10 Parts, 25 clauses

CBN Risk-Based Cybersecurity Framework

The framework as published by the Central Bank of Nigeria for Deposit Money Banks and Payment Service Banks. Organised the way CBN organises it: 10 Parts, 25 clauses, with the intent of each Part and a short summary of each clause. A secondary tab exposes an unofficial third-party mapping to NIST SP 800-53 Rev 5, clearly flagged as not part of CBN's own numbering.

Source: Central Bank of Nigeria (CBN), Banking Supervision Department, Risk-Based Cybersecurity Framework and Guidelines for Deposit Money Banks and Payment Service Banks (BSD/TEN/CON/SRF/03/057, February 19, 2024 (effective July 2024)). Clause titles are as published by CBN. Summaries are Symbiosis paraphrases and are not a substitute for the CBN circular.

Official CBN structure. Part and clause numbering (Part 1, 1.1, 1.2, etc.) is CBN's own, as published in the Risk-Based Cybersecurity Framework circular. No third-party mapping or renumbering is applied on this tab.

Showing 25 of 25 clauses across 10 of 10 Parts / Domains.

Sign in to record status (In place / Partially / Not applicable / Not assessed), add notes, and attach evidence directly to each CBN clause.

Establishes accountability for cybersecurity at the Board, senior management, and CISO level, and requires a documented cybersecurity policy framework approved by the Board.

  • 1.1Cybersecurity Governance - Board of Directors Oversight#1.1

    The Board is ultimately accountable for cybersecurity, must approve the cybersecurity strategy and policy, and must receive regular cybersecurity reporting.

    Current: Not Assessed
    (sign in to record)
  • 1.2Cybersecurity Governance - Senior Management and CISO#1.2

    Senior management implements the cybersecurity programme. A Chief Information Security Officer (CISO) must be appointed with defined authority, independence, and reporting lines.

    Current: Not Assessed
    (sign in to record)
  • 1.3Cybersecurity Policy Framework#1.3

    A comprehensive, Board-approved cybersecurity policy framework covering all key domains must be documented, communicated, and reviewed at least annually.

    Current: Not Assessed
    (sign in to record)

Requires a formal, ongoing risk management process: identification, measurement, monitoring, reporting, third-party oversight, and assurance activities such as vulnerability assessment and penetration testing.

  • 2.1Cybersecurity Risk Assessment and Measurement#2.1

    Institutions must perform periodic cybersecurity risk assessments using a documented methodology, rating inherent and residual risk against defined risk appetite.

    Current: Not Assessed
    (sign in to record)
  • 2.2Risk Monitoring, Risk Register and Reporting#2.2

    Maintain a cybersecurity risk register, monitor risks continuously, and report status to senior management and the Board on a defined cadence.

    Current: Not Assessed
    (sign in to record)
  • 2.3Vulnerability Assessment and Penetration Testing#2.3

    Conduct vulnerability assessments regularly and independent penetration tests at least annually. Findings must be tracked to remediation.

    Current: Not Assessed
    (sign in to record)
  • 2.4Third-Party Risk Management#2.4

    Cybersecurity risk from vendors, cloud providers, and outsourced service providers must be assessed pre-engagement, contractually managed, and monitored throughout the relationship.

    Current: Not Assessed
    (sign in to record)

Prescribes the operational controls that protect, detect, respond, and recover: asset management, access control, network and data protection, monitoring, incident response, business continuity, and cyber drills.

  • 3.1Know Your Environment - Asset Management#3.1

    Maintain a complete, accurate inventory of information assets (hardware, software, data, cloud services) with ownership and classification.

    Current: Not Assessed
    (sign in to record)
  • 3.2Preventive Controls - Access Control and Identity Management#3.2

    Enforce least-privilege access, strong authentication (including MFA for privileged and remote access), session controls, and periodic access recertification.

    Current: Not Assessed
    (sign in to record)
  • 3.3Preventive Controls - Network and Infrastructure Security#3.3

    Segment networks, harden systems to baselines, patch timely, protect against malware, and secure name resolution and boundary services.

    Current: Not Assessed
    (sign in to record)
  • 3.4Preventive Controls - Data Protection and Encryption#3.4

    Classify data, encrypt sensitive data at rest and in transit using approved algorithms, and manage cryptographic keys and media through their lifecycle.

    Current: Not Assessed
    (sign in to record)
  • 3.5Monitoring, Detection and 24/7 Security Operations#3.5

    Operate 24/7 security monitoring (SOC), collect and protect audit logs, and detect suspicious activity with defined use cases and response playbooks.

    Current: Not Assessed
    (sign in to record)
  • 3.6Incident Response and Recovery#3.6

    Maintain a documented incident response plan, a trained response team, and defined reporting channels including notification to CBN and NigFinCERT.

    Current: Not Assessed
    (sign in to record)
  • 3.7Cyber Resilience - Business Continuity and Disaster Recovery#3.7

    Maintain business continuity and disaster recovery plans covering cyber scenarios, with defined RTO/RPO, alternate sites, and regular testing.

    Current: Not Assessed
    (sign in to record)
  • 3.8Cyber Drills and Industry Exercises#3.8

    Participate in periodic cyber drills, tabletop exercises, and industry-wide simulations coordinated by CBN and NigFinCERT.

    Current: Not Assessed
    (sign in to record)

Requires participation in NigFinCERT and other trusted intelligence-sharing arrangements, and operationalising threat intelligence into detection and response.

  • 4Cyber Threat Intelligence#4

    Subscribe to and share cyber threat intelligence via NigFinCERT and other trusted sources; integrate indicators into monitoring and response processes.

    Current: Not Assessed
    (sign in to record)

Establishes governance and control expectations for adoption of AI, cloud, distributed-ledger technology, and open banking / API-based services.

  • 5.1Emerging Technologies - AI, Cloud, and DLT Governance#5.1

    Assess and govern risks in AI, cloud, and distributed-ledger technology adoption, with due diligence, architecture review, and continuous assurance.

    Current: Not Assessed
    (sign in to record)
  • 5.2Emerging Technologies - Open Banking and API Security#5.2

    Secure open-banking and third-party API interfaces: strong client authentication, transport and message-level encryption, and input validation.

    Current: Not Assessed
    (sign in to record)

Requires defined performance metrics for the cybersecurity programme and structured reporting to CBN, including the annual Cybersecurity Self-Assessment (CSAT).

  • 6.1Cybersecurity Metrics and Performance Measurement#6.1

    Define, collect, and report cybersecurity performance metrics that let management track programme effectiveness over time.

    Current: Not Assessed
    (sign in to record)
  • 6.2Regulatory Reporting and Self-Assessment#6.2

    Submit required cybersecurity reports to CBN, including the annual Cybersecurity Self-Assessment (CSAT) and event-driven notifications.

    Current: Not Assessed
    (sign in to record)

Aligns the cybersecurity programme with wider statutory and regulatory obligations and describes CBN's supervisory and enforcement stance.

  • 7.1Compliance with Statutory and Regulatory Requirements#7.1

    The cybersecurity programme must satisfy applicable statutory and regulatory requirements, including NDPA 2023 and other CBN circulars.

    Current: Not Assessed
    (sign in to record)
  • 7.2Enforcement and CBN Supervisory Oversight#7.2

    CBN may examine, request evidence, and take enforcement action for non-compliance, including administrative sanctions.

    Current: Not Assessed
    (sign in to record)

Requires role-based cybersecurity training for all staff (including the Board), with awareness for customers and third parties.

  • 8Cybersecurity Awareness and Training#8

    Deliver ongoing cybersecurity awareness for all staff and role-based training for technical and privileged roles; extend awareness to customers.

    Current: Not Assessed
    (sign in to record)

Sets expectations for pre-employment screening, ongoing personnel security controls, and the insider-threat programme.

  • 9Personnel Security and Insider Threat#9

    Screen personnel appropriate to role sensitivity, enforce separation of duties, and operate an insider-threat programme covering monitoring and response.

    Current: Not Assessed
    (sign in to record)

Requires physical protection of data centres, offices, and supporting environmental controls for the cybersecurity infrastructure.

  • 10Physical and Environmental Security#10

    Protect facilities that host information systems with physical access controls, monitoring, power, cooling, fire suppression, and environmental hazard protection.

    Current: Not Assessed
    (sign in to record)