CBUAE Cyber Risk and Operational Resilience Framework
Central Bank of the UAE mandatory framework for cyber risk governance, security operations, incident management, and operational resilience for all CBUAE-regulated financial institutions. 14 sections covering governance, risk management, SOC, identity and access management, data protection, application and infrastructure security, cryptography, incident management, security testing, awareness, third-party risk, operational resilience, and regulatory reporting.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| CR-1 | Cyber Risk Governance | |
| CR-2 | Cyber Risk Management | |
| CR-3 | Cyber Security Operations | |
| CR-4 | Identity and Access Management | |
| CR-5 | Data Protection | |
| CR-6 | Application Security | |
| CR-7 | Infrastructure Security | |
| CR-8 | Cryptography | |
| CR-9 | Cyber Incident Management | |
| CR-10 | Cyber Security Testing | |
| CR-11 | Cybersecurity Awareness and Training | |
| CR-12 | Third-Party Cyber Risk | |
| CR-13 | Operational Resilience | |
| CR-14 | Regulatory Compliance and Reporting |