CBN Risk-Based Cybersecurity Framework for DMBs and PSBs
Central Bank of Nigeria mandatory risk-based cybersecurity framework for all deposit money banks and payment service banks. 10 parts covering governance, risk management, cyber resilience, threat intelligence, emerging technologies, metrics and reporting, compliance and enforcement, awareness and training, personnel security, and physical security. Requires annual self-assessment (CSAT) and participation in NigFinCERT. Effective July 2024.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| Part1.1 | Cybersecurity Governance — Board of Directors Oversight | |
| Part1.2 | Cybersecurity Governance — Senior Management and CISO | |
| Part1.3 | Cybersecurity Policy Framework | |
| Part2.1 | Cybersecurity Risk Assessment and Measurement | |
| Part2.2 | Risk Monitoring, Risk Register and Reporting | |
| Part2.3 | Vulnerability Assessment and Penetration Testing | |
| Part2.4 | Third-Party Risk Management | |
| Part3.1 | Know Your Environment — Asset Management | |
| Part3.2 | Preventive Controls — Access Control and Identity Management | |
| Part3.3 | Preventive Controls — Network and Infrastructure Security | |
| Part3.4 | Preventive Controls — Data Protection and Encryption | |
| Part3.5 | Monitoring, Detection and 24/7 Security Operations | |
| Part3.6 | Incident Response and Recovery | |
| Part3.7 | Cyber Resilience — Business Continuity and Disaster Recovery | |
| Part3.8 | Cyber Drills and Industry Exercises | |
| Part4 | Cyber Threat Intelligence | |
| Part5.1 | Emerging Technologies — AI, Cloud, and DLT Governance | |
| Part5.2 | Emerging Technologies — Open Banking and API Security | |
| Part6.1 | Cybersecurity Metrics and Performance Measurement | |
| Part6.2 | Regulatory Reporting and Self-Assessment | |
| Part7.1 | Compliance with Statutory and Regulatory Requirements | |
| Part7.2 | Enforcement and CBN Supervisory Oversight | |
| Part8 | Cybersecurity Awareness and Training | |
| Part9 | Personnel Security and Insider Threat | |
| Part10 | Physical and Environmental Security |