Learning Objectives:
-
Understand the concept of cybersecurity maturity models.
-
Identify the key elements of cybersecurity maturity assessment.
-
Apply maturity models to assess cyber resilience.
-
Recognise the role of maturity models in continuous improvement.
7.1 What are Cybersecurity Maturity Models?
Cybersecurity maturity models provide a framework for assessing the effectiveness of an organisation’s cybersecurity capabilities. The BSP’s Cybersecurity Maturity Framework gives institutions a structured way to measure and strengthen their defenses across key areas of risk and control .
Maturity models typically describe a progression from ad hoc, reactive approaches to proactive, integrated, and continuously improving approaches. The model helps organisations assess their current state, identify gaps, and develop plans for improvement.
7.2 The BSP Cybersecurity Maturity Framework
The BSP’s Cybersecurity Maturity Framework ranks institutions across four maturity levels :
Foundational: An institution has only minimal adoption of cybersecurity controls. Risk assessments may be irregular, informal or not yet considered in business decisions.
Established: The institution already has policies, procedures or guidelines approved by its board or relevant committee. These controls provide baseline protection for customer information, systems and operations, although implementation may not yet be consistent across all business units.
Managed: The institution has fully adopted relevant requirements, regularly test the effectiveness of their controls and integrate cybersecurity considerations across the business.
Optimized: The institution is expected to use advanced tools, technologies and threat intelligence to identify and respond to emerging cyber threats. Cybersecurity risks should also be fully considered in strategic planning and enterprise-wide decision-making.
7.3 Expected Maturity Levels
The BSP notes that the expected maturity level will depend on the size and complexity of an institution’s IT profile :
-
Simple IT Operations: Expected to fall within the foundational to established levels.
-
Moderate IT Profiles: Should be within the established to managed levels.
-
Complex IT Operations: Expected to reach the managed to optimized levels.
7.4 Maturity Assessment and Self-Assessment
The BSP requires financial institutions to conduct periodic and rigorous self-assessment exercises as part of their information security risk management system . The assessments are conducted through the Cybersecurity Control Self-Assessment (CCSA) tool .
The Central Bank of Nigeria’s Framework also requires the submission of a Cybersecurity Self-Assessment Tool (CSAT) report, signed by the CISO and approved by senior management, to the Director of Supervision no later than 31 March annually .
The BSP said the results of the self-assessment, together with other supervisory activities, will be used to classify institutions under the four maturity levels .