← Frameworks / Financial Regulation

Bank of Mauritius Guideline on Cyber and Technology Risk Management

Comprehensive technology risk management guideline for all banks and non-bank deposit-taking institutions licensed by the Bank of Mauritius. 5 parts (governance, identification, protection, detection, response and recovery) across 26 sections covering board oversight, CISO, technology strategy, risk framework, control functions, network and infrastructure security, logical security, encryption, physical security, change management, technology refresh, people, third-party management, data hosting, secure coding, threat intelligence, monitoring, vulnerability testing, incident management, BCP/DRP, and technology audit. Structured around NIST CSF five-function model.

Clause Title SP 800-53 Controls
1.1 Board and Senior Management Oversight
1.2 Roles and Responsibilities of the CISO
1.3 Technology Strategy
1.4 Cyber and Technology Risk Management Strategy and Framework
1.5 Control Functions (Three Lines of Defence)
2.1 Identification of Cyber and Technology Risks
3.1 Control Implementation and Design
3.2 Network and Infrastructure Management
3.3 Logical Security Management
3.4 Encryption and Cryptographic Materials
3.5 Physical Security Management
3.6 Change and Patch Management
3.7 Technology Refresh Management
3.8 People Management
3.9 Third-Party Service Providers
3.10 Hosting of Customer Information Outside Mauritius
3.11 Secure Coding in Application Development
3.12 End-User Computing
3.13 Online Financial Services Security
4.1 Cyber and Technology Threat Intelligence
4.2 Detection of Cyber Events and Monitoring
4.3 Vulnerability Assessment and Penetration Testing
5.1 Cyber Incident Management
5.2 Business Continuity and Response and Recovery Planning
5.3 Situational Awareness, Learning and Evolving
5.4 Technology Audit