← Frameworks / Regulatory

OSFI Guideline B-13 Technology and Cyber Risk Management

Canadian federal prudential guideline for technology and cyber risk management at federally regulated financial institutions. Covers 4 domains: governance and risk management, technology operations and resilience, cyber security (identify/defend/detect/respond), and third-party technology risk including cloud-specific considerations.

Clause Title SP 800-53 Controls
B-13.1.1 Technology and cyber risk governance, accountability, and culture
B-13.1.2 Technology and cyber risk strategy
B-13.1.3 Technology and cyber risk management framework
B-13.1.4 Technology and cyber risk reporting
B-13.2.1 Technology asset management
B-13.2.2 Technology architecture and standards
B-13.2.3 Technology change management
B-13.2.4 Technology vulnerability and patch management
B-13.2.5 Technology incident management
B-13.2.6 Technology resilience and disaster recovery
B-13.3.1 Cyber risk identification and assessment
B-13.3.2 Cyber security controls
B-13.3.3 Cyber security monitoring and detection
B-13.3.4 Cyber incident response
B-13.3.5 Cyber security testing
B-13.4.1 Third-party technology risk management
B-13.4.2 Third-party technology risk oversight and monitoring