Central Bank of Bahrain Technology Module
Mandatory technology governance and cybersecurity requirements for all CBB-licensed financial institutions in Bahrain. 16 sections covering board oversight, IT governance, information security, risk management, operations, access control, application and network security, data security, physical security, vulnerability management, SOC, incident response, BCM/DR, third-party management, and regulatory reporting.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| TM-1 | Board and Senior Management Oversight | |
| TM-2 | IT Governance | |
| TM-3 | Information Security | |
| TM-4 | IT Risk Management | |
| TM-5 | IT Operations Management | |
| TM-6 | Access Control | |
| TM-7 | Application Security | |
| TM-8 | Network Security | |
| TM-9 | Data Security | |
| TM-10 | Physical Security | |
| TM-11 | Vulnerability Management and Patch Management | |
| TM-12 | Cybersecurity Operations Centre | |
| TM-13 | Incident Response | |
| TM-14 | Business Continuity and Disaster Recovery | |
| TM-15 | Third Party Management | |
| TM-16 | Regulatory Reporting |