Learning Objectives:

  • Understand the role of central banks in setting national cybersecurity standards.

  • Analyse the components of national cybersecurity frameworks.

  • Recognise the importance of sectoral cybersecurity strategies.

  • Understand the relationship between national and international standards.

7.1 The Central Bank’s Role in Cybersecurity Standard-Setting

Central banks play a key role in setting cybersecurity standards for the financial sector. The Central Bank of Kuwait’s Cybersecurity and Operational Resilience Framework (CORF) is an example of a national framework that sets comprehensive cybersecurity requirements for the banking and financial sector . The framework represents a significant increase in scope and rigor compared to the previous framework, expanding from a cybersecurity framework to a comprehensive cyber and operational resilience framework .

The Central Bank of Nigeria’s Risk-Based Cybersecurity Framework sets comprehensive requirements for cybersecurity governance, risk management, and operational resilience for other financial institutions . The objective of the guidelines is to create a safer and more secure cyber environment that supports information system security and promotes stability of the OFI sub-sector .

7.2 National Cybersecurity Frameworks

National cybersecurity frameworks typically include several key components:

Cyber Resilience: The Central Bank of Kuwait’s CORF includes a Cyber Resilience baseline that addresses the core cybersecurity capabilities required to protect against cyber threats .

Operational Resilience: The CORF includes an Operational Resilience baseline that addresses the ability to withstand and recover from disruptions .

Third-Party Risk Management: The CORF includes a Third-Party Risk Management (TPRM) baseline that addresses the risks associated with third-party service providers .

Expanded Control Landscape: The CORF is structured into a four-level hierarchy of 27 Domains, 93 Sub-Domains, 200 Control Areas and 876 Controls .

Dynamic Assessment Model: The CORF uses a 3-tier risk-based assessment model, alongside a 5-level Maturity Model to evaluate how well capabilities are institutionalized and automated .

7.3 Sectoral Cybersecurity Strategies

The TNM recommendations emphasise the need for focused work to formulate national-level and financial sector-level cyber security strategies . With reference to the BCBS’s “Principles for Operational Resilience” and “Revised Principles for the Sound Management of Operational Risk”, and the CPMI and IOSCO’s “Guidance on Cyber Resilience for Financial Market Infrastructures”, the TNM outlines the core ingredients of effective governance .

The TNM emphasises the benefits that can arise from co-ordination between financial regulators beyond the sharing of information, including achieving harmonised regulations, developing best supervisory approaches and tackling cyber incidents collectively where applicable . It recommends the use of memorandums of understanding between financial regulators to help formalise institutional arrangements .

7.4 Harmonisation with International Standards

National frameworks are increasingly aligned with international standards. The IT Security Controls book notes that the implementation proposal is designed to comply with the most relevant market standards (ISO 27001, NIST, PCI-DSS, and COBIT) and a significant number of regulatory frameworks from central banks across the world . This reflects the trend toward harmonisation of cybersecurity standards across jurisdictions.

The BSP noted that the expected maturity level will depend on the size and complexity of an institution’s IT profile, reflecting a risk-based approach to standard-setting . The BSP also updated its reporting requirements, requiring BSFIs to submit their annual IT profile within 25 calendar days after the end of the reference year .