← Frameworks / Financial Regulation

CBN Risk-Based Cybersecurity Framework for DMBs and PSBs

Central Bank of Nigeria mandatory risk-based cybersecurity framework for all deposit money banks and payment service banks. 10 parts covering governance, risk management, cyber resilience, threat intelligence, emerging technologies, metrics and reporting, compliance and enforcement, awareness and training, personnel security, and physical security. Requires annual self-assessment (CSAT) and participation in NigFinCERT. Effective July 2024.

Clause Title SP 800-53 Controls
Part1.1 Cybersecurity Governance — Board of Directors Oversight
Part1.2 Cybersecurity Governance — Senior Management and CISO
Part1.3 Cybersecurity Policy Framework
Part2.1 Cybersecurity Risk Assessment and Measurement
Part2.2 Risk Monitoring, Risk Register and Reporting
Part2.3 Vulnerability Assessment and Penetration Testing
Part2.4 Third-Party Risk Management
Part3.1 Know Your Environment — Asset Management
Part3.2 Preventive Controls — Access Control and Identity Management
Part3.3 Preventive Controls — Network and Infrastructure Security
Part3.4 Preventive Controls — Data Protection and Encryption
Part3.5 Monitoring, Detection and 24/7 Security Operations
Part3.6 Incident Response and Recovery
Part3.7 Cyber Resilience — Business Continuity and Disaster Recovery
Part3.8 Cyber Drills and Industry Exercises
Part4 Cyber Threat Intelligence
Part5.1 Emerging Technologies — AI, Cloud, and DLT Governance
Part5.2 Emerging Technologies — Open Banking and API Security
Part6.1 Cybersecurity Metrics and Performance Measurement
Part6.2 Regulatory Reporting and Self-Assessment
Part7.1 Compliance with Statutory and Regulatory Requirements
Part7.2 Enforcement and CBN Supervisory Oversight
Part8 Cybersecurity Awareness and Training
Part9 Personnel Security and Insider Threat
Part10 Physical and Environmental Security