },
          {
           "id": "9.1.2.3",
           "text": "Backups shall be periodically tested, at least quarterly, for selective critical systems leading to testing backups of all critical systems within one year, for recoverability to ensure integrity and completeness of backed-up data.",
           "key": "CRB:9.1.2.3"
          }
         ]
        },
        {
         "num": "9.1.3",
         "name": "Critical Services and Dependencies Management",
         "controls": [
          {
           "id": "9.1.3.1",
           "text": "Regulated Entities shall identify and document all critical services and their dependencies, including internal systems, third-party vendors, and supply chain components.",
           "key": "CRB:9.1.3.1"
          },
          {
           "id": "9.1.3.2",
           "text": "Interdependencies among critical services shall be assessed, at least annually, to identify single points of failure and mitigate risks.",
           "key": "CRB:9.1.3.2"
          },
          {
           "id": "9.1.3.3",
           "text": "Third-party service providers supporting critical services shall be subject to annual risk assessments.",
           "key": "CRB:9.1.3.3"
          },
          {
           "id": "9.1.3.4",
           "text": "Service Level Agreements (SLAs) with critical service providers shall include requirements for operational resilience, RTOs, and breach notification.",
           "key": "CRB:9.1.3.4"
          },
          {
           "id": "9.1.3.5",
           "text": "Contingency plans shall be established for critical service failures, including redundancy mechanisms or alternative providers.",
           "key": "CRB:9.1.3.5"
          }
         ]
        },
        {
         "num": "9.1.4",
         "name": "Testing and Validation",
         "controls": [
          {
           "id": "9.1.4.1",
           "text": "Periodic restoration tests, at least annually, shall be conducted on the backed-up information to validate the effectiveness and completeness of the backups.",
           "key": "CRB:9.1.4.1"
          },
          {
           "id": "9.1.4.2",
           "text": "Regulated Entities shall conduct annual business continuity and disaster recovery exercises and tests (e.g. BCP drill, failovers), to ensure the effectiveness of recovery strategies and operational continuity. All critical systems, core activities and system support, and business users involved in these processes shall be part of these tests.",
           "key": "CRB:9.1.4.2"
          },
          {
           "id": "9.1.4.3",
           "text": "Business continuity and disaster recovery test results and deviations, if any, shall be documented with the appropriate action/mitigation plans. The documented outcomes and action plans shall be signed off by Executive/Senior Management.",
           "key": "CRB:9.1.4.3"
          },
          {
           "id": "9.1.4.4",
           "text": "Tabletop exercises shall be conducted annually to assess the effectiveness of recovery methods, validate scenario readiness, and ensure the practicality of action plans.",
           "key": "CRB:9.1.4.4"
          },
          {
           "id": "9.1.4.5",
           "text": "The alternate recovery site shall have physical security and access controls in accordance with Regulated Entity’s Risk Management process.",
           "key": "CRB:9.1.4.5"
          },
          {
           "id": "9.1.4.6",
           "text": "In addition to business continuity and disaster recovery testing, Regulated Entities should also consider establishing a comprehensive operational resilience testing program focusing on the ability of the organization to withstand and recover from cyber incidents, operational disruptions and third-party failures.",
           "key": "CRB:9.1.4.6"
          },
          {
           "id": "9.1.4.7",
           "text": "Regulated Entities shall ensure that the comprehensive operational resilience testing program covers all critical business services and processes, with any interdependencies identified and managed appropriately.",
           "key": "CRB:9.1.4.7"
          },
          {
           "id": "9.1.4.8",
           "text": "Regulated Entities shall ensure to perform scenario-based testing to simulate a wide range of disruption scenarios, including cyber incidents, and the results of these tests should be documented for evaluation and continuous improvement.",
           "key": "CRB:9.1.4.8"
          },
          {
           "id": "9.1.4.9",
           "text": "Regulated Entities shall perform operational resilience testing at minimum annually, or when significant changes in the operating environment occur requiring the operational recovery capabilities to be assessed again.",
           "key": "CRB:9.1.4.9"
          },
          {
           "id": "9.1.4.10",
           "text": "Regulated Entities shall ensure that any critical third parties / vendors are considered in the operational resilience testing program to ensure the recovery capabilities and impact of third-party failures are evaluated.",
           "key": "CRB:9.1.4.10"
          }
         ]
        }
       ]
      },
      {
       "num": "9.2",
       "name": "Cyber Crisis Management",
       "areas": [
        {
         "num": "9.2.1",
         "name": "Crisis Management Planning and Governance",
         "controls": [
          {
           "id": "9.2.1.1",
           "text": "Regulated Entities shall maintain updated crisis management plans that support their enterprise resilience, including cyber crisis management planning as an integrated component. These plans shall be: a) approved by the Board or Executive/Senior Management; b) implemented enterprise-wide to ensure coverage of key organizational functions, authorities, and responsibilities; c) aligned with legal, regulatory, and organizational requirements; d) aligned with operational risk management considerations (e.g., disaster recovery, business continuity, and communications [internal/external] policies, plans, procedures, and templates).",
           "key": "CRB:9.2.1.1"
          },
          {
           "id": "9.2.1.2",
           "text": "Regulated Entities shall define a Crisis Management Team that integrates the technical, business, and management functions of the Regulated Entities.",
           "key": "CRB:9.2.1.2"
          },
          {
           "id": "9.2.1.3",
           "text": "Crisis Management Team shall be led by the Crisis Response Lead and comprise empowered representatives specifically from Operations, Information Technology, Information Security, Legal, and Communications. The team shall: a) develop, maintain, promote, and exercise crisis management planning; b) assist the Crisis Response Lead to assess whether an incident with crisis level impact exists and whether a formal response is required; c) mobilize and deploy necessary internal and external resources to deliver the response; d) oversee execution of response activities; and e) manage the communication with internal and external stakeholders throughout a crisis management life-cycle.",
           "key": "CRB:9.2.1.3"
          },
          {
           "id": "9.2.1.4",
           "text": "Regulated Entities shall ensure that the Crisis Response Lead : a) holds a senior executive position with the authority to make strategic decisions; b) have skills and experience to understand the Regulated Entity’s operations and to and to be able to manage crisis; and c) have an appointed deputy in the absence of the lead.",
           "key": "CRB:9.2.1.4"
          },
          {
           "id": "9.2.1.5",
           "text": "A cyber crisis management process shall be documented, approved, tested, reviewed and updated annually or upon significant changes. The process shall: a) address operational risk management considerations (e.g., disaster recovery, business continuity, and communications (internal/external) policies, plans, procedures, and templates); and b) cover the entire enterprise to ensure coverage of key organizational functions, authorities, and responsibilities.",
           "key": "CRB:9.2.1.5"
          },
          {
           "id": "9.2.1.6",
           "text": "Regulated Entities shall define a severity impact matrix that is approved by their Board or Executive/Senior Management. The severity impact matrix shall: a) consider the outcomes of entity specific business impact analyses, internal assessments, and risk analyses; b) tier the impact to the Regulated Entities (e.g., low, medium, high; minor, moderate, severe; etc.) across their categories of significant consideration in alignment with the sectoral severity impact matrix defined in CBK Operational Resilience Baselines, and Entity’s specific defined risk appetite; and c) specify the appropriate mitigating actions for each impact tier.",
           "key": "CRB:9.2.1.6"
          }
         ]
        },
        {
         "num": "9.2.2",
         "name": "Crisis Response and Communication",
         "controls": [
          {
           "id": "9.2.2.1",
           "text": "Regulated Entities shall implement and maintain appropriate tools and threat intelligence feeds from internal systems and third-party providers to assist the Regulated Entities in initiating enterprise-wide risk response efforts whenever necessary.",
           "key": "CRB:9.2.2.1"
          },
          {
           "id": "9.2.2.2",
           "text": "Regulated Entities shall implement emergency notification mechanisms to support timely contact with responders and employees in the event of an incident with crisis-level impact.",
           "key": "CRB:9.2.2.2"
          },
          {
           "id": "9.2.2.3",
           "text": "Regulated Entities shall implement crisis management response tools (e.g., a decision and action logging capability) to create an auditable trail of response considerations and assist in improvements based on lessons learned.",
           "key": "CRB:9.2.2.3"
          },
          {
           "id": "9.2.2.4",
           "text": "Regulated Entities shall report incidents, impacting confidentiality, integrity, and/or availability, regardless whether the root cause is cyber or not, to CBK in accordance with the timelines defined in CBK Operational Resilience Baselines, corresponding to the incident severity rating.",
           "key": "CRB:9.2.2.4"
          },
          {
           "id": "9.2.2.5",
           "text": "Regulated Entities shall update CBK on the situation/progress of the reported incidents in accordance with the timelines defined in CBK Operational Resilience Baselines.",
           "key": "CRB:9.2.2.5"
          },
          {
           "id": "9.2.2.6",
           "text": "Regulated Entities shall report incidents in accordance with the predefined templates and communication channels outlined in CBK Operational Resilience Baselines.",
           "key": "CRB:9.2.2.6"
          },
          {
           "id": "9.2.2.7",
           "text": "Regulated Entities shall identify and escalate incidents that meet the criteria for crisis-level event within the defined timeframe as defined and determined in CBK Operational Resilience Baselines.",
           "key": "CRB:9.2.2.7"
          },
          {
           "id": "9.2.2.8",
           "text": "Regulated Entities shall participate and collaborate for sectoral crisis responses based on assessed severity and action/s initiated by CBK.",
           "key": "CRB:9.2.2.8"
          }
         ]
        },
        {
         "num": "9.2.3",
         "name": "Training, Testing, and Continuous Improvement",
         "controls": [
          {
           "id": "9.2.3.1",
           "text": "Regulated Entities shall adopt a continuous learning model to promote ongoing improvements in future readiness for cyber incidents.",
           "key": "CRB:9.2.3.1"
          },
          {
           "id": "9.2.3.2",
           "text": "Regulated Entities shall provide: a) regular training, at least annually, appropriate to crisis responders’ roles in crisis response; and b) ad-hoc training if there is any change to the Regulated Entity’s response process.",
           "key": "CRB:9.2.3.2"
          },
          {
           "id": "9.2.3.3",
           "text": "Regulated Entities shall conduct cyber crisis exercises on an annual basis to ensure relevance and effectiveness of cyber crisis management plans, procedures, and response infrastructure.",
           "key": "CRB:9.2.3.3"
          },
          {
           "id": "9.2.3.4",
           "text": "Regulated Entities shall participate in CBK-organized sector-wide crisis exercises focused on cyber and other relevant crisis scenarios.",
           "key": "CRB:9.2.3.4"
          }
         ]
        }
       ]
      }
     ]
    }
   ],
   "counts": {
    "domains": 6,
    "subdomains": 33,
    "control_areas": 86,
    "controls": 516
   },
   "official_counts": {
    "domains": 6,
    "subdomains": 33,
    "control_areas": 87,
    "controls": 519
   }
  },
  {
   "code": "ORB",
   "name": "Operational Resilience Baselines",
   "domains": [
    {
     "domain": 1,
     "section": "3",
     "name": "Governance and Oversight",
     "subdomains": [
      {
       "num": "3.1",
       "name": "Operational Resilience Governance Structure and Oversight",
       "areas": [
        {
         "num": "3.1.1",
         "name": "Board of Directors",
         "controls": [
          {
           "id": "3.1.1.1",
           "text": "The Board of Directors (hereinafter referred as, the Board), of Regulated Entities shall be the approving authority for the operational resilience strategy and shall provide authorization for the Operational Resilience policy.",
           "key": "ORB:3.1.1.1"
          },
          {
           "id": "3.1.1.2",
           "text": "The Board may delegate certain responsibilities to relevant committees or independent functions, however, the Board shall retain ultimate accountability for the Entity’s overall operational resilience and shall be reviewed at least annually as part of its formal meetings.",
           "key": "ORB:3.1.1.2"
          },
          {
           "id": "3.1.1.3",
           "text": "The Board shall be accountable, including approving risk appetite and tolerance levels, and ensuring strategic oversight of evolving operational resilience trends and threats.",
           "key": "ORB:3.1.1.3"
          },
          {
           "id": "3.1.1.4",
           "text": "The Board shall ensure the allocation of adequate budget and resources to execute the required operational resilience activities.",
           "key": "ORB:3.1.1.4"
          },
          {
           "id": "3.1.1.5",
           "text": "The Board shall receive regular updates from the Operational Resilience Steering Committee on the overall status of the baseline, as well as additional updates as needed on emerging threats or significant changes in the threat landscape. Additionally, the Board, shall be informed and kept updated on any legal or regulatory implications of operational risks.",
           "key": "ORB:3.1.1.5"
          }
         ]
        },
        {
         "num": "3.1.2",
         "name": "Operational Resilience Steering Committee",
         "controls": [
          {
           "id": "3.1.2.1",
           "text": "The Operational Resilience Steering Committee shall be established with the participation of: a) The head of the Operational Resilience function; b) Executives and Senior Managers from all relevant departments/ functions (i.e.,CxOs, relevant business functions, and compliance); and",
           "key": "ORB:3.1.2.1"
          },
          {
           "id": "3.1.2.2",
           "text": "The Operational Resilience Steering Committee shall be chaired by a designated senior executive with relevant expertise and sufficient operational resilience knowledge.",
           "key": "ORB:3.1.2.2"
          },
          {
           "id": "3.1.2.3",
           "text": "The committee shall develop a charter that is approved by the Board. The charter must include, at a minimum: a) The committee’s objective; b) The committee members; and c) The frequency and quorum of meetings, with meetings held at least four (4) times a year.",
           "key": "ORB:3.1.2.3"
          },
          {
           "id": "3.1.2.4",
           "text": "The Board may delegate specific operational resilience related responsibilities to this Operational Resilience Steering Committee, which shall be established and mandated by the Board. These responsibilities shall be limited to advisory, oversight, and some operational coordination functions. This committee shall not have the authority to approve strategic decisions, such as the operational resilience strategy or risk appetite",
           "key": "ORB:3.1.2.4"
          },
          {
           "id": "3.1.2.5",
           "text": "The Operational Resilience Steering Committee shall: a) Review and endorse on the Operational Resilience strategy, Operational Resilience policy, Business Impact Analysis, Risk Assessment Consolidation Report, Crisis Management Plan and Recovery Strategy Report; b) Monitor the effectiveness of operational resilience activities through Key Risk Indicators (KRIs), Key Performance Indicators (KPIs) and resource-allocation status; c) Recommend the regulated entity’s impact-tolerance levels and confirm alignment of those tolerances with overall business objectives and risk appetite; d) Oversee incident and crisis response readiness, including post-incident reviews, lessons-learned and closure of remediation actions; e) Oversee testing, exercising, and training plans to ensure they address technology, cyber, supply-chain, and people disruptions, with results used to drive continual improvement; and f) Stay updated on emerging threats, regulatory changes, and ensure compliance.",
           "key": "ORB:3.1.2.5"
          }
         ]
        },
        {
         "num": "3.1.3",
         "name": "Executive/Senior Management",
         "controls": [
          {
           "id": "3.1.3.1",
           "text": "Executive/Senior Management shall be the approving authority of operational resilience policy, operational resilience initiatives supporting the strategy approved by the Board, and resilience tolerance levels.",
           "key": "ORB:3.1.3.1"
          },
          {
           "id": "3.1.3.2",
           "text": "Executive/Senior Management, including CEO and other C-level executives, shall support the effective execution of operational resilience strategy.",
           "key": "ORB:3.1.3.2"
          },
          {
           "id": "3.1.3.3",
           "text": "Executive/Senior Management shall be responsible for implementing operational resilience strategies, ensuring active alignment with the approved risk appetite and tolerance levels, and continuously adapting the entity’s operational resilience posture to evolving trends and threats.",
           "key": "ORB:3.1.3.3"
          },
          {
           "id": "3.1.3.4",
           "text": "Executive/Senior Management shall allocate proper operational resilience budget, define, and assign roles and responsibilities with relevant expertise and in alignment with ORB requirements, and continually promote a resilience culture throughout the Regulated Entity.",
           "key": "ORB:3.1.3.4"
          },
          {
           "id": "3.1.3.5",
           "text": "Executive/Senior Management shall approve the size and resources of the Operational Resilience function.",
           "key": "ORB:3.1.3.5"
          },
          {
           "id": "3.1.3.6",
           "text": "Executive/Senior Management shall ensure the alignment and implementation of operational resilience policies and standards, developed by the Operational Resilience function, across all business functions.",
           "key": "ORB:3.1.3.6"
          }
         ]
        },
        {
         "num": "3.1.4",
         "name": "Operational Resilience Function",
         "controls": [
          {
           "id": "3.1.4.1",
           "text": "Regulated Entities shall establish an Operational Resilience Function that is independent of business operations, empowered by the Board, with oversight from the Operational Resilience Steering Committee and in alignment with the Cyber Resilience function. The function shall be headed by a designated Head of Operational Resilience with proven expertise in resilience-related disciplines",
           "key": "ORB:3.1.4.1"
          },
          {
           "id": "3.1.4.2",
           "text": "The size of the Operational Resilience Function shall be determined based on the complexity, nature of business, technology assets, and complexity of operations.",
           "key": "ORB:3.1.4.2"
          },
          {
           "id": "3.1.4.3",
           "text": "The head of the Operational Resilience Function shall be responsible for defining and reviewing the operational resilience strategy.",
           "key": "ORB:3.1.4.3"
          },
          {
           "id": "3.1.4.4",
           "text": "Regulated Entities shall hold the Operational Resilience Function accountable for implementing, maintaining, and coordination of the operational resilience baseline across all relevant domains",
           "key": "ORB:3.1.4.4"
          },
          {
           "id": "3.1.4.5",
           "text": "The Operational Resilience Function shall provide overarching oversight over all functions that support the continuity and recovery of critical business service.",
           "key": "ORB:3.1.4.5"
          },
          {
           "id": "3.1.4.6",
           "text": "The Operational Resilience Function shall be responsible for managing the business continuity activities across the Regulated Entity.",
           "key": "ORB:3.1.4.6"
          },
          {
           "id": "3.1.4.7",
           "text": "The Operational Resilience Function shall ensure that operational resilience awareness and training programs are effectively provided/ delivered to all employees, contractors, and relevant third-party vendors.",
           "key": "ORB:3.1.4.7"
          },
          {
           "id": "3.1.4.8",
           "text": "The Operational Resilience Function shall update the Operational Resilience Steering Committee at least quarterly, or on a need basis, whenever there are any changes or emerging risks that require attention, about the overall status of their program.",
           "key": "ORB:3.1.4.8"
          },
          {
           "id": "3.1.4.9",
           "text": "The Operational Resilience Function shall consolidate the results for the Business Impact Analysis, Technology Impact Analysis, Risk Assessment, Business Continuity Plan, IT Disaster Recovery Plan, incident and crisis management plans and Recovery strategies report and report them to the Executive/Senior Management for approval.",
           "key": "ORB:3.1.4.9"
          }
         ]
        }
       ]
      },
      {
       "num": "3.2",
       "name": "Operational Resilience Policy and Strategy",
       "areas": [
        {
         "num": "3.2.1",
         "name": "Operational Resilience Strategy",
         "controls": [
          {
           "id": "3.2.1.1",
           "text": "The operational resilience strategy shall be defined, approved, implemented, and maintained at least annually, where: a) the operational resilience strategy shall undergo a formal and documented review on annual basis. b) the operational resilience strategy shall also be subject to change-driven reviews triggered by significant internal or external factors that require revisions. These factors may include, but not limited to: i. major changes in the operating environment (e.g., business expansion, merger, technological advancement). ii. new or updated regulatory, legal, or sectoral requirements. iii. significant shifts in the operational resilience threats landscape or newly identified risks. c) the head of the Operational Resilience function of the Regulated Entity shall present and obtain approval on the defined operational resilience strategy and roadmap from the Board or the corresponding function/ committee as defined in the organization’s structure, annually or following any change-driven revisions",
           "key": "ORB:3.2.1.1"
          },
          {
           "id": "3.2.1.2",
           "text": "Regulated Entities operational resilience strategy shall at a minimum define: a) The desired operational resilience maturity level and include clear objectives aligned with Regulated Entities business objectives; b) Road map with timelines for achieving strategic objectives; and c) Requirements for continual review and validation of alignment of the strategic objectives with operational resilience baselines.",
           "key": "ORB:3.2.1.2"
          },
          {
           "id": "3.2.1.3",
           "text": "Regulated Entities shall identify the responsibility and accountability for strategy implementation and monitoring Operational Resilience Policy.",
           "key": "ORB:3.2.1.3"
          },
          {
           "id": "3.2.1.4",
           "text": "The operational resilience policy shall be defined, approved, implemented, communicated, enforced, and made accessible to all employees, contractors, and relevant third-party vendors.",
           "key": "ORB:3.2.1.4"
          },
          {
           "id": "3.2.1.5",
           "text": "The operational resilience policy shall be reviewed and updated annually or upon significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:3.2.1.5"
          },
          {
           "id": "3.2.1.6",
           "text": "Regulated Entities shall develop and maintain an operational resilience policy that: a) Define operational resilience objectives and scope, Executive/ Senior Management’s commitment, operational and resilience roles, and responsibilities, (refer to section 3.2.1) enforcement mechanisms, and deterrents for non-compliance; b) Incorporate relevant international best practices, frameworks, and standards; c) Align with the Regulated Entity’s business objectives, requirements; and d) Consider applicable legal, regulatory requirements.",
           "key": "ORB:3.2.1.6"
          },
          {
           "id": "3.2.1.7",
           "text": "Regulated Entities shall ensure that supporting procedures, processes, and guidelines are established to enable the implementation of the policy.",
           "key": "ORB:3.2.1.7"
          },
          {
           "id": "3.2.1.8",
           "text": "The operational resilience policy shall be approved by the Executive/Senior Management and authorized by the Board, to ensure alignment with the Entity’s overall objectives and the proper management of resilience risks.",
           "key": "ORB:3.2.1.8"
          }
         ]
        }
       ]
      },
      {
       "num": "3.3",
       "name": "Compliance",
       "areas": [
        {
         "num": "3.3.1",
         "name": "Compliance",
         "controls": [
          {
           "id": "3.3.1.1",
           "text": "Regulated Entities shall identify, document, and maintain a compliance register documenting all applicable legal, regulatory, and compliance requirements. Any changes to these requirements must be identified, assessed, implemented, and appropriately reflected in the register, which shall be reviewed and updated regularly, at least annually.",
           "key": "ORB:3.3.1.1"
          },
          {
           "id": "3.3.1.2",
           "text": "The compliance register shall cover: a) CBK requirements, instructions, laws, and regulations, including but not limited to: • Operational Resilience Baselines for Kuwaiti Banking and Financial Sector; • Cyber Resilience Baselines for Kuwaiti Banking and Financial Sector; and • Other requirements, instructions, regulations issued by CBK. b) Relevant international standards and industry best practices related to operational resilience such as: • International Organization of Standardization (e.g., ISO 22301, ISO 31000, and ISO 22361). • BCI Good Practice Guideline • Basel Committee Principles for Operational Resilience",
           "key": "ORB:3.3.1.2"
          },
          {
           "id": "3.3.1.3",
           "text": "Regulated Entities shall obtain and maintain certification for ISO 22301 and shall provide attestation of compliance to CBK upon request or at regular intervals in line with the specific requirements of the relevant standards.",
           "key": "ORB:3.3.1.3"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 2,
     "section": "4",
     "name": "Risk and Threat Management",
     "subdomains": [
      {
       "num": "4.1",
       "name": "Risk Assessment Methodology",
       "areas": [
        {
         "num": "4.1.1",
         "name": "Risk Assessment Methodology",
         "controls": [
          {
           "id": "4.1.1.1",
           "text": "Operational Resilience Function shall define, implement, and maintain a risk assessment methodology on annual basis or upon significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:4.1.1.1"
          },
          {
           "id": "4.1.1.2",
           "text": "The Risk assessment shall be part of the regulated entity’s overall risk management and aligned with its risk appetite. It shall focus on identifying business disruption risks that could disrupt the regulated entity’s operation.",
           "key": "ORB:4.1.1.2"
          },
          {
           "id": "4.1.1.3",
           "text": "Regulated Entities shall ensure that Risk assessment methodology is based on international best practices, frameworks, and standards such as ISO 31000.",
           "key": "ORB:4.1.1.3"
          },
          {
           "id": "4.1.1.4",
           "text": "Operational Resilience Function shall conduct risk assessment for all sites that is used to support the operations of the Regulated Entities, including leased and outsourced sites.",
           "key": "ORB:4.1.1.4"
          }
         ]
        }
       ]
      },
      {
       "num": "4.2",
       "name": "Risk Assessment Process",
       "areas": [
        {
         "num": "4.2.1",
         "name": "Risk Identification and Analysis",
         "controls": [
          {
           "id": "4.2.1.1",
           "text": "Regulated Entities shall ensure that the risk identification exercise considers both internal and external threats that could disrupt the regulated entity’s operations.",
           "key": "ORB:4.2.1.1"
          },
          {
           "id": "4.2.1.2",
           "text": "Regulated Entities shall consider the following during risk identification: a) Regulatory and legal requirements as applicable; b) Environmental threats; c) Technological threats; d) Geopolitical threats; e) Societal threats; f) Third party threats; and g) Economic threats.",
           "key": "ORB:4.2.1.2"
          },
          {
           "id": "4.2.1.3",
           "text": "The identified business disruption risks, including threats, vulnerabilities, and controls, shall be documented in a centralized risk register.",
           "key": "ORB:4.2.1.3"
          },
          {
           "id": "4.2.1.4",
           "text": "Risks shall be evaluated based on severity, impact to business and operations, likelihood of their occurrence and controls implemented.",
           "key": "ORB:4.2.1.4"
          }
         ]
        }
       ]
      },
      {
       "num": "4.3",
       "name": "Risk Treatment and Reporting",
       "areas": [
        {
         "num": "4.3.1",
         "name": "Risk Treatment and Monitoring",
         "controls": [
          {
           "id": "4.3.1.1",
           "text": "Regulated Entities shall ensure that risks documented in the risk register translate into risk treatment plans that correspond to and address the risks identified in the risk register.",
           "key": "ORB:4.3.1.1"
          },
          {
           "id": "4.3.1.2",
           "text": "The risk treatment plans shall be reported to, discussed with, and agreed upon with the respective risk owners within the Regulated Entity to provide risk treatment response.",
           "key": "ORB:4.3.1.2"
          },
          {
           "id": "4.3.1.3",
           "text": "Risk treatment response shall be categorized (e.g., risk acceptance, risk avoidance, risk mitigation, and risk transfer.) tracked, and managed.",
           "key": "ORB:4.3.1.3"
          },
          {
           "id": "4.3.1.4",
           "text": "Regulated Entities shall document and approve the justification for risk acceptance, avoidance, or transfer in accordance with their risk management methodology.",
           "key": "ORB:4.3.1.4"
          },
          {
           "id": "4.3.1.5",
           "text": "Regulated Entities shall implement a risk monitoring process to track treatment plan compliance.",
           "key": "ORB:4.3.1.5"
          }
         ]
        },
        {
         "num": "4.3.2",
         "name": "Risk Reporting",
         "controls": [
          {
           "id": "4.3.2.1",
           "text": "Operational Resilience Function shall consolidate the risk assessment results and report it to the Executive/Senior Management for approval.",
           "key": "ORB:4.3.2.1"
          },
          {
           "id": "4.3.2.2",
           "text": "Operational Resilience Function shall update the Operational Resilience Steering Committee on a quarterly basis regarding the status of identified risks, treatment plans, and any changes in the risk profile.",
           "key": "ORB:4.3.2.2"
          },
          {
           "id": "4.3.2.3",
           "text": "Risk assessment shall be conducted annually or upon significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:4.3.2.3"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 3,
     "section": "5",
     "name": "Business Continuity Management",
     "subdomains": [
      {
       "num": "5.1",
       "name": "Business Impact Analysis (BIA)",
       "areas": [
        {
         "num": "5.1.1",
         "name": "BIA Methodology",
         "controls": [
          {
           "id": "5.1.1.1",
           "text": "Operational Resilience Function shall define, implement, and maintain a BIA methodology on annual basis or upon significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:5.1.1.1"
          },
          {
           "id": "5.1.1.2",
           "text": "Regulated Entities shall ensure that BIA methodology is based on international best practices, frameworks, and standards such as ISO 22301 and BCI Good Practice Guidelines.",
           "key": "ORB:5.1.1.2"
          }
         ]
        },
        {
         "num": "5.1.2",
         "name": "Business Processes identification",
         "controls": [
          {
           "id": "5.1.2.1",
           "text": "Regulated Entities shall establish and maintain a list of services along with criticality level.",
           "key": "ORB:5.1.2.1"
          },
          {
           "id": "5.1.2.2",
           "text": "Each service shall have a business service owner, who shall be responsible for the outcome and delivery of that service. This individual should have end-to-end accountability for ensuring the resilience and continuity of the service, regardless of functional or geographic boundaries within the regulated entity.",
           "key": "ORB:5.1.2.2"
          },
          {
           "id": "5.1.2.3",
           "text": "Regulated Entities shall perform a BIA to identify and map list of services to their supporting business processes along with the recovery resource requirements.",
           "key": "ORB:5.1.2.3"
          }
         ]
        },
        {
         "num": "5.1.3",
         "name": "Recovery Resource Identification",
         "controls": [
          {
           "id": "5.1.3.1",
           "text": "Regulated Entities shall identify recovery resources requirement to sustain critical services during disruptions. Identified resource categories shall cover at a minimum building, equipment, technology, human resources, third-party services, and vital records.",
           "key": "ORB:5.1.3.1"
          },
          {
           "id": "5.1.3.2",
           "text": "Regulated Entities shall define the Recovery Time Objectives (RTO) and Recovery Point Objectives (RPOs) for critical systems.",
           "key": "ORB:5.1.3.2"
          },
          {
           "id": "5.1.3.3",
           "text": "Regulated Entities shall identify and map the internal dependencies between each department within the regulated entity.",
           "key": "ORB:5.1.3.3"
          }
         ]
        },
        {
         "num": "5.1.4",
         "name": "Identification of Single point of failure and Consolidation",
         "controls": [
          {
           "id": "5.1.4.1",
           "text": "Regulated Entities shall identify SPOF across the recovery resource requirements.",
           "key": "ORB:5.1.4.1"
          },
          {
           "id": "5.1.4.2",
           "text": "Operational Resilience Function shall consolidate the BIA results and report it to the Executive/Senior Management for approval.",
           "key": "ORB:5.1.4.2"
          },
          {
           "id": "5.1.4.3",
           "text": "BIA shall be conducted annually or upon significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:5.1.4.3"
          }
         ]
        }
       ]
      },
      {
       "num": "5.2",
       "name": "Recovery Strategies",
       "areas": [
        {
         "num": "5.2.1",
         "name": "Recovery Strategy Identification",
         "controls": [
          {
           "id": "5.2.1.1",
           "text": "Regulated Entities shall use BIA and Risk Assessment results to formulate recovery strategy options and supporting resource allocation.",
           "key": "ORB:5.2.1.1"
          },
          {
           "id": "5.2.1.2",
           "text": "The recovery strategies shall be formulated based on the identified MAO/MTPD, RTOs and RPOs values of the critical Services/processes and systems.",
           "key": "ORB:5.2.1.2"
          },
          {
           "id": "5.2.1.3",
           "text": "The recovery strategies shall cover the recovery resources requirements (Building, Equipment, Technology, Human Resources, Third Parties and Vital Records) and consider multiple disruption scenarios (i.e. unavailability of the building, unavailability of critical systems etc.).",
           "key": "ORB:5.2.1.3"
          },
          {
           "id": "5.2.1.4",
           "text": "An alternate recovery site shall be identified for restoration of critical systems. This alternate site must be geographically separate from the primary site and not exposed to the same disaster event.",
           "key": "ORB:5.2.1.4"
          },
          {
           "id": "5.2.1.5",
           "text": "Regulated Entities shall identify a recovery strategy for business operations in the event of building unavailability. This strategy may include the use of an alternate site or secure remote working arrangements, as determined by the Regulated Entity.",
           "key": "ORB:5.2.1.5"
          }
         ]
        },
        {
         "num": "5.2.2",
         "name": "Recovery Strategy Selection and Monitoring",
         "controls": [
          {
           "id": "5.2.2.1",
           "text": "Regulated Entities shall ensure that the selection of recovery strategies is carried out by the Executive/Senior Management considering the cost and benefits of each identified recovery strategy.",
           "key": "ORB:5.2.2.1"
          },
          {
           "id": "5.2.2.2",
           "text": "Regulated Entities shall develop an action plan to implement the selected recovery strategies, including defined activities, responsibilities, and target timelines.",
           "key": "ORB:5.2.2.2"
          },
          {
           "id": "5.2.2.3",
           "text": "Regulated Entities shall track the implementation status of the recovery strategies and solutions.",
           "key": "ORB:5.2.2.3"
          },
          {
           "id": "5.2.2.4",
           "text": "Selected Recovery strategies shall be documented, approved, reviewed, and updated annually or upon significant changes.",
           "key": "ORB:5.2.2.4"
          }
         ]
        }
       ]
      },
      {
       "num": "5.3",
       "name": "Business Continuity Plans (BCP)",
       "areas": [
        {
         "num": "5.3.1",
         "name": "Plan Components",
         "controls": [
          {
           "id": "5.3.1.1",
           "text": "Regulated Entities shall define, implement and maintain BCP for each business function on an annual basis or upon significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:5.3.1.1"
          },
          {
           "id": "5.3.1.2",
           "text": "The plan shall contain, at a minimum define: a) Departmental activities (listed in order of priority). b) Key resources (e.g., Building, Equipment, Technology, Human resources, Third partied and vital records) and internal dependencies; c) Roles and responsibilities of different stakeholders; d) Initial response, activation and stand down procedures; e) Strategy Actions for the selected recovery strategies; f) A process for relocating to and activating an alternate recovery site for restoration of critical systems and business operations. g) Guideline for handling media; and h) A process to resume the regulated entity’s operations to business-as-usual once the incident is resolved.",
           "key": "ORB:5.3.1.2"
          },
          {
           "id": "5.3.1.3",
           "text": "Operational Resilience Function shall consolidate the BCP and report it to the Executive /Senior Management for approval.",
           "key": "ORB:5.3.1.3"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 4,
     "section": "6",
     "name": "Technology Resilience",
     "subdomains": [
      {
       "num": "6.1",
       "name": "Service Management",
       "areas": [
        {
         "num": "6.1.1",
         "name": "Service Management",
         "controls": [
          {
           "id": "6.1.1.1",
           "text": "Regulated Entities shall maintain a service catalog covering all in-house and outsourced services within the scope of operational resilience, documenting interdependencies and defining KPIs.",
           "key": "ORB:6.1.1.1"
          },
          {
           "id": "6.1.1.2",
           "text": "Regulated Entities shall embed “resilience by design” into the lifecycle of services and support models, ensuring resilience is integrated from planning and development through to operation and decommissioning.",
           "key": "ORB:6.1.1.2"
          },
          {
           "id": "6.1.1.3",
           "text": "Regulated Entities shall conduct periodic service reviews to assess performance and resilience against defined KPIs.",
           "key": "ORB:6.1.1.3"
          },
          {
           "id": "6.1.1.4",
           "text": "Regulated Entities shall define and monitor service-level objectives for recovery and availability.",
           "key": "ORB:6.1.1.4"
          }
         ]
        }
       ]
      },
      {
       "num": "6.2",
       "name": "Backup and Recovery Management",
       "areas": [
        {
         "num": "6.2.1",
         "name": "Backup Capabilities",
         "controls": [
          {
           "id": "6.2.1.1",
           "text": "A backup plan shall be defined, approved, implemented, reviewed, and updated annually or upon significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:6.2.1.1"
          },
          {
           "id": "6.2.1.2",
           "text": "The backup plan shall include at a minimum: a) Backup frequency considering the criticality of data and RPO. b) Secure storage and disposal mechanisms. c) Security measures to protect information and backup media, from different types of technology incidents including cyber incidents; and d) Backup storage in a safe and secure alternate location that is geographically separated from the primary site and not exposed to the same disaster event.",
           "key": "ORB:6.2.1.2"
          },
          {
           "id": "6.2.1.3",
           "text": "Regulated Entities shall implement immutable storage and/or air-gapped backup solutions for critical systems to prevent backup compromise during cyber incidents.",
           "key": "ORB:6.2.1.3"
          },
          {
           "id": "6.2.1.4",
           "text": "Information shall be backed up in accordance with the approved backup plan, stored and retained in alignment with organizational requirements, regulatory requirements and applicable laws.",
           "key": "ORB:6.2.1.4"
          },
          {
           "id": "6.2.1.5",
           "text": "Backups shall be periodically tested, at least quarterly for selective critical systems leading to testing backups of all critical systems within one year, for recoverability to ensure integrity and completeness of backed-up data.",
           "key": "ORB:6.2.1.5"
          }
         ]
        }
       ]
      },
      {
       "num": "6.3",
       "name": "Technology Resilience Capabilities",
       "areas": [
        {
         "num": "6.3.1",
         "name": "High Availability Design",
         "controls": [
          {
           "id": "6.3.1.1",
           "text": "Regulated Entities shall implement high-availability configurations for critical systems identified through the TIA to ensure continuous access and recoverability.",
           "key": "ORB:6.3.1.1"
          },
          {
           "id": "6.3.1.2",
           "text": "Regulated Entities shall adopt scalable and redundant technology architecture to prevent single point of failure.",
           "key": "ORB:6.3.1.2"
          },
          {
           "id": "6.3.1.3",
           "text": "Regulated Entities shall monitor IT system availability and performance periodically.",
           "key": "ORB:6.3.1.3"
          },
          {
           "id": "6.3.1.4",
           "text": "Regulated Entities shall ensure data availability and integrity validation mechanisms.",
           "key": "ORB:6.3.1.4"
          }
         ]
        }
       ]
      },
      {
       "num": "6.4",
       "name": "Technology Recovery Plans",
       "areas": [
        {
         "num": "6.4.1",
         "name": "Technology Impact Analysis (TIA)",
         "controls": [
          {
           "id": "6.4.1.1",
           "text": "Regulated Entities shall define, implement, and maintain a TIA methodology on annual basis or upon significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:6.4.1.1"
          },
          {
           "id": "6.4.1.2",
           "text": "Regulated Entities shall identify the required technology resources to meet the RTO and RPO identified in the BIA.",
           "key": "ORB:6.4.1.2"
          },
          {
           "id": "6.4.1.3",
           "text": "Regulated Entities shall prioritize IT systems based on criticality to support recovery planning.",
           "key": "ORB:6.4.1.3"
          },
          {
           "id": "6.4.1.4",
           "text": "Regulated Entities shall map each IT systems to its underlying infrastructure, including physical/virtual server, operating system, and hardware specifications (e.g., CPU, RAM, storage).",
           "key": "ORB:6.4.1.4"
          },
          {
           "id": "6.4.1.5",
           "text": "Operational Resilience Function shall consolidate the TIA results and report it to the Executive/Senior Management for approval.",
           "key": "ORB:6.4.1.5"
          },
          {
           "id": "6.4.1.6",
           "text": "TIA shall be conducted annually or upon significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:6.4.1.6"
          }
         ]
        },
        {
         "num": "6.4.2",
         "name": "Recovery Planning",
         "controls": [
          {
           "id": "6.4.2.1",
           "text": "Regulated Entities shall define, implement, and maintain an IT Disaster Recovery Plan (IT DRP) to recover and restore technology services and infrastructure components (e.g., data, systems, network, services, and applications), in alignment with the Technology and Business Impact Analysis.",
           "key": "ORB:6.4.2.1"
          },
          {
           "id": "6.4.2.2",
           "text": "The IT DRP shall contain at a minimum to define: a) Response Team Structure; b) Role descriptions for the response team; c) Plan activation and escalation protocols; d) Recovery steps; e) Application Recovery interdependency Mapping; f) IT Recovery Strategies (including cyber-attack recovery); g) IT environment architecture; and h) Application Recovery procedures (including cyber-attack recovery).",
           "key": "ORB:6.4.2.2"
          },
          {
           "id": "6.4.2.3",
           "text": "Regulated Entities shall establish a Disaster Recovery (DR) site to enable the restoration of critical technology services in the event of a disruption. The DR site shall be geographically separated from the primary site and equipped with the necessary infrastructure to meet recovery objectives and not exposed to the same disaster.",
           "key": "ORB:6.4.2.3"
          },
          {
           "id": "6.4.2.4",
           "text": "Operational Resilience Function shall report the IT DR Plan to the Executive/Senior Management for approval.",
           "key": "ORB:6.4.2.4"
          },
          {
           "id": "6.4.2.5",
           "text": "Regulated Entities shall review IT DRP annually or when significant changes to current business processes, technology assets, operating environment, or new regulatory requirements.",
           "key": "ORB:6.4.2.5"
          }
         ]
        }
       ]
      },
      {
       "num": "6.5",
       "name": "Cyber Recovery Plans",
       "areas": [
        {
         "num": "6.5.1",
         "name": "Cyber Recovery Capabilities",
         "controls": [
          {
           "id": "6.5.1.1",
           "text": "Regulated Entities shall identify all, or a subset of critical technology services (Refer to 6.4.1 Technology Impact Assessment) deemed as most critical based on business requirements.",
           "key": "ORB:6.5.1.1"
          },
          {
           "id": "6.5.1.2",
           "text": "Regulated Entities shall establish logically and physically segregated recovery capabilities for technology services identified in section 6.5.1.1, to ensure recovery from cyber incidents impacting primary and disaster recovery sites.",
           "key": "ORB:6.5.1.2"
          },
          {
           "id": "6.5.1.3",
           "text": "Regulated Entities shall validate recovery images, backup integrity, and configuration baselines prior to restoration to ensure recovered systems are free from compromise.",
           "key": "ORB:6.5.1.3"
          }
         ]
        },
        {
         "num": "6.5.2",
         "name": "Cyber Recovery Planning",
         "controls": [
          {
           "id": "6.5.2.1",
           "text": "Regulated Entities shall define, implement, and maintain a Cyber Recovery Plan (CRP) to restore technology services, applications, and data following a cyber incident.",
           "key": "ORB:6.5.2.1"
          },
          {
           "id": "6.5.2.2",
           "text": "The Cyber Recovery Plan shall include at a minimum: a) Governance & Scope - Define scope, objectives, roles, responsibilities, assumptions and escalation paths. b) Recovery Priorities - Identify critical services, dependencies, recovery objectives and priorities. c) Recovery strategies - Define strategies tailored to cyber-attacks (e.g., ransomware recovery, malware eradication). d) Recovery Environment - Define recovery environment such as immutable backup, Cyber Vault / Isolated Recovery Environment (IRE), Segregated Network Access, etc. e) Triggers - Define triggers for invoking the Cyber Recovery Plan (e.g. post containment). f) Recovery Procedures - Define detailed procedures/technical runbooks for verifying and restoring clean systems and applications. g) Testing & Validation - Define testing, validation frequency and plan. h) Continuous Improvement - Define the process for continuous improvement including but not limited to updating the plan post-incident, after major changes and newly identified threats.",
           "key": "ORB:6.5.2.2"
          },
          {
           "id": "6.5.2.3",
           "text": "Regulated Entities shall align the Cyber Recovery Plan with the IT Disaster Recovery Plan (IT DRP), and Business Continuity Plan (BCP), to ensure coordinated recovery.",
           "key": "ORB:6.5.2.3"
          },
          {
           "id": "6.5.2.4",
           "text": "Operational Resilience Function shall submit the Cyber Recovery Plan to the Executive/Senior Management for approval.",
           "key": "ORB:6.5.2.4"
          },
          {
           "id": "6.5.2.5",
           "text": "The Cyber Recovery Plan shall be reviewed annually or upon significant changes to technology assets, cyber threat landscape, or operating environment.",
           "key": "ORB:6.5.2.5"
          }
         ]
        },
        {
         "num": "6.5.3",
         "name": "Cyber Recovery Testing",
         "controls": [
          {
           "id": "6.5.3.1",
           "text": "Regulated Entities shall conduct cyber recovery testing at least annually, including scenario- based exercises such as ransomware recovery drills, data integrity validation, and reconstitution of compromised environments.",
           "key": "ORB:6.5.3.1"
          },
          {
           "id": "6.5.3.2",
           "text": "Testing results shall be documented, analyzed, and reported to the Executive/Senior Management, with identified gaps remediated within defined timelines.",
           "key": "ORB:6.5.3.2"
          },
          {
           "id": "6.5.3.3",
           "text": "Regulated Entities shall integrate lessons learned from cyber recovery testing into continuous improvement of the Cyber Recovery Plan.",
           "key": "ORB:6.5.3.3"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 5,
     "section": "8",
     "name": "Incident and Crisis Management",
     "subdomains": [
      {
       "num": "8.1",
       "name": "Incident and Crisis Management Governance and Planning",
       "areas": [
        {
         "num": "8.1.1",
         "name": "Response Team",
         "controls": [
          {
           "id": "8.1.1.1",
           "text": "Regulated Entities shall define a response structure that comprises of different teams to handle incident and crisis situations (e.g. strategic, tactical, and operational teams) that integrates the technical, business, and management functions of the Regulated Entity.",
           "key": "ORB:8.1.1.1"
          },
          {
           "id": "8.1.1.2",
           "text": "Regulated Entities shall establish a three-layered response structure that includes: a) Crisis Management Team (Strategic level) b) Incident Management Team (Tactical Level) c) Incident Response Team (Operational Level)",
           "key": "ORB:8.1.1.2"
          },
          {
           "id": "8.1.1.3",
           "text": "Regulated Entities shall adopt the severity impact matrix outlined below as its internal impact matrix. Impact Category Team Theft and data Legal and Operational Reputational Activated Severity breach regulatory Tier and Impact levels No data breach or No negative impact No breaches to All service channels are theft attempt, and m on reputation in laws, regulations a Insignificant available and no impact on no impact to e social media, local or contractual T customer base customers or e media outlets. obligations s n systems. o p Low Reportable s e Few service channels are Few social media Attempted theft or R breaches or t not available causing posts with limited exposure of non- n temporary e d Low minimal disruption and reach (<# views) and sensitive data with ic inability to n impacting less than xxx% of no reporting in local no material loss or I comply with customers base. media outlets. customer impact. regulations t n # service channels are not Between # to # Contained incident Reportable t e negative posts from involving breaches which n m m available causing e d ic n e g a n a e T Medium Moderate noticeable disruption and p so u c b ia lic l m fig e u d r ia e s on u ac n c a e u s t s h o o r r i m ze i d n or r r e e s g u u l l t a t in o ry I a impacting x%-x% of M platforms that have financial loss, with investigation customers base. a potential of limited customer and remediation trending with data affected. plans with moderate reach (#-# defined views) due to timelines engaging content, relevant hashtag, tagging of the regulated entity and limited coverage by local media outlets. Between # to # negative posts from Reportable public figures on breaches or social media Confirmed data failures # services channel are not platforms that is breach or theft identified by available causing major trending with high involving sensitive High regulatory disruption and impacting engagement (#-# information and authorities x%-x% of customers base. views), cross multiple affected which result in platform sharing and customers. financial m traction via hashtags a penalties e and reports in T t n national media. e m Formal e High More than # g a regulatory n negative posts from a intervention, M public figures on s including is social media Major data breach ir financial C No service channel is platforms that or large-scale penalties which available causing gained widely viral financial theft with results in Severe operational shutdown and engagement with a widespread appointment of impacting more than x% of massive reach (># exposure of external 3rd customers base. views), sensitive data and party advisors to along with headline customer harm. oversee or coverage in major implement national and remediation international media. plans *Note: The impact level shall be determined based on the highest severity observed across one or more impact categories, recognizing that a single significant impact in any category is sufficient to trigger the corresponding severity tier.",
           "key": "ORB:8.1.1.3"
          },
          {
           "id": "8.1.1.4",
           "text": "Regulated Entities shall establish an Incident Management Team (IMT) that is activated and structured based on the nature, scope, and impact of the incident. The team shall include Incident Responders from the impacted function(s).",
           "key": "ORB:8.1.1.4"
          },
          {
           "id": "8.1.1.5",
           "text": "IMT leader shall be designated to lead response activities, oversee documentation of actions taken, and initiate a post-incident review upon resolution.",
           "key": "ORB:8.1.1.5"
          },
          {
           "id": "8.1.1.6",
           "text": "Regulated Entities shall maintain a Crisis Management Team distinct from Incident Management and Incident Response teams.",
           "key": "ORB:8.1.1.6"
          },
          {
           "id": "8.1.1.7",
           "text": "Crisis Management Team shall be led by the Crisis Response Lead and can comprise empowered representatives from Human Resources, Operations, Information Technology, Information Security, Legal, Finance, Communications, Log keeper and Business Continuity. The team shall: a) Assess the impacts of the crisis; b) Maintain centralized and strategic oversight of the crisis; c) Mobilize and deploy necessary internal and external resources to deliver the response; d) Oversee execution of response activities; e) Provide strategic inputs regarding crisis communication with internal and external stakeholders throughout the crisis management life cycle; and f) Monitor the effect of the crisis and take necessary actions to minimize the financial, operational, reputational and/or legal damages.",
           "key": "ORB:8.1.1.7"
          },
          {
           "id": "8.1.1.8",
           "text": "Regulated Entities shall ensure that the Crisis Response Lead shall: a) Holds a senior executive position with the authority to make strategic decisions; b) Have skills and experience to understand the Regulated Entity’s operations and to be able to manage the crisis; and c) Have an appointed deputy in the absence of the lead.",
           "key": "ORB:8.1.1.8"
          },
          {
           "id": "8.1.1.9",
           "text": "Regulated Entities shall have incident and crisis management response toolkit (e.g., a decision and action logging) to create an auditable trail of response considerations and assist in improvements based on lessons learned.",
           "key": "ORB:8.1.1.9"
          },
          {
           "id": "8.1.1.10",
           "text": "Regulated Entities shall establish a crisis command center.",
           "key": "ORB:8.1.1.10"
          }
         ]
        },
        {
         "num": "8.1.2",
         "name": "Plans Development",
         "controls": [
          {
           "id": "8.1.2.1",
           "text": "Regulated Entities shall document, review, and maintain Incident and crisis management plans that supports their response, including incident and crisis management planning as an integrated component on annual basis. The plan shall be: a) Approved by the Executive/Senior Management; b) Implemented at regulated entity wide to ensure coverage of key functions, authorities, and responsibilities; c) Aligned with legal, regulatory, and organizational requirements; and d) Aligned with operational risk management considerations (e.g., DR, BC, and communications [internal/external] policies, plans, procedures, and templates).",
           "key": "ORB:8.1.2.1"
          },
          {
           "id": "8.1.2.2",
           "text": "Regulated Entities shall develop and maintain incident management plans that are proportionate with the nature, scale, and complexity of its operations, and shall, at a minimum, include the following components: a) Team Structure; b) Role descriptions for the response team; c) Incident classification criteria and severity levels; d) Activation and escalation protocols; e) Incident Lifecycle; and f) Communication procedures with internal and external stakeholders.",
           "key": "ORB:8.1.2.2"
          },
          {
           "id": "8.1.2.3",
           "text": "Regulated Entities shall develop and maintain crisis management plan that include at a minimum: a) Criteria for declaring a crisis; b) Activation and escalation mechanism for crisis response; c) Crisis Management team structure; d) Contact details of the crisis management team members and their backups; e) Crisis response and recovery lifecycle; f) Set of responsibilities to be undertaken before, during, and after a crisis or disaster; and g) Communication protocols to address communication with the internal and external stakeholders during a crisis.",
           "key": "ORB:8.1.2.3"
          }
         ]
        }
       ]
      },
      {
       "num": "8.2",
       "name": "Communication and Escalation",
       "areas": [
        {
         "num": "8.2.1",
         "name": "Internal and External Communication",
         "controls": [
          {
           "id": "8.2.1.1",
           "text": "Regulated Entities shall have documented communication protocols that pre-define incident and crisis communication statements for various scenarios, communication channels, frequency of communication and responsibilities to ensure that accurate and timely information is disseminated to all internal and external stakeholders.",
           "key": "ORB:8.2.1.1"
          },
          {
           "id": "8.2.1.2",
           "text": "Regulated Entities shall implement effective communication mechanisms to support timely contact with responders and employees in the event of crisis.",
           "key": "ORB:8.2.1.2"
          },
          {
           "id": "8.2.1.3",
           "text": "Regulated Entities shall assign a crisis communication team responsible for managing all communication activities during crisis.",
           "key": "ORB:8.2.1.3"
          },
          {
           "id": "8.2.1.4",
           "text": "Regulated Entities shall appoint a spokesperson responsible for communicating with external stakeholders during the crisis.",
           "key": "ORB:8.2.1.4"
          }
         ]
        },
        {
         "num": "8.2.2",
         "name": "Escalation and reporting to CBK",
         "controls": [
          {
           "id": "8.2.2.1",
           "text": "Regulated Entities shall initially report incidents to CBK in accordance with the below timelines, corresponding to the incident severity rating: a) Medium severity incidents shall be reported within (4) hours of discovery; and b) High severity incidents shall be reported within (1) hour of discovery.",
           "key": "ORB:8.2.2.1"
          },
          {
           "id": "8.2.2.2",
           "text": "Regulated Entities shall update CBK on the situation/progress of the reported incidents in accordance with the below timelines: a) Medium severity incidents shall be updated on daily basis or when requested by CBK; and b) High severity incidents shall be updated in every 4 hours from prior notification, or when requested by CBK.",
           "key": "ORB:8.2.2.2"
          },
          {
           "id": "8.2.2.3",
           "text": "Regulated Entities shall submit closure incident report to CBK in accordance with the below timelines, corresponding to the incident severity rating: a) Low severity incidents shall be consolidated and reported on a monthly basis; and b) Medium and High severity incidents shall submit closure report once the incident is resolved.",
           "key": "ORB:8.2.2.3"
          },
          {
           "id": "8.2.2.4",
           "text": "Regulated Entities shall determine the estimated financial loss in the initial situational/progress report and confirm the final loss amount in the closure report.",
           "key": "ORB:8.2.2.4"
          },
          {
           "id": "8.2.2.5",
           "text": "Regulated Entities shall report incidents in accordance with the predefined templates (specified in the Appendix section 12.1) and communication channels. Notification requirements for Regulated Entities to CBK Severity Initial Reporting Situation Reporting Closure Reporting High Within 1 hours of discovery Every 4 hours Upon closure Medium Within 4 hours of discovery Once a day Upon closure Low Not Applicable Not Applicable Monthly",
           "key": "ORB:8.2.2.5"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 6,
     "section": "10",
     "name": "Training, Testing and Continuous Improvement",
     "subdomains": [
      {
       "num": "10.1",
       "name": "Training, Testing and Exercising",
       "areas": [
        {
         "num": "10.1.1",
         "name": "Table-Top Exercises",
         "controls": [
          {
           "id": "10.1.1.1",
           "text": "Tabletop exercises shall be conducted at least annually to test the effectiveness of operational resilience plans and decision-making processes under simulated disruption scenarios with respective stakeholders within the regulated entity.",
           "key": "ORB:10.1.1.1"
          },
          {
           "id": "10.1.1.2",
           "text": "Scenarios shall be realistic, relevant to the regulated entity’s operating context, and clearly defined with objectives. Examples may include function-specific, location-based, process- level, or High risks identified in the risk assessment.",
           "key": "ORB:10.1.1.2"
          },
          {
           "id": "10.1.1.3",
           "text": "Defined test scenarios shall cover the activation of operational resilience plans (BCP, IT DRP).",
           "key": "ORB:10.1.1.3"
          }
         ]
        },
        {
         "num": "10.1.2",
         "name": "Business Continuity and Disaster Recovery Testing",
         "controls": [
          {
           "id": "10.1.2.1",
           "text": "Business continuity and Disaster recovery tests shall be conducted at least annually. Testing shall cover both business process continuity and IT systems recovery.",
           "key": "ORB:10.1.2.1"
          },
          {
           "id": "10.1.2.2",
           "text": "Tests shall be designed to validate: a) Verify compliance with RTO and RPO targets for critical systems and data; b) Functionality of alternate work locations; and c) End to end recovery across the business unit and systems.",
           "key": "ORB:10.1.2.2"
          }
         ]
        },
        {
         "num": "10.1.3",
         "name": "Crisis Simulation",
         "controls": [
          {
           "id": "10.1.3.1",
           "text": "Full-scale or partial crisis simulations shall be conducted at least annually to test the effectiveness of operational resilience plans and decision-making processes under simulated disruption scenarios.",
           "key": "ORB:10.1.3.1"
          },
          {
           "id": "10.1.3.2",
           "text": "Scenarios shall be developed to reflect high-impact, realistic disruption events that test the regulated entity’s ability to manage complex and evolving crises. Scenarios may include multi-layered incidents such as cyberattacks, infrastructure failure, critical third-party disruption, or concurrent operational and reputational risks.",
           "key": "ORB:10.1.3.2"
          },
          {
           "id": "10.1.3.3",
           "text": "Defined test scenarios should cover the activation and involvement for crisis management team and other response teams as applicable.",
           "key": "ORB:10.1.3.3"
          }
         ]
        },
        {
         "num": "10.1.4",
         "name": "Sector Wide Simulation",
         "controls": [
          {
           "id": "10.1.4.1",
           "text": "Regulated Entities shall participate in sector-wide simulation exercises coordinated by CBK where applicable. These exercises are designed to assess the readiness of the regulated entities to respond to large-scale, systemic disruptions affecting the broader banking ecosystem.",
           "key": "ORB:10.1.4.1"
          }
         ]
        },
        {
         "num": "10.1.5",
         "name": "Continuous Improvement",
         "controls": [
          {
           "id": "10.1.5.1",
           "text": "Regulated Entities shall ensure that detailed results of all exercises and tests are documented for future reference and continuous improvement. The documentation shall include, at a minimum: a) Document the objectives and scope of the exercised plan; b) Document the participants; c) Exercise / test results; d) Document lessons learnt and the required improvements; and e) In case of failure, Capture the root-cause of the failure and remediation actions should be tracked to successful conclusion.",
           "key": "ORB:10.1.5.1"
          },
          {
           "id": "10.1.5.2",
           "text": "Regulated Entities shall report the testing results to the Executive/Senior Management.",
           "key": "ORB:10.1.5.2"
          }
         ]
        },
        {
         "num": "10.1.6",
         "name": "Training and Awareness",
         "controls": [
          {
           "id": "10.1.6.1",
           "text": "Regulated Entities shall ensure that all internal employees, contractors, and relevant third- party staff within the regulated entity are: a) Familiar with relevant parts of operational resilience policies and plans b) Familiar with their roles and responsibilities during disruptive incidents",
           "key": "ORB:10.1.6.1"
          },
          {
           "id": "10.1.6.2",
           "text": "Specialized awareness training shall be provided once on an annual basis to employees involved in resilience related disciplines to achieve the required level of experience, skills, and competences.",
           "key": "ORB:10.1.6.2"
          },
          {
           "id": "10.1.6.3",
           "text": "Specialized awareness training for the top management shall be delivered at least annually, to ensure they understand their roles in developing operational resilience culture.",
           "key": "ORB:10.1.6.3"
          },
          {
           "id": "10.1.6.4",
           "text": "Regulated Entities shall retain relevant documented information as evidence of all conducted awareness and training programs, including attendance records and assessment results.",
           "key": "ORB:10.1.6.4"
          },
          {
           "id": "10.1.6.5",
           "text": "Regulated Entities shall measure the effectiveness of the training and awareness program.",
           "key": "ORB:10.1.6.5"
          }
         ]
        }
       ]
      }
     ]
    }
   ],
   "counts": {
    "domains": 6,
    "subdomains": 17,
    "control_areas": 35,
    "controls": 148
   },
   "official_counts": {
    "domains": 8,
    "subdomains": 17,
    "control_areas": 35,
    "controls": 146
   }
  },
  {
   "code": "TPRM",
   "name": "Third-Party Risk Management Baselines",
   "domains": [
    {
     "domain": 1,
     "section": "3",
     "name": "Governance Structure and Oversight",
     "subdomains": [
      {
       "num": "3.1",
       "name": "TPRM Policy and Strategy",
       "areas": [
        {
         "num": "3.1.1",
         "name": "TPRM Policy",
         "controls": [
          {
           "id": "3.1.1.1",
           "text": "Regulated entities shall develop and maintain a TPRM policy that: a) defines TPRM scope, activities that could be outsourced and not outsourced, Executive/Senior Management’s commitment, roles and responsibilities, enforcement mechanisms, and deterrents for non-compliance; b) incorporates relevant international best practices, frameworks, and standards; c) aligns with business objectives, relevant organizational policies, legal, regulatory, and contractual requirements",
           "key": "TPRM:3.1.1.1"
          },
          {
           "id": "3.1.1.2",
           "text": "The TPRM policy shall be defined, approved, implemented, communicated, enforced, and made accessible to all employees.",
           "key": "TPRM:3.1.1.2"
          },
          {
           "id": "3.1.1.3",
           "text": "The TPRM policy shall be reviewed and updated annually or upon significant changes in the third-party ecosystem.",
           "key": "TPRM:3.1.1.3"
          },
          {
           "id": "3.1.1.4",
           "text": "Regulated entities shall ensure that supporting procedures, processes, and guidelines are established to enable the implementation of the policy.",
           "key": "TPRM:3.1.1.4"
          },
          {
           "id": "3.1.1.5",
           "text": "The TPRM policy shall be approved by the Executive/Senior Management and authorized by the Board to ensure alignment with the Entity’s overall objectives and the proper management of third-party risks.",
           "key": "TPRM:3.1.1.5"
          }
         ]
        },
        {
         "num": "3.1.2",
         "name": "TPRM Strategy",
         "controls": [
          {
           "id": "3.1.2.1",
           "text": "The Regulated Entities TPRM strategy shall include: a) define the desired TPRM maturity level and include clear objectives aligned with organizational goals and business objectives; b) include a roadmap with timelines for achieving strategic objectives; c) include requirements for continual review and validation of alignment of the TPRM program with strategic objectives; d) identify the responsibility and accountability for strategy implementation and monitoring.",
           "key": "TPRM:3.1.2.1"
          },
          {
           "id": "3.1.2.2",
           "text": "The TPRM strategy shall be defined, approved, and implemented, where: a) the strategy shall undergo a formal and documented review on an annual basis; b) the strategy shall also be subject to change-driven reviews triggered by significant internal or external factors, including: i. Significant shifts in the third-party threat landscape (e.g., onboarding of critical vendors, outsourcing of key services, newly identified risks); ii. New or updated regulatory, legal, or sectoral requirements;",
           "key": "TPRM:3.1.2.2"
          }
         ]
        }
       ]
      },
      {
       "num": "3.2",
       "name": "Roles and Responsibilities",
       "areas": [
        {
         "num": "3.2.1",
         "name": "Defined Ownership",
         "controls": [
          {
           "id": "3.2.1.1",
           "text": "Regulated entities shall assign explicit ownership of third-party risk to designated functions such as Risk Management, Procurement, Legal, Business, Finance, Information Security, etc. Each function should be responsible for managing risks within its domain, ensuring that third-party engagements are assessed, monitored, and governed appropriately.",
           "key": "TPRM:3.2.1.1"
          }
         ]
        },
        {
         "num": "3.2.2",
         "name": "Three Lines of Defense Model",
         "controls": [
          {
           "id": "3.2.2.1",
           "text": "Regulated entities shall implement a structured approach to risk governance using the Three Lines of Defense model:",
           "key": "TPRM:3.2.2.1"
          }
         ]
        }
       ]
      },
      {
       "num": "3.3",
       "name": "Board and Senior Management Oversight",
       "areas": [
        {
         "num": "3.3.1",
         "name": "Board of Directors",
         "controls": [
          {
           "id": "3.3.1.1",
           "text": "The Board of Directors (hereinafter referred as, Board) shall serve as the ultimate approving authority for the Third-Party Risk Management (TPRM) strategy. It shall also provide authorization for the TPRM policy, ensuring alignment with the entity’s overall risk appetite and regulatory obligations.",
           "key": "TPRM:3.3.1.1"
          },
          {
           "id": "3.3.1.2",
           "text": "The Board shall ensure the allocation of adequate financial, technological, and human resources to support the effective implementation and sustainability of the TPRM framework.",
           "key": "TPRM:3.3.1.2"
          },
          {
           "id": "3.3.1.3",
           "text": "The Board shall mandate the establishment of a dedicated TPRM Oversight Committee, with clearly defined responsibilities and authority to oversee third-party risk activities.",
           "key": "TPRM:3.3.1.3"
          },
          {
           "id": "3.3.1.4",
           "text": "The Board shall receive periodic reports (at least quarterly) from the TPRM Oversight Committee or relevant executive functions. These reports shall include: • Updates on the third-party risk posture; • Emerging threats and vulnerabilities; • Regulatory developments and compliance status; • Status of remediation actions and incident responses.",
           "key": "TPRM:3.3.1.4"
          }
         ]
        },
        {
         "num": "3.3.2",
         "name": "TPRM Oversight Committee",
         "controls": [
          {
           "id": "3.3.2.1",
           "text": "The TPRM Oversight Committee shall be chaired by a designated senior executive and shall composed of senior representatives from key functions, including: • Head of TPRM function; • Procurement and Vendor Management; • Legal and Compliance; • Information Security and Technology; • Business Units with critical third-party dependencies; • Business Continuity and Risk Management functions; • Internal Audit (as an observer).",
           "key": "TPRM:3.3.2.1"
          },
          {
           "id": "3.3.2.2",
           "text": "The Committee shall be chaired by a senior executive with expertise in third-party risk, governance, and regulatory compliance.",
           "key": "TPRM:3.3.2.2"
          },
          {
           "id": "3.3.2.3",
           "text": "The Committee shall develop and maintain a formal charter, approved by the Board, which shall include: • The Committee’s mandate and objectives; • Membership composition and roles; • Meeting frequency (minimum quarterly) and quorum requirements; • Reporting lines and escalation protocols.",
           "key": "TPRM:3.3.2.3"
          },
          {
           "id": "3.3.2.4",
           "text": "The Committee shall be responsible for: • Reviewing and endorsing the TPRM strategy and policy; • Monitoring program effectiveness through Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and resource utilization; • Reviewing risk assessments and classifications of critical third-party service providers; • Overseeing incident response, post-incident reviews, and closure of remediation actions related to third-party failures; • Ensuring the implementation of training and awareness programs across the organization; • Staying aware of regulatory changes, industry developments, and ensuring ongoing compliance with applicable laws and standards.",
           "key": "TPRM:3.3.2.4"
          }
         ]
        },
        {
         "num": "3.3.3",
         "name": "Executive and Senior Management",
         "controls": [
          {
           "id": "3.3.3.1",
           "text": "Executive and Senior Management shall ensure the effective execution of the TPRM framework, including integration with enterprise risk management, business continuity, and operational resilience programs.",
           "key": "TPRM:3.3.3.1"
          },
          {
           "id": "3.3.3.2",
           "text": "Senior Management shall allocate sufficient resources-financial, technological, and personnel to support the TPRM lifecycle, including onboarding, monitoring, and offboarding of third-party relationships.",
           "key": "TPRM:3.3.3.2"
          },
          {
           "id": "3.3.3.3",
           "text": "They shall foster a culture of risk awareness, ethical conduct, and continuous improvement in third-party engagements across all levels of the organization.",
           "key": "TPRM:3.3.3.3"
          },
          {
           "id": "3.3.3.4",
           "text": "Executive Management is responsible for reviewing and implementing actions arising from assessments and audits. These evaluations shall be used to inform strategic decisions and drive enhancements in the program.",
           "key": "TPRM:3.3.3.4"
          }
         ]
        },
        {
         "num": "3.3.4",
         "name": "Third-Party Risk Management Function",
         "controls": [
          {
           "id": "3.3.4.1",
           "text": "The head of the Third-Party Risk Management function shall be responsible for defining and reviewing the TPRM strategy",
           "key": "TPRM:3.3.4.1"
          },
          {
           "id": "3.3.4.2",
           "text": "Regulated entities shall establish a Third-Party Risk Management (TPRM) function with clearly defined roles and responsibilities, empowered by executive/senior management and overseen by the BRC Committee or equivalent authority.",
           "key": "TPRM:3.3.4.2"
          },
          {
           "id": "3.3.4.3",
           "text": "The TPRM function shall be appropriately staffed with personnel possessing knowledge in Chapter 6 vendor risk, compliance, legal, and information security, commensurate with the scale and complexity of third-party engagements.",
           "key": "TPRM:3.3.4.3"
          },
          {
           "id": "3.3.4.4",
           "text": "The TPRM function shall be responsible and accountable for establishing and maintaining policies, procedures, and tools to identify, assess, mitigate, and monitor risks associated with third-party relationships.",
           "key": "TPRM:3.3.4.4"
          },
          {
           "id": "3.3.4.5",
           "text": "The function shall coordinate with business units, procurement, legal, compliance, finance (or equivalent), IT and Information Security to ensure a holistic approach to third-party risk management across the organization.",
           "key": "TPRM:3.3.4.5"
          },
          {
           "id": "3.3.4.6",
           "text": "The Head of TPRM shall ensure that third-party risk assessments, due diligence, and ongoing monitoring activities are conducted consistently and that risk findings are escalated and addressed in a timely manner.",
           "key": "TPRM:3.3.4.6"
          },
          {
           "id": "3.3.4.7",
           "text": "Periodic reporting on third-party risk posture, emerging risks, and remediation status shall be provided to the TPRM Oversight Committee, at least quarterly or as required by significant changes in the third-party landscape.",
           "key": "TPRM:3.3.4.7"
          },
          {
           "id": "3.3.4.8",
           "text": "Periodic reporting on third-party risk posture, emerging risks, and remediation status shall be provided to the TPRM Oversight Committee, at least quarterly or as required by significant changes in the third-party landscape.",
           "key": "TPRM:3.3.4.8"
          }
         ]
        }
       ]
      },
      {
       "num": "3.4",
       "name": "Approvals and Periodic Reviews",
       "areas": [
        {
         "num": "3.4.1",
         "name": "Annual Review and Approval",
         "controls": [
          {
           "id": "3.4.1.1",
           "text": "The TPRM policy and overarching strategy shall be reviewed and formally approved by senior management or the designated governance committee at least annually. Additional reviews shall be conducted upon the occurrence of significant changes in the regulatory landscape, business operations, or risk environment.",
           "key": "TPRM:3.4.1.1"
          }
         ]
        },
        {
         "num": "3.4.2",
         "name": "Periodic Risk Assessment Reviews",
         "controls": [
          {
           "id": "3.4.2.1",
           "text": "Third-party risk assessments, including due diligence outcomes, control effectiveness, and residual risk ratings, shall be reviewed periodically based on the criticality and risk profile of the third-party. High-risk third-parties shall be reviewed annually, medium-risk every two years, and low-risk every three years.",
           "key": "TPRM:3.4.2.1"
          },
          {
           "id": "3.4.2.2",
           "text": "Controls implemented to mitigate third-party risks shall be evaluated regularly to ensure they remain effective and aligned with current threats, vulnerabilities, and compliance requirements.",
           "key": "TPRM:3.4.2.2"
          },
          {
           "id": "3.4.2.3",
           "text": "All approvals, reviews, and updates to the TPRM policy, strategy, and risk assessments shall be documented. The review process shall ensure continued alignment with applicable regulatory guidelines and leading industry standards. Chapter 6",
           "key": "TPRM:3.4.2.3"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 2,
     "section": "4",
     "name": "Risk Management Framework",
     "subdomains": [
      {
       "num": "4.1",
       "name": "Critical Third-Party Service Identification",
       "areas": [
        {
         "num": "4.1.1",
         "name": "Impact on Critical Business Services",
         "controls": [
          {
           "id": "4.1.1.1",
           "text": "Regulated entities shall evaluate the extent to which a third-party supports essential business functions or services that, if disrupted, could significantly affect operations or customer outcomes.",
           "key": "TPRM:4.1.1.1"
          }
         ]
        },
        {
         "num": "4.1.2",
         "name": "Data Sensitivity and Volume",
         "controls": [
          {
           "id": "4.1.2.1",
           "text": "Regulated entities shall assess the nature and volume of data shared with or processed by third-parties, based on its classification.",
           "key": "TPRM:4.1.2.1"
          }
         ]
        },
        {
         "num": "4.1.3",
         "name": "Regulatory and Operational Dependencies",
         "controls": [
          {
           "id": "4.1.3.1",
           "text": "Regulated entities shall consider dependencies arising from regulatory obligations, licensing requirements, or operational interlinkages that may elevate the criticality of the third-party.",
           "key": "TPRM:4.1.3.1"
          }
         ]
        },
        {
         "num": "4.1.4",
         "name": "Centralized and continuously updated inventory",
         "controls": [
          {
           "id": "4.1.4.1",
           "text": "Regulated Entities shall maintain a centralized and periodically updated inventory of all third-party relationships, clearly flagging those classified as critical. This inventory should be integrated with risk registers and business continuity plans.",
           "key": "TPRM:4.1.4.1"
          },
          {
           "id": "4.1.4.2",
           "text": "The centralized inventory shall be maintained by the designated TPRM function and updated at least quarterly or upon any significant change in third-party relationships.",
           "key": "TPRM:4.1.4.2"
          }
         ]
        }
       ]
      },
      {
       "num": "4.2",
       "name": "Risk Identification and Assessment Methodology",
       "areas": [
        {
         "num": "4.2.1",
         "name": "Multi-Dimensional Risk Assessment",
         "controls": [
          {
           "id": "4.2.1.1",
           "text": "Regulated entities shall evaluate third-party risks across key dimensions, including: a) financial risk b) operational risk c) cybersecurity and information security risk d) legal and contractual risk e) reputational risk f) regulatory and compliance risk",
           "key": "TPRM:4.2.1.1"
          }
         ]
        },
        {
         "num": "4.2.2",
         "name": "Risk Scoring and Prioritization",
         "controls": [
          {
           "id": "4.2.2.1",
           "text": "Regulated entities shall apply quantitative and qualitative risk scoring to classify third-party relationships into tiers based on service criticality, data sensitivity, and customer impact, enabling prioritized oversight and mitigation.",
           "key": "TPRM:4.2.2.1"
          }
         ]
        },
        {
         "num": "4.2.3",
         "name": "Due Diligence and Ongoing Monitoring",
         "controls": [
          {
           "id": "4.2.3.1",
           "text": "Regulated entities shall conduct thorough due diligence during onboarding and implement periodic reassessments based on risk tiering and performance indicators.",
           "key": "TPRM:4.2.3.1"
          }
         ]
        }
       ]
      },
      {
       "num": "4.3",
       "name": "Dependency Mapping to Critical Processes",
       "areas": [
        {
         "num": "4.3.1",
         "name": "Identify Single Points of Failure and Concentration Risks",
         "controls": [
          {
           "id": "4.3.1.1",
           "text": "Regulated entities shall highlight areas where reliance on a single third-party or service could lead to operational disruption.",
           "key": "TPRM:4.3.1.1"
          },
          {
           "id": "4.3.1.2",
           "text": "Regulated entities shall identify third-party concentration risk exposure where dependency on a single vendor is on multiple critical services.",
           "key": "TPRM:4.3.1.2"
          }
         ]
        },
        {
         "num": "4.3.2",
         "name": "Interdependencies and BCP Integrations",
         "controls": [
          {
           "id": "4.3.2.1",
           "text": "Regulated entities shall document interconnections between third-parties and their internal processes, systems, or downstream dependencies to other vendors to assess cascading risk impacts.",
           "key": "TPRM:4.3.2.1"
          },
          {
           "id": "4.3.2.2",
           "text": "Regulated entities shall ensure that dependency mapping informs BCP and disaster recovery strategies, enabling timely response and recovery in the event of third-party failure.",
           "key": "TPRM:4.3.2.2"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 3,
     "section": "5",
     "name": "Contractual Agreements Considerations",
     "subdomains": [
      {
       "num": "5.1",
       "name": "Contractual Safeguards",
       "areas": [
        {
         "num": "5.1.1",
         "name": "Scope of Service, Termination Clauses, Right to Audit",
         "controls": [
          {
           "id": "5.1.1.1",
           "text": "Regulated entities shall ensure that Third-Party obtain, maintain, and provide evidence of all necessary approvals, licenses, permits, and authorizations required by applicable laws and regulations to perform the contracted services.",
           "key": "TPRM:5.1.1.1"
          }
         ]
        }
       ]
      },
      {
       "num": "5.2",
       "name": "Legal Binding Agreement",
       "areas": [
        {
         "num": "5.2.1",
         "name": "Contract Repository",
         "controls": [
          {
           "id": "5.2.1.1",
           "text": "Regulated entities shall maintain a consolidated repository of all third-party contracts and arrangements, including purchase orders (PO), non-PO engagements, and one-time vendor agreements, where third-parties access, process, or store Regulated entities' data. This repository shall be regularly updated, centrally accessible to authorized personnel, and structured to support oversight, compliance, and audit requirements.",
           "key": "TPRM:5.2.1.1"
          },
          {
           "id": "5.2.1.2",
           "text": "Regulated entities shall ensure that all third-party engagements are governed by legally binding agreements, duly executed by authorized signatories. These agreements shall be enforceable under applicable laws and reviewed by legal counsel prior to execution. Copies of executed contracts shall be securely maintained and made available for audit or regulatory review upon request. Contracts shall clearly define the scope of services, roles and responsibilities, and incorporate comprehensive safeguarding clauses, including but not limited to: a) right to audit the third-party and its subcontractors; b) exit strategies, including termination rights for non-compliance and mandatory handover of assets, data, and documentation; c) confidentiality, data privacy, and data portability/erasure obligations; d) adherence to the entity’s information and cybersecurity policies; e) access to all records and information relevant to the outsourced activity; f) liability for security breaches and data leakage, supported by cyber insurance or equivalent coverage; g) escrow arrangements for source code, if applicable; h) right to deny access to unauthorized personnel; i) defined performance metrics (e.g., SLA, TAT, service quality) and remedies for SLA breaches; j) visibility and control over subcontractor involvement; and k) dispute resolution mechanisms and termination conditions.",
           "key": "TPRM:5.2.1.2"
          }
         ]
        },
        {
         "num": "5.2.2",
         "name": "Contract Execution and Enforceability",
         "controls": [
          {
           "id": "5.2.2.1",
           "text": "Regulated entities shall ensure that all contractual arrangements with third-parties are governed by legally binding agreements that are duly executed by authorized signatories of both parties. These agreements shall clearly define the scope of services, roles and responsibilities, confidentiality obligations, liability clauses, dispute resolution mechanisms, and termination conditions.",
           "key": "TPRM:5.2.2.1"
          },
          {
           "id": "5.2.2.2",
           "text": "Regulated entities shall verify that such agreements are enforceable under applicable laws and are reviewed by legal counsel prior to execution. Copies of executed contracts shall be securely maintained and made available for audit or regulatory review upon request.",
           "key": "TPRM:5.2.2.2"
          }
         ]
        }
       ]
      },
      {
       "num": "5.3",
       "name": "Regular Monitoring and Assessment",
       "areas": [
        {
         "num": "5.3.1",
         "name": "Ongoing Oversight of Contractual Compliance",
         "controls": [
          {
           "id": "5.3.1.1",
           "text": "Regulated entities shall establish and implement a structured process for the regular monitoring and assessment of third-party compliance with contractual obligations. This includes: a. evaluating service delivery against agreed performance metrics Chapter 6 b. verifying adherence to legal and operational clauses (e.g., scope of services, termination rights, audit provisions) c. ensuring the effectiveness of back-to-back arrangements with subcontractors",
           "key": "TPRM:5.3.1.1"
          },
          {
           "id": "5.3.1.2",
           "text": "Monitoring activities shall be documented, and any deviations or risks identified shall be escalated and addressed through corrective actions, contract amendments, or enhanced oversight measures.",
           "key": "TPRM:5.3.1.2"
          }
         ]
        }
       ]
      },
      {
       "num": "5.4",
       "name": "Health Safety & Environment",
       "areas": [
        {
         "num": "5.4.1",
         "name": "Contractual adequacy",
         "controls": [
          {
           "id": "5.4.1.1",
           "text": "Regulated entities shall ensure that all contractual agreements with third-parties explicitly incorporate comprehensive Environmental, Health, and Safety (EHS) obligations. These contractual provisions shall: d. align with applicable regulatory standards and cover workplace safety, environmental protection, and emergency preparedness. e. require third-parties to maintain a formally documented EHS policy, approved by senior management, communicated to stakeholders, and periodically reviewed for relevance and effectiveness. f. mandate the implementation of a safety program addressing high-risk operational areas such as confined spaces, hazardous energy control (Lock Out/Tag Out), hot work, working at heights, and contractor EHS management. g. include requirements for documented contingency plans to manage pollutant releases (e.g., spills, emissions to air, water, or waste), with procedures for immediate response, mitigation, and regulatory reporting. h. ensure third-parties maintain valid permits, have no unresolved regulatory violations in the current financial year, and conduct documented safety training for their workforce. i. allow for periodic assessments by Regulated Entities to verify ongoing compliance with these EHS obligations.",
           "key": "TPRM:5.4.1.1"
          }
         ]
        }
       ]
      },
      {
       "num": "5.5",
       "name": "Financial Viability",
       "areas": [
        {
         "num": "5.5.1",
         "name": "Assessment of Financial Indicators",
         "controls": [
          {
           "id": "5.5.1.1",
           "text": "Regulated Entities shall establish a risk-based approach to assess the financial viability of third-parties throughout the engagement lifecycle. This includes incorporating contractual provisions that mandate the demonstration and maintenance of financial health: a. the depth and frequency of financial assessments shall be proportionate to the criticality of the third-party. b. for critical vendors, Regulated Entities shall perform comprehensive financial assessments, including analysis of key financial indicators such as credit ratings, current ratios, debt-equity ratios, profitability trends, and revenue growth. c. for non-critical vendors, basic financial health checks - such as verification of valid trade licenses, solvency confirmation, and absence of bankruptcy proceedings - may be deemed sufficient. d. this control supports ongoing monitoring and enables timely identification of financial instability risks that may impact service delivery or regulatory compliance.",
           "key": "TPRM:5.5.1.1"
          }
         ]
        }
       ]
      },
      {
       "num": "5.6",
       "name": "Compliance (Geopolitics, Regulatory, Organizational, Country and Legal)",
       "areas": [
        {
         "num": "5.6.1",
         "name": "Anti-Bribery and Anti-Corruption Policy",
         "controls": [
          {
           "id": "5.6.1.1",
           "text": "Regulated entities shall have documented and approved anti-bribery and anti-corruption policy that shall commensurate with the size, risk, and criticality of the third-party relationship, ensure that third-parties maintain a formally documented and approved Anti- Bribery and Anti-Corruption (ABAC) Policy.",
           "key": "TPRM:5.6.1.1"
          },
          {
           "id": "5.6.1.2",
           "text": "The (ABAC) Policy shall be communicated to all relevant employees, contractors, and agents, and, where appropriate, incorporated into the third-party’s Code of Conduct.",
           "key": "TPRM:5.6.1.2"
          },
          {
           "id": "5.6.1.3",
           "text": "The (ABAC) Policy shall be reviewed and updated at regular intervals-at least annually or upon significant regulatory or operational changes. Where feasible and proportionate to the risk, regulated entities shall maintain records of bribery or corruption-related investigations or legal actions.",
           "key": "TPRM:5.6.1.3"
          }
         ]
        },
        {
         "num": "5.6.2",
         "name": "Identification of Applicable Legislation & Contractual Requirements",
         "controls": [
          {
           "id": "5.6.2.1",
           "text": "Regulated Entities shall ensure that third-parties identify, document, and track all relevant legislative, statutory, regulatory, and contractual security requirements applicable to their operations. Compliance shall be maintained through a structured governance framework that includes: a. maintenance of a compliance register or tracker; b. regular reviews and updates based on changes in laws or contracts; c. assignment of ownership for each requirement; d. periodic audits and assessments to verify adherence; and e. documentation of evidence supporting compliance.",
           "key": "TPRM:5.6.2.1"
          }
         ]
        },
        {
         "num": "5.6.3",
         "name": "Litigation and Legal Exposure",
         "controls": [
          {
           "id": "5.6.3.1",
           "text": "Regulated entities shall ensure that third-parties disclose any litigation involving allegations of intellectual property infringement, misappropriation, or related claims. This includes cases involving the third-party itself, its directors, officers, owners, or majority shareholders, as well as any third-party products or services offered. Such disclosures shall be documented and incorporated into the entity’s legal compliance and third-party risk assessment framework.",
           "key": "TPRM:5.6.3.1"
          }
         ]
        }
       ]
      },
      {
       "num": "5.7",
       "name": "Corporate Governance",
       "areas": [
        {
         "num": "5.7.1",
         "name": "Investigation",
         "controls": [
          {
           "id": "5.7.1.1",
           "text": "Regulated entities shall ensure that third-parties disclose any investigations or audits conducted by regulators or government agencies for alleged non-compliance with applicable laws. This includes, but is not limited to, violations related to bribery, kickbacks, or other improper payments to government officials. Disclosures shall cover the third-party itself, as well as its directors, officers, majority shareholders, affiliated entities, and employees. Such information shall be documented and factored into Regulated entities' third-party risk assessment and compliance oversight processes.",
           "key": "TPRM:5.7.1.1"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 4,
     "section": "6",
     "name": "Risk Assessment and Monitoring",
     "subdomains": [
      {
       "num": "6.1",
       "name": "Identification, Assessment, and Mitigation",
       "areas": [
        {
         "num": "6.1.1",
         "name": "Conduct Periodic Reassessments",
         "controls": [
          {
           "id": "6.1.1.1",
           "text": "Regulated entities shall reassess third-party risks at defined intervals based on their risk tier, service criticality, and performance history. Trigger reassessments upon significant changes in services, regulations, threat landscape or upon renewal and breaches.",
           "key": "TPRM:6.1.1.1"
          }
         ]
        },
        {
         "num": "6.1.2",
         "name": "Identify Emerging Risks",
         "controls": [
          {
           "id": "6.1.2.1",
           "text": "Regulated entities shall continuously monitor for new risk vectors, including changes in legal frameworks, threat landscapes, and operational dependencies.",
           "key": "TPRM:6.1.2.1"
          }
         ]
        },
        {
         "num": "6.1.3",
         "name": "Mitigation Planning",
         "controls": [
          {
           "id": "6.1.3.1",
           "text": "Regulated entities shall develop and implement targeted treatment plans for identified risks. Each plan shall include: a. defined risk owner(s) b. specific mitigation actions c. timelines and milestones d. monitoring and reporting mechanisms",
           "key": "TPRM:6.1.3.1"
          }
         ]
        }
       ]
      },
      {
       "num": "6.2",
       "name": "Risk Classification",
       "areas": [
        {
         "num": "6.2.1",
         "name": "Classify Based on Inherent and Residual Risk",
         "controls": [
          {
           "id": "6.2.1.1",
           "text": "Regulated entities shall evaluate third-parties based on the nature of the service (inherent risk) and the effectiveness of controls in place (residual risk).",
           "key": "TPRM:6.2.1.1"
          }
         ]
        },
        {
         "num": "6.2.2",
         "name": "Determine Oversight Intensity",
         "controls": [
          {
           "id": "6.2.2.1",
           "text": "Regulated entities shall use classification outcomes to define the frequency and depth of due diligence, monitoring, and audit activities. High-risk third-parties should be subject to enhanced scrutiny and more frequent reviews.",
           "key": "TPRM:6.2.2.1"
          }
         ]
        },
        {
         "num": "6.2.3",
         "name": "Align with Regulatory Expectations",
         "controls": [
          {
           "id": "6.2.3.1",
           "text": "Regulated entities shall ensure that classification methodologies and oversight practices are consistent with regulatory guidance and leading international standards.",
           "key": "TPRM:6.2.3.1"
          }
         ]
        }
       ]
      },
      {
       "num": "6.3",
       "name": "Ongoing Monitoring of Critical Third Parties",
       "areas": [
        {
         "num": "6.3.1",
         "name": "Performance and SLA Monitoring",
         "controls": [
          {
           "id": "6.3.1.1",
           "text": "Regulated entities shall regularly track service delivery against agreed Service Level Agreements (SLAs) and Key Performance Indicators (KPIs) to ensure operational reliability.",
           "key": "TPRM:6.3.1.1"
          }
         ]
        },
        {
         "num": "6.3.2",
         "name": "Compliance and Risk Surveillance",
         "controls": [
          {
           "id": "6.3.2.1",
           "text": "Regulated entities shall monitor compliance with contractual obligations, regulatory requirements, and internal policies. Identify emerging risks such as geopolitical shifts, cyber threats, or financial instability.",
           "key": "TPRM:6.3.2.1"
          }
         ]
        },
        {
         "num": "6.3.3",
         "name": "Automated Risk Intelligence Tools",
         "controls": [
          {
           "id": "6.3.3.1",
           "text": "Regulated entities may leverage technology platforms that provide real-time alerts, external risk signals, and automated updates on third-party risk profiles. These tools could integrate with internal systems to support proactive decision-making.",
           "key": "TPRM:6.3.3.1"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 5,
     "section": "7",
     "name": "Business Continuity Management & Disaster Recovery",
     "subdomains": [
      {
       "num": "7.1",
       "name": "Business Continuity Plans",
       "areas": [
        {
         "num": "7.1.1",
         "name": "Business Continuity and Disaster Recovery Plans",
         "controls": [
          {
           "id": "7.1.1.1",
           "text": "Regulated Entities shall ensure that third-parties maintain a comprehensive Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that are formally documented, approved by relevant authorities, and effectively implemented.",
           "key": "TPRM:7.1.1.1"
          }
         ]
        }
       ]
      },
      {
       "num": "7.2",
       "name": "Data Back up and Replication",
       "areas": [
        {
         "num": "7.2.1",
         "name": "Policy Review and Maintenance",
         "controls": [
          {
           "id": "7.2.1.1",
           "text": "Regulated Entities shall ensure that third-parties periodically review and update their backup policies, procedures, and plan documents to maintain suitability, adequacy, and effectiveness. Reviews should account for changes in business operations, technology, and regulatory requirements, and shall include validation of backup and restoration processes. All updates shall be documented and approved through appropriate governance mechanisms.",
           "key": "TPRM:7.2.1.1"
          }
         ]
        },
        {
         "num": "7.2.2",
         "name": "Information Backup",
         "controls": [
          {
           "id": "7.2.2.1",
           "text": "Regulated Entities shall ensure that their third-parties have an approved backup policy and procedure governing the management, execution, and oversight of data backup activities. Additionally, third-party shall maintain a formally documented and authorized Backup Plan that includes: a. information to be backed up, including data types and criticality; b. identification of systems hosting the information (e.g., server or application names); c. supporting IT infrastructure details (e.g., hardware specifications, storage configurations); d. defined backup periodicity (e.g., daily, weekly, monthly, annual) based on business and data sensitivity requirements; and e. data retention schedules aligned with applicable legal, contractual, and regulatory obligations.",
           "key": "TPRM:7.2.2.1"
          }
         ]
        },
        {
         "num": "7.2.3",
         "name": "Contingency Environments - Change Management",
         "controls": [
          {
           "id": "7.2.3.1",
           "text": "Regulated Entities shall ensure that third-party service providers have a formal change management process in place to ensure that all changes are consistently replicated across primary and contingency environments.",
           "key": "TPRM:7.2.3.1"
          }
         ]
        }
       ]
      },
      {
       "num": "7.3",
       "name": "Periodic Testing of DR Capabilities",
       "areas": [
        {
         "num": "7.3.1",
         "name": "Availability of Key Infrastructure",
         "controls": [
          {
           "id": "7.3.1.1",
           "text": "Regulated Entities shall ensure that their third-party service providers maintain a Disaster Recovery (DR) center to support continuity of operations during major disruptions. The DR center should be geographically separated from the primary data center, preferably located in a different seismic zone, to mitigate regional risks and enhance redundancy.",
           "key": "TPRM:7.3.1.1"
          },
          {
           "id": "7.3.1.2",
           "text": "Ensure all key infrastructure should be deployed in High Availability (HA) mode to ensure uninterrupted service delivery.",
           "key": "TPRM:7.3.1.2"
          }
         ]
        },
        {
         "num": "7.3.2",
         "name": "Resilience testing",
         "controls": [
          {
           "id": "7.3.2.1",
           "text": "Regulated Entities shall ensure that third-parties conduct periodic testing of their Business Continuity Plans (BCPs) to validate effectiveness and readiness in responding to disruptive events.",
           "key": "TPRM:7.3.2.1"
          },
          {
           "id": "7.3.2.2",
           "text": "Regulated Entities shall ensure that third-parties have defined and documented Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all critical services provided.",
           "key": "TPRM:7.3.2.2"
          },
          {
           "id": "7.3.2.3",
           "text": "Regulated Entities shall ensure that parameters be reviewed periodically and aligned with business impact assessments and agreed service-level expectations.",
           "key": "TPRM:7.3.2.3"
          }
         ]
        }
       ]
      },
      {
       "num": "7.4",
       "name": "Recovery and Restoration Procedures",
       "areas": [
        {
         "num": "7.4.1",
         "name": "Restoration testing",
         "controls": [
          {
           "id": "7.4.1.1",
           "text": "Regulated Entities shall ensure that third-parties perform periodic restoration testing of backup data to verify its integrity, accuracy, and recoverability. Each test shall be documented in a Backup Restoration Log, detailing the date, scope, results, and any issues encountered.",
           "key": "TPRM:7.4.1.1"
          },
          {
           "id": "7.4.1.2",
           "text": "Discrepancies or errors identified during testing shall be promptly reported to relevant stakeholders and addressed through corrective actions to ensure the reliability of backup systems.",
           "key": "TPRM:7.4.1.2"
          }
         ]
        }
       ]
      },
      {
       "num": "7.5",
       "name": "Business Continuity Management & Recovery",
       "areas": [
        {
         "num": "7.5.1",
         "name": "Contractual guarantees",
         "controls": [
          {
           "id": "7.5.1.1",
           "text": "Regulated Entities shall ensure that third-parties offer contractual guarantees, such as Service Level Agreements (SLAs), to ensure reliability and accountability in the delivery of products and services. SLAs should define measurable performance metrics, including uptime commitments, response and resolution times, and applicable penalties or remedies for service disruptions. Regulated Entities shall ensure that documentation of all active SLAs is maintained and clearly communicated to relevant stakeholders.",
           "key": "TPRM:7.5.1.1"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 6,
     "section": "8",
     "name": "Incident Management",
     "subdomains": [
      {
       "num": "8.1",
       "name": "Incident Detection and Monitoring",
       "areas": [
        {
         "num": "8.1.1",
         "name": "Threat Detection Capability",
         "controls": [
          {
           "id": "8.1.1.1",
           "text": "All applicable controls related to incident detection and monitoring, defined in the Cyber Resilience Baselines, shall be evaluated as a part of the assessment process.",
           "key": "TPRM:8.1.1.1"
          },
          {
           "id": "8.1.1.2",
           "text": "Regulated Entities shall ensure that third-parties implement real-time security monitoring tools that continuously track and alert on unauthorized or anomalous activity within infrastructure, endpoints, and cloud systems.",
           "key": "TPRM:8.1.1.2"
          },
          {
           "id": "8.1.1.3",
           "text": "Regulated Entities shall ensure that third-parties configure systems to detect abnormal behavior patterns that may indicate compromised accounts or malicious insider activity through User and Entity Behavior Analytics (UEBA).",
           "key": "TPRM:8.1.1.3"
          },
          {
           "id": "8.1.1.4",
           "text": "Regulated Entities shall ensure that third-parties subscribe to and integrate actionable threat intelligence feeds to enhance detection capabilities against known indicators of compromise (IOCs) and emerging global threats.",
           "key": "TPRM:8.1.1.4"
          }
         ]
        },
        {
         "num": "8.1.2",
         "name": "Logging and Monitoring",
         "controls": [
          {
           "id": "8.1.2.1",
           "text": "Regulated Entities shall ensure that third-parties establish centralized and tamper-resistant logging of critical system events, with defined retention, log review schedules, and correlation to support incident detection and analysis.",
           "key": "TPRM:8.1.2.1"
          },
          {
           "id": "8.1.2.2",
           "text": "Regulated entities shall ensure that third-parties enforce heightened monitoring and alerting controls around mission-critical systems, such as finance, authentication, and customer data stores.",
           "key": "TPRM:8.1.2.2"
          },
          {
           "id": "8.1.2.3",
           "text": "Regulated entities shall ensure that third-parties establish processes to triage and prioritize alerts based on severity, impact, asset criticality, and data sensitivity to reduce alert fatigue and ensure rapid incident response.",
           "key": "TPRM:8.1.2.3"
          },
          {
           "id": "8.1.2.4",
           "text": "Regulated entities shall ensure that third-parties define the scope of systems to be logged for incident detection purposes and conduct periodic reviews to ensure completeness and compliance with retention policies.",
           "key": "TPRM:8.1.2.4"
          },
          {
           "id": "8.1.2.5",
           "text": "Regulated entities shall ensure that third-parties implement tools and protocols to detect unauthorized actions or unusual behaviors by internal users, with contextual awareness of access levels, job roles, and data movement.",
           "key": "TPRM:8.1.2.5"
          },
          {
           "id": "8.1.2.6",
           "text": "Regulated entities shall ensure that third-parties configure cloud platforms (e.g., AWS CloudTrail, Azure Monitor) to capture administrative actions, user activity, and API events, ensuring alerting and retention settings are compliant.",
           "key": "TPRM:8.1.2.6"
          },
          {
           "id": "8.1.2.7",
           "text": "Regulated Entities shall ensure that third-parties integrate SaaS platforms with SIEM or CASB tools and enable event-based notifications for critical activities like account takeovers and data sharing,",
           "key": "TPRM:8.1.2.7"
          },
          {
           "id": "8.1.2.8",
           "text": "Regulated Entities shall offer secure, anonymous channels for employees or third-parties to report suspected cybersecurity or privacy incidents, with clear procedures for investigation.",
           "key": "TPRM:8.1.2.8"
          }
         ]
        }
       ]
      },
      {
       "num": "8.2",
       "name": "Incident Escalation and Communication Protocols",
       "areas": [
        {
         "num": "8.2.1",
         "name": "Internal and External Notification Criteria",
         "controls": [
          {
           "id": "8.2.1.1",
           "text": "Regulated entities and their third-parties shall define and maintain an incident escalation matrix outlining severity levels, responsible personnel, communication timelines, and response thresholds for various incident types.",
           "key": "TPRM:8.2.1.1"
          },
          {
           "id": "8.2.1.2",
           "text": "Regulated entities shall ensure that third-parties document internal notification protocols for promptly informing senior leadership, legal, and compliance stakeholders during major or high-risk incidents.",
           "key": "TPRM:8.2.1.2"
          },
          {
           "id": "8.2.1.3",
           "text": "Regulated entities shall identify legal and regulatory thresholds for incident reporting (in line with the timelines defined in the Operational Risk Baselines) and establish workflows to ensure timely notifications, from third-parties.",
           "key": "TPRM:8.2.1.3"
          },
          {
           "id": "8.2.1.4",
           "text": "Regulated entities shall establish criteria, channels, and content templates for notifying affected customers of security breaches, including support channels and mitigation advice with third-parties.",
           "key": "TPRM:8.2.1.4"
          },
          {
           "id": "8.2.1.5",
           "text": "Regulated entities shall define procedures for handling media inquiries, public disclosures, and social media messaging during active third-party incidents to avoid reputational damage and misinformation.",
           "key": "TPRM:8.2.1.5"
          },
          {
           "id": "8.2.1.6",
           "text": "Regulated entities shall establish agreements with third-party vendors and cloud providers for mutual notification, impact assessment, and collaborative response to incidents involving shared systems or data.",
           "key": "TPRM:8.2.1.6"
          }
         ]
        },
        {
         "num": "8.2.2",
         "name": "Secure Communication Channels",
         "controls": [
          {
           "id": "8.2.2.1",
           "text": "Regulated entities shall ensure that third-parties have availability of secure, redundant communication tools (e.g., Signal, PGP-encrypted email) for use during incident response to prevent eavesdropping.",
           "key": "TPRM:8.2.2.1"
          },
          {
           "id": "8.2.2.2",
           "text": "Regulated entities shall ensure that third-parties periodically test communication trees, escalation paths, and approval chains for incident response to verify response readiness and reduce decision-making delays.",
           "key": "TPRM:8.2.2.2"
          },
          {
           "id": "8.2.2.3",
           "text": "Regulated entities shall ensure that third-parties maintain detailed logs of all internal and external communications conducted during incidents, including timestamps, recipients, and delivery confirmation.",
           "key": "TPRM:8.2.2.3"
          }
         ]
        }
       ]
      },
      {
       "num": "8.3",
       "name": "Root Cause Analysis",
       "areas": [
        {
         "num": "8.3.1",
         "name": "RCA Standard and Documentation",
         "controls": [
          {
           "id": "8.3.1.1",
           "text": "Regulated entities shall ensure that third-parties perform and document formal Root Cause Analysis (RCA) requiring RCA for High and Medium incidents (as defined in the Operational Resilience Baselines).",
           "key": "TPRM:8.3.1.1"
          },
          {
           "id": "8.3.1.2",
           "text": "Regulated entities shall ensure that third-parties compile RCA reports with background, root causes, corrective actions, and preventive recommendations, and share them with senior leadership for review and approval.",
           "key": "TPRM:8.3.1.2"
          },
          {
           "id": "8.3.1.3",
           "text": "Regulated entities shall ensure that third-parties assign defined roles to security, IT, legal, and business stakeholders in the RCA process, ensuring cross-functional participation and agreement on findings.",
           "key": "TPRM:8.3.1.3"
          }
         ]
        },
        {
         "num": "8.3.2",
         "name": "Evidence Collection and Retention",
         "controls": [
          {
           "id": "8.3.2.1",
           "text": "Regulated entities shall ensure that third-parties collect relevant forensic evidence (e.g., logs, system images) during incident response, preserve it with documented chain-of- custody for RCA and legal purposes and enable Regulated Entities with access.",
           "key": "TPRM:8.3.2.1"
          },
          {
           "id": "8.3.2.2",
           "text": "Regulated entities shall ensure that third-parties reconstruct incident timelines from detection to recovery using logs, alerts, and communications to identify gaps in detection and delays in response.",
           "key": "TPRM:8.3.2.2"
          },
          {
           "id": "8.3.2.3",
           "text": "Regulated entities shall ensure that third-parties document specific control failures or process weaknesses that led to the incident and assess their effectiveness during detection, escalation, or containment.",
           "key": "TPRM:8.3.2.3"
          }
         ]
        },
        {
         "num": "8.3.3",
         "name": "Incident Documentation",
         "controls": [
          {
           "id": "8.3.3.1",
           "text": "Regulated entities shall ensure that third-parties review past incidents to identify trends, Chapter 6 recurring vulnerabilities, or systemic issues contributing to repeated breaches or disruptions.",
           "key": "TPRM:8.3.3.1"
          },
          {
           "id": "8.3.3.2",
           "text": "Regulated entities shall ensure that third-parties maintain a central repository of lessons learned from all security incidents and use these insights to drive future process and control improvements.",
           "key": "TPRM:8.3.3.2"
          },
          {
           "id": "8.3.3.3",
           "text": "Regulated entities shall ensure that third-parties incorporate any changes identified during RCA into updated playbooks, SOPs, detection rules, or technical configurations within agreed timelines.",
           "key": "TPRM:8.3.3.3"
          },
          {
           "id": "8.3.3.4",
           "text": "Regulated entities shall ensure that third-parties define KPIs for the closure of RCA action items, track them through dashboards, and periodically report progress to stakeholders.",
           "key": "TPRM:8.3.3.4"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 7,
     "section": "9",
     "name": "Data Protection and Confidentiality",
     "subdomains": [
      {
       "num": "9.1",
       "name": "Data Encryption and Masking",
       "areas": [
        {
         "num": "9.1.1",
         "name": "Encryption and Key Management",
         "controls": [
          {
           "id": "9.1.1.1",
           "text": "Regulated entities shall ensure that third-parties establish a comprehensive encryption policy that mandates the protection of sensitive data using encryption both in transit and at rest. The sensitive data can include personal data, as well as internal confidential organizational data. This policy shall specify algorithm standards, key management practices, and the scope of assets covered.",
           "key": "TPRM:9.1.1.1"
          },
          {
           "id": "9.1.1.2",
           "text": "Regulated entities shall ensure that third-parties implement a centralized key management system to ensure the secure generation, rotation, storage, revocation, and disposal of cryptographic keys used in personal data encryption.",
           "key": "TPRM:9.1.1.2"
          },
          {
           "id": "9.1.1.3",
           "text": "Regulated entities shall ensure that all personal data transmitted over public or untrusted networks by third-parties is encrypted using strong cryptographic protocols (e.g., TLS 1.2 or above) to prevent interception or tampering.",
           "key": "TPRM:9.1.1.3"
          },
          {
           "id": "9.1.1.4",
           "text": "Regulated entities shall ensure that all personal data stored in databases, files, portable devices, or media by third-parties is encrypted using approved algorithms (e.g., AES-256), and the encryption is enforced through technical controls.",
           "key": "TPRM:9.1.1.4"
          },
          {
           "id": "9.1.1.5",
           "text": "Regulated entities shall ensure that third-parties enforce encryption policies on all end-user devices (laptops, mobile phones, tablets) where personal data is stored or accessed, including mobile device management (MDM) for enforcement.",
           "key": "TPRM:9.1.1.5"
          },
          {
           "id": "9.1.1.6",
           "text": "Regulated entities shall ensure that sensitive data is either masked or anonymized by third- parties before being used in development, test, or sandbox environments to prevent unauthorized access or misuse. The sensitive data can include personal data, as well as internal confidential organizational data.",
           "key": "TPRM:9.1.1.6"
          },
          {
           "id": "9.1.1.7",
           "text": "Regulated entities shall ensure that third-parties assess and implement tokenization or pseudonymization techniques to reduce the identifiability of personal data, especially in analytics or multi-tenant environments.",
           "key": "TPRM:9.1.1.7"
          },
          {
           "id": "9.1.1.8",
           "text": "Regulated entities shall ensure that third-parties deploy approved data masking tools to enforce consistent redaction or substitution of sensitive fields in structured and unstructured data sources.",
           "key": "TPRM:9.1.1.8"
          },
          {
           "id": "9.1.1.9",
           "text": "Regulated entities shall ensure that all backup media or snapshots containing personal data in third-party ecosystem are encrypted at rest using standard encryption algorithms and stored securely with access controls.",
           "key": "TPRM:9.1.1.9"
          },
          {
           "id": "9.1.1.10",
           "text": "Regulated entities shall ensure that third-parties define and apply standardized cryptographic algorithms approved by recognized bodies (e.g., AES-256, RSA 2048) and prohibit weak or outdated algorithms.",
           "key": "TPRM:9.1.1.10"
          },
          {
           "id": "9.1.1.11",
           "text": "Regulated entities shall ensure that access to encrypted personal data is granted only to authorized personnel based on business need, with decryption activity monitored and logged, within third-party ecosystem.",
           "key": "TPRM:9.1.1.11"
          },
          {
           "id": "9.1.1.12",
           "text": "Regulated entities shall ensure that third-parties regularly review encryption implementation across systems to ensure compliance with policy and detect any deviations or unprotected assets.",
           "key": "TPRM:9.1.1.12"
          }
         ]
        }
       ]
      },
      {
       "num": "9.2",
       "name": "Data Retention and Disposal",
       "areas": [
        {
         "num": "9.2.1",
         "name": "Data Retention and Archival",
         "controls": [
          {
           "id": "9.2.1.1",
           "text": "Regulated entities shall ensure that third-parties establish and implement a personal data retention policy that defines maximum retention periods for each data category, aligned with business purpose and legal requirements.",
           "key": "TPRM:9.2.1.1"
          },
          {
           "id": "9.2.1.2",
           "text": "Regulated entities shall ensure that third-parties define and map retention periods for each processing activity, ensuring alignment with the original data collection purpose and business relevance.",
           "key": "TPRM:9.2.1.2"
          },
          {
           "id": "9.2.1.3",
           "text": "Regulated entities shall ensure that third-parties identify applicable legal and regulatory requirements for personal data retention and integrate them into the organizational retention policy.",
           "key": "TPRM:9.2.1.3"
          },
          {
           "id": "9.2.1.4",
           "text": "Regulated entities shall ensure that third-parties review retained personal data at regular intervals to identify records exceeding defined limits and flag them for secure deletion or archival.",
           "key": "TPRM:9.2.1.4"
          },
          {
           "id": "9.2.1.5",
           "text": "Regulated entities shall ensure that third-parties implement technical and procedural safeguards to ensure personal data is permanently destroyed when it reaches end of life, using methods such as shredding, secure wiping, or degaussing.",
           "key": "TPRM:9.2.1.5"
          },
          {
           "id": "9.2.1.6",
           "text": "Regulated entities shall ensure that third-parties shall log personal data disposal activities including timestamp, responsible personnel, method of destruction, and confirmation of successful deletion.",
           "key": "TPRM:9.2.1.6"
          },
          {
           "id": "9.2.1.7",
           "text": "Regulated entities shall ensure that third-parties configure automated systems and applications to delete or anonymize personal data based on pre-set retention triggers and schedules.",
           "key": "TPRM:9.2.1.7"
          },
          {
           "id": "9.2.1.8",
           "text": "Regulated entities shall ensure that third-parties perform periodic reviews of archived personal data to ensure ongoing necessity, legal compliance, and timely removal of redundant data sets.",
           "key": "TPRM:9.2.1.8"
          },
          {
           "id": "9.2.1.9",
           "text": "Regulated entities shall ensure that third-parties contracts include enforceable clauses for secure data disposal or return upon contract termination.",
           "key": "TPRM:9.2.1.9"
          },
          {
           "id": "9.2.1.10",
           "text": "Regulated entities shall ensure that third-parties document exceptions to data retention schedules, supported by legal or operational justifications, and subject to approval by the DPO or designated authority.",
           "key": "TPRM:9.2.1.10"
          },
          {
           "id": "9.2.1.11",
           "text": "Regulated entities shall validate that cloud providers support complete, auditable, and timely deletion of personal data from all storage layers when requested.",
           "key": "TPRM:9.2.1.11"
          }
         ]
        },
        {
         "num": "9.2.2",
         "name": "Awareness and Training",
         "controls": [
          {
           "id": "9.2.2.1",
           "text": "Regulated entities shall ensure that third-parties incorporate data retention and secure disposal practices into employee privacy training programs and monitor comprehension through assessments.",
           "key": "TPRM:9.2.2.1"
          }
         ]
        }
       ]
      },
      {
       "num": "9.3",
       "name": "Data Classification and Handling Policies",
       "areas": [
        {
         "num": "9.3.1",
         "name": "Data Classification and Inventory",
         "controls": [
          {
           "id": "9.3.1.1",
           "text": "Regulated entities shall ensure that third-parties maintain a real-time, centralized inventory of all sensitive data assets, including source, classification level, storage location, format, and assigned data owner. The sensitive data can include personal data, as well as internal confidential organizational data.",
           "key": "TPRM:9.3.1.1"
          },
          {
           "id": "9.3.1.2",
           "text": "Regulated entities shall ensure that third-parties implement and enforce a classification policy to categorize personal data based on sensitivity and processing risk, assigning clear handling rules per classification.",
           "key": "TPRM:9.3.1.2"
          },
          {
           "id": "9.3.1.3",
           "text": "Regulated entities shall ensure that all personal data is properly labelled or tagged within third-party storage systems and applications to indicate its classification and handling requirements.",
           "key": "TPRM:9.3.1.3"
          },
          {
           "id": "9.3.1.4",
           "text": "Regulated entities shall ensure that third-parties designate responsible data owners for each personal data category to manage lifecycle, access, quality, and classification maintenance.",
           "key": "TPRM:9.3.1.4"
          },
          {
           "id": "9.3.1.5",
           "text": "Regulated entities shall ensure that third-parties map personal data storage locations across environments (e.g., on-premise, cloud, mobile) and ensure traceability and compliance with classification labels.",
           "key": "TPRM:9.3.1.5"
          },
          {
           "id": "9.3.1.6",
           "text": "Regulated entities shall ensure that third-parties implement role-based access control mechanisms that limit access to personal data based on its classification, and conduct periodic access reviews.",
           "key": "TPRM:9.3.1.6"
          },
          {
           "id": "9.3.1.7",
           "text": "Regulated entities shall ensure that third-parties review personal data inventories, ownership, and classification tags on at least an annual basis or upon significant operational changes.",
           "key": "TPRM:9.3.1.7"
          }
         ]
        },
        {
         "num": "9.3.2",
         "name": "Data Handling",
         "controls": [
          {
           "id": "9.3.2.1",
           "text": "Regulated entities shall ensure that third-parties document detailed handling procedures for each classification level, covering storage, transfer, encryption, disposal, and breach escalation steps.",
           "key": "TPRM:9.3.2.1"
          },
          {
           "id": "9.3.2.2",
           "text": "Regulated entities shall ensure that third-parties identify and map all cross-border personal data transfers, specifying transfer mechanisms (e.g., SCCs, BCRs) and destination countries per classification.",
           "key": "TPRM:9.3.2.2"
          },
          {
           "id": "9.3.2.3",
           "text": "Regulated entities shall ensure that third-parties deploy automated discovery and classification tools capable of scanning repositories, detecting personal data, and tagging it as per policy.",
           "key": "TPRM:9.3.2.3"
          },
          {
           "id": "9.3.2.4",
           "text": "Regulated entities shall ensure that each classified personal data item is associated with a documented lawful basis for processing, and this is captured within the data inventory by third-parties.",
           "key": "TPRM:9.3.2.4"
          }
         ]
        },
        {
         "num": "9.3.3",
         "name": "Awareness on Classification",
         "controls": [
          {
           "id": "9.3.3.1",
           "text": "Regulated entities shall ensure that third-parties provide training to relevant staff on the classification policy and proper handling techniques for different categories of personal data, with emphasis on risk mitigation.",
           "key": "TPRM:9.3.3.1"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 8,
     "section": "10",
     "name": "Sub-Contracting",
     "subdomains": [
      {
       "num": "10.1",
       "name": "Disclosure of Subcontractor and Approval from Regulated Entities",
       "areas": [
        {
         "num": "10.1.1",
         "name": "Disclosure and Approval:",
         "controls": [
          {
           "id": "10.1.1.1",
           "text": "Regulated entities shall ensure that the third-parties have the following: a) Identification of sub-contracting and approval from Regulated entities before utilizing sub-contractors for the active/new/change of scope of service b) Vendor Risk Management Policy and Procedure c) Identification of \"nth parties\"",
           "key": "TPRM:10.1.1.1"
          }
         ]
        }
       ]
      },
      {
       "num": "10.2",
       "name": "Monitoring and Oversight",
       "areas": [
        {
         "num": "10.2.1",
         "name": "Sub-contracting Monitoring and Oversight",
         "controls": [
          {
           "id": "10.2.1.1",
           "text": "Regulated entities shall ensure that there is a sub-contracting agreement signed with the sub-contracted vendor(s) and the third-parties and risk assessment is performed on them.",
           "key": "TPRM:10.2.1.1"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 9,
     "section": "11",
     "name": "Exit Strategy",
     "subdomains": [
      {
       "num": "11.1",
       "name": "Exit Strategy Planning",
       "areas": [
        {
         "num": "11.1.1",
         "name": "Exit Plan and Process",
         "controls": [
          {
           "id": "11.1.1.1",
           "text": "Regulated entities shall have a process to off-board / de-activate / blacklist third-party engagements, covering different scenarios while ensuring service continuity.",
           "key": "TPRM:11.1.1.1"
          },
          {
           "id": "11.1.1.2",
           "text": "Regulated entities shall have a formalized checklist for off-boarding of third-party engagement.",
           "key": "TPRM:11.1.1.2"
          },
          {
           "id": "11.1.1.3",
           "text": "Regulated entities shall have the exit/end of agreement/termination clauses in all third- party agreements.",
           "key": "TPRM:11.1.1.3"
          },
          {
           "id": "11.1.1.4",
           "text": "Regulated entities shall conduct knowledge transfer session with the third-party to ensure that all information / knowledge base including all process documents are taken over",
           "key": "TPRM:11.1.1.4"
          },
          {
           "id": "11.1.1.5",
           "text": "Regulated entities shall take disposal certificate from the third-party post removal / deletion / purging of necessary information from their system, post the data retention period is completed, wherever applicable.",
           "key": "TPRM:11.1.1.5"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 10,
     "section": "12",
     "name": "Storage of Data",
     "subdomains": [
      {
       "num": "12.1",
       "name": "Data Storage Security",
       "areas": [
        {
         "num": "12.1.1",
         "name": "Storage Access and Segmentation",
         "controls": [
          {
           "id": "12.1.1.1",
           "text": "Regulated entities shall ensure that third-parties enforce role-based access control (RBAC) for all storage environments, ensuring only authorized personnel can access, modify, or delete data based on job responsibilities.",
           "key": "TPRM:12.1.1.1"
          },
          {
           "id": "12.1.1.2",
           "text": "Regulated entities shall ensure that third-parties logically or physically segregate storage locations for different data classifications (e.g., public, internal, restricted) to prevent unauthorized access or data leakage",
           "key": "TPRM:12.1.1.2"
          },
          {
           "id": "12.1.1.3",
           "text": "Regulated entities shall ensure that third-parties maintain a comprehensive inventory of all physical and cloud-based storage locations where personal, sensitive, or regulated data resides, including geographic location",
           "key": "TPRM:12.1.1.3"
          },
          {
           "id": "12.1.1.4",
           "text": "Regulated entities shall ensure that third-parties restrict use of portable storage (e.g., USB drives, external HDDs) and enforce encryption and tracking mechanisms for permitted devices.",
           "key": "TPRM:12.1.1.4"
          }
         ]
        },
        {
         "num": "12.1.2",
         "name": "Storage Configuration Management",
         "controls": [
          {
           "id": "12.1.2.1",
           "text": "Regulated entities shall ensure that third-parties define and implement baseline configurations for all data storage systems, including permissions, patch levels, and encryption settings.",
           "key": "TPRM:12.1.2.1"
          },
          {
           "id": "12.1.2.2",
           "text": "Regulated entities shall ensure that third-parties configure cloud storage services with encryption, access control, activity logging, and data residency compliance in line with organizational security policies.",
           "key": "TPRM:12.1.2.2"
          },
          {
           "id": "12.1.2.3",
           "text": "Regulated entities shall ensure that third-parties implement network segmentation to isolate critical storage infrastructure from general corporate networks and reduce the attack surface.",
           "key": "TPRM:12.1.2.3"
          }
         ]
        }
       ]
      },
      {
       "num": "12.2",
       "name": "Storage Lifecycle Management",
       "areas": [
        {
         "num": "12.2.1",
         "name": "Data Retention",
         "controls": [
          {
           "id": "12.2.1.1",
           "text": "Regulated Entities shall ensure that third-parties implement automated mechanisms within storage platforms to enforce retention periods and flag or delete expired data.",
           "key": "TPRM:12.2.1.1"
          },
          {
           "id": "12.2.1.2",
           "text": "Regulated entities shall ensure that third-parties securely delete data using methods aligned with best practices (e.g., cryptographic erase, secure wipe) to ensure data cannot be reconstructed.",
           "key": "TPRM:12.2.1.2"
          },
          {
           "id": "12.2.1.3",
           "text": "Regulated entities shall ensure data stored in backup repositories by third-parties adheres to the same retention, access control, and encryption policies as primary data stores.",
           "key": "TPRM:12.2.1.3"
          }
         ]
        },
        {
         "num": "12.2.2",
         "name": "Archival and Purge",
         "controls": [
          {
           "id": "12.2.2.1",
           "text": "Regulated entities shall ensure that third-parties define archival policies for inactive or legacy data, ensuring that only essential data is retained and remains accessible when needed.",
           "key": "TPRM:12.2.2.1"
          },
          {
           "id": "12.2.2.2",
           "text": "Regulated entities shall ensure that third-parties perform scheduled reviews of stored data and purge non-essential or obsolete records based on data minimization principles.",
           "key": "TPRM:12.2.2.2"
          },
          {
           "id": "12.2.2.3",
           "text": "Regulated entities shall ensure that third-parties periodically audit data storage platforms to ensure compliance with the defined retention and deletion policies.",
           "key": "TPRM:12.2.2.3"
          },
          {
           "id": "12.2.2.4",
           "text": "Regulated entities shall ensure that third-parties define procedures for data migration across storage platforms, ensuring secure handling, classification preservation, and integrity validation.",
           "key": "TPRM:12.2.2.4"
          },
          {
           "id": "12.2.2.5",
           "text": "Regulated entities shall ensure that third-parties periodically evaluate stored data sets to eliminate unnecessary personal or duplicate data in accordance with data minimization obligations.",
           "key": "TPRM:12.2.2.5"
          },
          {
           "id": "12.2.2.6",
           "text": "Regulated entities shall ensure that third-parties implement appropriate storage redundancy (e.g., RAID, replication) aligned with criticality and availability needs, ensuring resilience and continuity.",
           "key": "TPRM:12.2.2.6"
          }
         ]
        }
       ]
      },
      {
       "num": "12.3",
       "name": "Data Integrity and Availability",
       "areas": [
        {
         "num": "12.3.1",
         "name": "Backup and Recovery",
         "controls": [
          {
           "id": "12.3.1.1",
           "text": "Regulated entities shall ensure that third-parties establish and test comprehensive backup and restoration procedures for all critical data to ensure data availability and resilience.",
           "key": "TPRM:12.3.1.1"
          },
          {
           "id": "12.3.1.2",
           "text": "Regulated entities shall ensure that third-parties implement automated integrity checks (e.g., checksums, hashes) on stored data to detect corruption or unauthorized changes.",
           "key": "TPRM:12.3.1.2"
          },
          {
           "id": "12.3.1.3",
           "text": "Regulated entities shall ensure that third-parties deploy storage systems with fault- tolerance features (e.g., failover, replication) to ensure continuous access to critical data even during hardware failure or outages.",
           "key": "TPRM:12.3.1.3"
          },
          {
           "id": "12.3.1.4",
           "text": "Regulated entities shall ensure that third-parties define time-bound objectives (RTO/RPO) for restoring access to data in case of disruptions and monitor adherence through simulations and reviews.",
           "key": "TPRM:12.3.1.4"
          },
          {
           "id": "12.3.1.5",
           "text": "Regulated entities shall ensure that third-parties use write-once or immutable storage configurations for critical system logs, audit trails, and evidence repositories to prevent tampering or deletion.",
           "key": "TPRM:12.3.1.5"
          },
          {
           "id": "12.3.1.6",
           "text": "Regulated entities shall ensure that third-parties integrate storage infrastructure with the enterprise disaster recovery plan to ensure timely and secure restoration of stored data following a major incident.",
           "key": "TPRM:12.3.1.6"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 11,
     "section": "13",
     "name": "Cross-Border Transaction",
     "subdomains": [
      {
       "num": "13.1",
       "name": "Regulatory & Legal Compliance",
       "areas": [
        {
         "num": "13.1.1",
         "name": "Transactional Controls",
         "controls": [
          {
           "id": "13.1.1.1",
           "text": "Regulated entities shall route cross-border payments exclusively via licensed payment systems recognized by CBK, ensuring full compliance with regulations and cross-border settlement standards (e.g., FSB PFMIs).",
           "key": "TPRM:13.1.1.1"
          },
          {
           "id": "13.1.1.2",
           "text": "Regulated entities shall maintain complete documentation, including invoices, bills of lading, and customs entries, as per trade regulations and international norms.",
           "key": "TPRM:13.1.1.2"
          },
          {
           "id": "13.1.1.3",
           "text": "Regulated entities shall screen counterparties and transactions against FATF, UN, US, EU, and other internationally recognized sanctions and embargo lists in real time.",
           "key": "TPRM:13.1.1.3"
          },
          {
           "id": "13.1.1.4",
           "text": "Regulated entities shall collect and validate valid LEIs for counterparties involved in transactions above defined thresholds, complying with global LEI standards.",
           "key": "TPRM:13.1.1.4"
          },
          {
           "id": "13.1.1.5",
           "text": "Regulated entities shall verify that cross-border transactions have the necessary CBK approvals and adhere to foreign exchange control authorizations, corporate licensing, and sector-specific limits.",
           "key": "TPRM:13.1.1.5"
          }
         ]
        }
       ]
      },
      {
       "num": "13.2",
       "name": "Due Diligence & KYC/AML",
       "areas": [
        {
         "num": "13.2.1",
         "name": "Due Diligence Process",
         "controls": [
          {
           "id": "13.2.1.1",
           "text": "Regulated entities shall perform comprehensive KYC, including identity verification and Chapter 6 beneficial ownership checks, prior to initiating cross-border transactions.",
           "key": "TPRM:13.2.1.1"
          },
          {
           "id": "13.2.1.2",
           "text": "Regulated entities shall apply risk-based due diligence, considering jurisdictional risk, transaction size, and customer profile, and document all findings accordingly.",
           "key": "TPRM:13.2.1.2"
          },
          {
           "id": "13.2.1.3",
           "text": "Regulated entities shall perform enhanced due diligence, including source-of-funds and senior management approval, on PEPs, high-risk countries, or large-value transactions.",
           "key": "TPRM:13.2.1.3"
          },
          {
           "id": "13.2.1.4",
           "text": "Regulated entities shall transmit full originator and beneficiary details in accordance with FATF Recommendation 16 (Travel Rule) for all cross-border transfers above applicable thresholds.",
           "key": "TPRM:13.2.1.4"
          },
          {
           "id": "13.2.1.5",
           "text": "Regulated entities shall assess and document AML/CFT controls of correspondent banks per FATF and BIS guidance, with periodic updates based on risk.",
           "key": "TPRM:13.2.1.5"
          }
         ]
        }
       ]
      },
      {
       "num": "13.3",
       "name": "Secure Data Transfers & Privacy",
       "areas": [
        {
         "num": "13.3.1",
         "name": "Data Minimization and Secure Transmission",
         "controls": [
          {
           "id": "13.3.1.1",
           "text": "Regulated entities shall limit cross-border data to only what is strictly necessary and proportionate, in adherence to CBK privacy directives and international data protection frameworks.",
           "key": "TPRM:13.3.1.1"
          },
          {
           "id": "13.3.1.2",
           "text": "Regulated entities shall ensure cross-border payment data is transmitted using encrypted methods (e.g., TLS 1.2+, IPsec) and authenticated interfaces.",
           "key": "TPRM:13.3.1.2"
          },
          {
           "id": "13.3.1.3",
           "text": "Regulated Entities shall implement legal transfer mechanisms (e.g., SCCs, BCRs), or obtain CBK permissions for data transfers.",
           "key": "TPRM:13.3.1.3"
          },
          {
           "id": "13.3.1.4",
           "text": "Regulated Entities shall conduct PIAs or DPIAs for new or high-risk data transfers crossing borders, recording risk assessments and mitigating actions.",
           "key": "TPRM:13.3.1.4"
          }
         ]
        }
       ]
      },
      {
       "num": "13.4",
       "name": "Monitoring, Reporting & Audit",
       "areas": [
        {
         "num": "13.4.1",
         "name": "Transaction Monitoring & Alerts",
         "controls": [
          {
           "id": "13.4.1.1",
           "text": "Regulated Entities shall operate real-time AML/CFT systems to detect unusual cross-border patterns (e.g., volume, frequency, location), generating alerts and case investigations.",
           "key": "TPRM:13.4.1.1"
          },
          {
           "id": "13.4.1.2",
           "text": "Regulated Entities shall maintain tamper-evident, time-stamped logs of all transaction workflows, including initiation, approval, messages, and settlement, for a retention period as specified.",
           "key": "TPRM:13.4.1.2"
          }
         ]
        },
        {
         "num": "13.4.2",
         "name": "Regulatory Reporting Requirements",
         "controls": [
          {
           "id": "13.4.2.1",
           "text": "Regulated Entities shall submit cross-border reports (e.g., large transfers, STR/FTR filings, statistical returns) to CBK and affiliated authorities within prescribed timelines.",
           "key": "TPRM:13.4.2.1"
          },
          {
           "id": "13.4.2.2",
           "text": "Regulated Entities shall conduct internal or external audits of cross-border compliance controls and submit the resulting findings and remediation plans to CBK.",
           "key": "TPRM:13.4.2.2"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 12,
     "section": "14",
     "name": "Usage of Cloud Services",
     "subdomains": [
      {
       "num": "14.1",
       "name": "Cloud Security",
       "areas": [
        {
         "num": "14.1.1",
         "name": "Cloud Security Safeguards",
         "controls": [
          {
           "id": "14.1.1.1",
           "text": "All applicable cloud security controls defined in the Cyber Resilience Baselines shall be evaluated as part of the assessment process.",
           "key": "TPRM:14.1.1.1"
          },
          {
           "id": "14.1.1.2",
           "text": "Regulated Entities shall have a record of Cloud Service Provider (CSP) details, locations and type of cloud services used: a) Public Cloud b) Private Cloud c) Hybrid Cloud d) Community cloud",
           "key": "TPRM:14.1.1.2"
          },
          {
           "id": "14.1.1.3",
           "text": "Regulated Entities shall have details of Cloud service model that is being utilized for providing services: a) Software as a Service (SaaS) b) Platform as a Service (PaaS) c) Infrastructure as a Service (IaaS)",
           "key": "TPRM:14.1.1.3"
          },
          {
           "id": "14.1.1.4",
           "text": "Regulated Entities shall ensure that all legal and regulatory requirements that apply to the provision and use of cloud services are identified. Particularly where the processing, storage and communication capabilities are geographically distributed and multiple jurisdictions are involved.",
           "key": "TPRM:14.1.1.4"
          },
          {
           "id": "14.1.1.5",
           "text": "Regulated Entities shall ensure that the Cloud Service Provider is a Cloud Security Alliance Security, Trust and Assurance Registry (“STAR”) certified provider or holds a cloud-based certification (i.e., ISO 27017, FedRAMP).",
           "key": "TPRM:14.1.1.5"
          },
          {
           "id": "14.1.1.6",
           "text": "Regulated Entities shall ensure that security control ownership is clearly defined in a shared security responsibility model between CSP and RE and documentation is available.",
           "key": "TPRM:14.1.1.6"
          },
          {
           "id": "14.1.1.7",
           "text": "Regulated Entities shall have strategies in place to mitigate the risk of vendor lock-in with the cloud service providers and have measures related to data portability, use of open standards, and multi-cloud strategies etc.",
           "key": "TPRM:14.1.1.7"
          },
          {
           "id": "14.1.1.8",
           "text": "Regulated Entities shall ensure that CSP provide a third-party audit report i.e., SOC 2 Type II report / ISAE 3402 report or equivalent.",
           "key": "TPRM:14.1.1.8"
          },
          {
           "id": "14.1.1.9",
           "text": "Regulated Entities shall ensure that procedures are in place to ensure the secure termination of services and data retrieval when the agreement ends.",
           "key": "TPRM:14.1.1.9"
          },
          {
           "id": "14.1.1.10",
           "text": "Regulated Entities to ensure that the CSP have the capabilities to enable them to monitor activity within a cloud computing environment.",
           "key": "TPRM:14.1.1.10"
          }
         ]
        }
       ]
      }
     ]
    },
    {
     "domain": 13,
     "section": "15",
     "name": "Inter-Affiliates",
     "subdomains": [
      {
       "num": "15.1",
       "name": "Due Diligence and Periodic Review",
       "areas": [
        {
         "num": "15.1.1",
         "name": "Inter-Affiliates Monitoring and Oversight",
         "controls": [
          {
           "id": "15.1.1.1",
           "text": "Regulates Entities shall define the scope of due-diligence on affiliates, have Service Level Agreements (SLAs) in place, perform periodic reviews and have an exit strategy in place.",
           "key": "TPRM:15.1.1.1"
          },
          {
           "id": "15.1.1.2",
           "text": "Regulates Entities shall seek prior approval from the CBK before entering material or high- risk service arrangements with affiliates. Regulated Entities shall ensure robust risk assessment, governance, and compliance with regulatory requirements for all affiliate services, and seek approval where such arrangements could impact the entity’s risk profile or operational resilience.",
           "key": "TPRM:15.1.1.2"
          }
         ]
        }
       ]
      },
      {
       "num": "15.2",
       "name": "Customer Consent",
       "areas": [
        {
         "num": "15.2.1",
         "name": "Customer Consent for Data Sharing",
         "controls": [
          {
           "id": "15.2.1.1",
           "text": "Regulated Entities shall ensure to have a customer consent procedure in the case of data sharing with the affiliates.",
           "key": "TPRM:15.2.1.1"
          }
         ]
        }
       ]
      },
      {
       "num": "15.3",
       "name": "Foreign Affiliates",
       "areas": [
        {
         "num": "15.3.1",
         "name": "Foreign Affiliates",
         "controls": [
          {
           "id": "15.3.1.1",
           "text": "Regulated entities shall ensure similar controls and governance are adhered to in the case of foreign affiliates apart from considering geo-political relations between countries.",
           "key": "TPRM:15.3.1.1"
          }
         ]
        }
       ]
      },
      {
       "num": "15.4",
       "name": "Resource Planning",
       "areas": [
        {
         "num": "15.4.1",
         "name": "Business Continuity",
         "controls": [
          {
           "id": "15.4.1.1",
           "text": "Regulated entities shall ensure resource planning and availability to ensure service viability.",
           "key": "TPRM:15.4.1.1"
          }
         ]
        }
       ]
      }
     ]
    }
   ],
   "counts": {
    "domains": 13,
    "subdomains": 43,
    "control_areas": 77,
    "controls": 210
   },
   "official_counts": {
    "domains": 13,
    "subdomains": 43,
    "control_areas": 78,
    "controls": 211
   }
  }
 ],
 "counts": {
  "controls_extracted": 874,
  "controls_official": 876,
  "domains": 25,
  "subdomains": 93
 }
}