Central Bank of Egypt Financial Cybersecurity Framework
Mandatory cybersecurity framework for all banks, financial institutions, and payment service providers regulated by the Central Bank of Egypt. 5 functions (governance, risk management, technology and operations, cyber defence, outsourcing and vendor management) across 23 domains covering leadership, compliance, asset management, IAM, data protection, cryptography, application security, network security, SOC, incident management, and business resilience. Built on NIST CSF, ISO 27001, and SWIFT CSCF.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| CD-1 | Security Operations, Threat Intelligence, and Insider Threat | |
| CD-2 | Incident Management | |
| CRM-1 | Risk Assessment and Management | |
| CRM-2 | Asset Management | |
| CTO-1 | Identity and Access Management | |
| CTO-2 | Data Protection and Privacy | |
| CTO-3 | Cryptography | |
| CTO-4 | Application Security | |
| CTO-5 | Digital Channels Security | |
| CTO-6 | Network Security | |
| CTO-7 | Endpoint Security | |
| CTO-8 | Email Security | |
| CTO-9 | Vulnerability and Patch Management | |
| CTO-10 | Physical and Environmental Security | |
| CTO-11 | Cloud Security | |
| CTO-12 | Change Management | |
| GOV-1 | Leadership, Governance, and Strategy | |
| GOV-2 | Cybersecurity Roles, Responsibilities, and HR Security | |
| GOV-3 | Compliance and Regulatory Reporting | |
| GOV-4 | Security Awareness and Training | |
| OVM-1 | Outsourcing and Vendor Management | |
| OVM-2 | Business Resilience | |
| OVM-3 | Cybersecurity Testing |