Learning Objectives:

  • Understand the key international cybersecurity frameworks and their components.

  • Explain the structure and principles of the NIST Cybersecurity Framework.

  • Identify the requirements of ISO 27001 for information security management.

  • Recognise the role of COBIT in IT governance and control.

1.1 The NIST Cybersecurity Framework

The National Institute of Standards and Technology (NIST) Cybersecurity Framework is a widely adopted standard for managing cybersecurity risk. The framework provides a common language for organisations to understand, manage, and communicate cybersecurity risk . The NIST framework is organised around five core functions:

Identify: The Identify function develops the organisational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. It includes asset management, business environment, governance, risk assessment, and risk management strategy.

Protect: The Protect function develops and implements appropriate safeguards to ensure delivery of critical infrastructure services. It includes access control, awareness and training, data security, information protection processes and procedures, maintenance, and protective technology.

Detect: The Detect function develops and implements appropriate activities to identify the occurrence of a cybersecurity event. It includes anomalies and events, security continuous monitoring, and detection processes.

Respond: The Respond function develops and implements appropriate activities to take action regarding a detected cybersecurity incident. It includes response planning, communications, analysis, mitigation, and improvements.

Recover: The Recover function develops and implements appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident. It includes recovery planning, improvements, and communications.

The NIST framework is designed to be flexible and adaptable to organisations of all sizes and types. It can be used to assess current cybersecurity posture, set improvement goals, and measure progress.

1.2 ISO 27001 and ISO 27002

ISO 27001 is the international standard for information security management systems (ISMS). It specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS . The standard is based on a process approach that includes:

  • Establishing the ISMS: Defining the scope, policy, and risk assessment approach.

  • Implementing and Operating the ISMS: Implementing the risk treatment plan and controls.

  • Monitoring and Reviewing the ISMS: Monitoring, measuring, and auditing the ISMS.

  • Maintaining and Improving the ISMS: Continually improving the ISMS.

ISO 27002 provides a reference set of information security controls, including security policies, organisation of information security, human resource security, asset management, access control, cryptography, physical and environmental security, operations security, communications security, system acquisition, development and maintenance, supplier relationships, incident management, business continuity management, and compliance .

The Saudi Central Bank’s Cybersecurity Framework requires entities to define, approve, implement, and communicate cyber security policies and procedures that are supported by detailed security standards . This reflects the integration of the ISO 27001 framework into regulatory requirements.

1.3 COBIT 5 for Information Security

COBIT (Control Objectives for Information and Related Technology) is a framework for IT governance and management. COBIT 5 for Information Security provides a comprehensive framework for the governance and management of information security . The framework is based on five key principles:

Meeting Stakeholder Needs: Information security should meet the needs of stakeholders.

Covering the Enterprise End-to-End: Information security should cover the entire enterprise.

Applying a Single Integrated Framework: Information security should be integrated with other governance frameworks.

Enabling a Holistic Approach: Information security should address all enablers.

Separating Governance from Management: Governance and management should be clearly distinguished.

COBIT provides a set of process goals that are applied to information security, including:

  • Manage the IT Management Framework: Establish the IT governance framework.

  • Manage IT Risk: Identify, assess, and manage IT risk.

  • Manage Information Security: Establish and maintain an information security management system.

1.4 Other Regulatory Frameworks

In addition to international standards, central banks and financial institutions must comply with a range of regulatory frameworks. The IT Security Controls book notes that the implementation proposal is designed to comply with the most relevant market standards and a significant number of regulatory frameworks from central banks across the world (European Union, Switzerland, UK, Singapore, Hong Kong, India, Qatar, Kuwait, Saudi Arabia, Oman, etc.) .

These frameworks include:

  • Saudi Arabian Monetary Authority (SAMA) Cybersecurity Framework: Requires entities to develop a robust cyber security governance structure supported with appropriate resources .

  • Monetary Authority of Singapore (MAS) Guidelines: Provides guidance on technology risk management and cyber resilience.

  • Reserve Bank of India (RBI) Guidelines: Sets cybersecurity requirements for financial institutions.

  • BDDK (Turkey) Requirements: Establishes cybersecurity standards for the banking sector.