Learning Objectives:
-
Understand the concept of cybersecurity maturity frameworks.
-
Apply self-assessment tools to evaluate cyber resilience.
-
Identify the four maturity levels commonly used in regulatory frameworks.
-
Recognise the relationship between IT complexity and expected maturity.
4.1 The Purpose of Cybersecurity Maturity Frameworks
Cybersecurity maturity frameworks provide a structured way to measure and strengthen cyber defenses across key areas of risk and control . The Bangko Sentral ng Pilipinas (BSP) introduced a Cybersecurity Maturity Framework to support financial institutions in strengthening both institutional and sector-wide cyber resilience in light of increasing digitalization and the evolving threat landscape .
The Central Bank of Kuwait’s Cybersecurity and Operational Resilience Framework (CORF) represents a significant increase in scope and rigor, structured into a four-level hierarchy of 27 Domains, 93 Sub-Domains, 200 Control Areas and 876 Controls . This reflects the growing complexity of regulatory expectations for cybersecurity.
4.2 Self-Assessment Tools
The BSP requires financial institutions to conduct periodic and rigorous self-assessment exercises as part of their information security risk management system . These assessments are conducted through the Cybersecurity Control Self-Assessment (CCSA), a tool that allows institutions to review their current activities, internal processes and cybersecurity practices .
Key Features of Self-Assessment Tools:
-
Activity and Capability-Based Questions: The assessment tool contains questions intended to reflect the BSFI’s maturity in a particular control area and to gather cyber trends and practices .
-
Risk-Based Approach: Institutions are expected to achieve maturity tiers in line with their risk profile .
-
Continuous Improvement: Institutions are encouraged to continuously strengthen their cybersecurity capabilities and adopt more advanced controls .
The Central Bank of Nigeria also requires the submission of a Cybersecurity Self-Assessment Tool (CSAT) report, signed by the CISO and approved by senior management, to the Director of Supervision . The CBN stated that the guidelines represented the minimum requirements to be put in place by all OFIs .
4.3 Maturity Levels
The BSP ranks institutions across four maturity levels :
Foundational: An institution has only minimal adoption of cybersecurity controls. Risk assessments may be irregular, informal or not yet considered in business decisions .
Established: The institution already has policies, procedures or guidelines approved by its board or relevant committee. These controls provide baseline protection for customer information, systems and operations, although implementation may not yet be consistent across all business units .
Managed: The institution has fully adopted relevant requirements, regularly test the effectiveness of their controls and integrate cybersecurity considerations across the business .
Optimized: The institution is expected to use advanced tools, technologies and threat intelligence to identify and respond to emerging cyber threats. Cybersecurity risks should also be fully considered in strategic planning and enterprise-wide decision-making .
4.4 Expected Maturity by IT Complexity
The BSP notes that the expected maturity level will depend on the size and complexity of an institution’s IT profile :
-
Simple IT Operations: Expected to fall within the foundational to established levels .
-
Moderate IT Profiles: Should be within the established to managed levels .
-
Complex IT Operations: Expected to reach the managed to optimized levels .
The Central Bank of Kuwait’s CORF framework uses a dynamic assessment model with a 3-tier risk-based assessment model, alongside a 5-level Maturity Model to evaluate how well capabilities are institutionalized and automated . This reflects the trend toward more granular and sophisticated maturity assessments.