Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct
BMA Code Section V: Identification of Assets and Risks

Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct BMA-4: Chief Information Security Officer

Chief Information Security Officer (CISO). A CISO with the necessary experience and competencies must be appointed to deliver the operational cyber risk management programme (paras 17-18).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 67 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles
  • 58.1 Scope
  • 58.3 Definitions
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA

ISO/IEC 27011:2024 · 2 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • AMLCTF-82 Part A Compliance

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • AS9100D-8.1 Operational Planning and Control
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • ACQS-8-4 Risk Management
  • AZ-DPA-2 Article 2 - Basic Concepts
  • 62351-2 Glossary of terms

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy
  • 27050-1.4 Terms and definitions

ISO/IEC 27400:2022 · 1 control

  • 27400-3 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions
  • BIPA-SEC5-1 Biometric Identifier Definition
  • NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed
  • AIGF-1.1 Risk Management and Internal Controls
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in BMA Code Section V: Identification of Assets and Risks

Query this from an agent

The graph holds this control, the 67 it maps to, and the evidence behind each claim, over MCP and REST.