Rulebook cyber security modules
Requires a qualified CISO with authority to implement the cyber security strategy, and testing using grey box and black box approaches aligned to NIST or OWASP. The incident clock is the tightest in the Gulf: the CBB notified within one hour by telephone, an initial report within two hours, a detailed root-cause report within ten calendar days, then weekly updates until resolution. Conventional banks, Islamic banks, insurance, investment business and specialised licensees each have their own module.
