The framework as published by the Central Bank of Nigeria for Deposit Money Banks and Payment Service Banks. Organised the way CBN organises it: 10 Parts, 25 clauses, with the intent of each Part and a short summary of each clause. A secondary tab exposes an unofficial third-party mapping to NIST SP 800-53 Rev 5, clearly flagged as not part of CBN's own numbering.
Source: Central Bank of Nigeria (CBN), Banking Supervision Department, Risk-Based Cybersecurity Framework and Guidelines for Deposit Money Banks and Payment Service Banks (BSD/TEN/CON/SRF/03/057, February 19, 2024 (effective July 2024)). Clause titles are as published by CBN. Summaries are Symbiosis paraphrases and are not a substitute for the CBN circular.
Showing 25 of 25 clauses across 10 of 10 Parts / Domains.
Establishes accountability for cybersecurity at the Board, senior management, and CISO level, and requires a documented cybersecurity policy framework approved by the Board.
The Board is ultimately accountable for cybersecurity, must approve the cybersecurity strategy and policy, and must receive regular cybersecurity reporting.
Senior management implements the cybersecurity programme. A Chief Information Security Officer (CISO) must be appointed with defined authority, independence, and reporting lines.
A comprehensive, Board-approved cybersecurity policy framework covering all key domains must be documented, communicated, and reviewed at least annually.
Requires a formal, ongoing risk management process: identification, measurement, monitoring, reporting, third-party oversight, and assurance activities such as vulnerability assessment and penetration testing.
Institutions must perform periodic cybersecurity risk assessments using a documented methodology, rating inherent and residual risk against defined risk appetite.
Maintain a cybersecurity risk register, monitor risks continuously, and report status to senior management and the Board on a defined cadence.
Conduct vulnerability assessments regularly and independent penetration tests at least annually. Findings must be tracked to remediation.
Cybersecurity risk from vendors, cloud providers, and outsourced service providers must be assessed pre-engagement, contractually managed, and monitored throughout the relationship.
Prescribes the operational controls that protect, detect, respond, and recover: asset management, access control, network and data protection, monitoring, incident response, business continuity, and cyber drills.
Maintain a complete, accurate inventory of information assets (hardware, software, data, cloud services) with ownership and classification.
Enforce least-privilege access, strong authentication (including MFA for privileged and remote access), session controls, and periodic access recertification.
Segment networks, harden systems to baselines, patch timely, protect against malware, and secure name resolution and boundary services.
Classify data, encrypt sensitive data at rest and in transit using approved algorithms, and manage cryptographic keys and media through their lifecycle.
Operate 24/7 security monitoring (SOC), collect and protect audit logs, and detect suspicious activity with defined use cases and response playbooks.
Maintain a documented incident response plan, a trained response team, and defined reporting channels including notification to CBN and NigFinCERT.
Maintain business continuity and disaster recovery plans covering cyber scenarios, with defined RTO/RPO, alternate sites, and regular testing.
Participate in periodic cyber drills, tabletop exercises, and industry-wide simulations coordinated by CBN and NigFinCERT.
Requires participation in NigFinCERT and other trusted intelligence-sharing arrangements, and operationalising threat intelligence into detection and response.
Subscribe to and share cyber threat intelligence via NigFinCERT and other trusted sources; integrate indicators into monitoring and response processes.
Establishes governance and control expectations for adoption of AI, cloud, distributed-ledger technology, and open banking / API-based services.
Assess and govern risks in AI, cloud, and distributed-ledger technology adoption, with due diligence, architecture review, and continuous assurance.
Secure open-banking and third-party API interfaces: strong client authentication, transport and message-level encryption, and input validation.
Requires defined performance metrics for the cybersecurity programme and structured reporting to CBN, including the annual Cybersecurity Self-Assessment (CSAT).
Define, collect, and report cybersecurity performance metrics that let management track programme effectiveness over time.
Submit required cybersecurity reports to CBN, including the annual Cybersecurity Self-Assessment (CSAT) and event-driven notifications.
Aligns the cybersecurity programme with wider statutory and regulatory obligations and describes CBN's supervisory and enforcement stance.
The cybersecurity programme must satisfy applicable statutory and regulatory requirements, including NDPA 2023 and other CBN circulars.
CBN may examine, request evidence, and take enforcement action for non-compliance, including administrative sanctions.
Requires role-based cybersecurity training for all staff (including the Board), with awareness for customers and third parties.
Deliver ongoing cybersecurity awareness for all staff and role-based training for technical and privileged roles; extend awareness to customers.
Sets expectations for pre-employment screening, ongoing personnel security controls, and the insider-threat programme.
Screen personnel appropriate to role sensitivity, enforce separation of duties, and operate an insider-threat programme covering monitoring and response.
Requires physical protection of data centres, offices, and supporting environmental controls for the cybersecurity infrastructure.
Protect facilities that host information systems with physical access controls, monitoring, power, cooling, fire suppression, and environmental hazard protection.