Frameworks / Nigeria Open Banking Regulatory Framework (CBN, 2023) / NGOB-3 Nigeria Open Banking Regulatory Framework (CBN, 2023)
API Security
Nigeria Open Banking Regulatory Framework (CBN, 2023) NGOB-3: API Security Standards, mTLS, and Encryption Implement Open Banking API security per Common Banking Industry API Standards + OAuth 2.0 + OpenID Connect (OIDC) + FAPI 2.0 (Financial-grade API) + Mutual TLS (mTLS) client authentication. Apply encryption: TLS 1.3 in transit + AES-256 at rest. Use signed JWTs with detached signatures per FAPI requirements. Apply API rate limiting + token expiration + nonce + audience claims. Coordinate with Open Banking Nigeria Ltd standardisation body.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 98 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism PQC-5 Cryptographic Inventory and PQC Migration Roadmap PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection CJIS-8 Media Protection CJIS-9 System and Communications Protection ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) APPI-A34 Request for Correction, Addition or Deletion ASD37-17 TLS encryption between email servers (Limited) BSI-08 Cryptographic protection of data FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-9 Cyber security key management 27010-10.1 Cryptographic Protection 27011-8.3 Cryptography and key management 27400-6.2 Device Identity and Authentication 29115-7.4 Level of Assurance 4 (LoA4) STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NZISM-3 Personnel Security, Physical Security, and Cryptography OWASPAPI-6 Security Misconfiguration and Secure API Design NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control AUPRV-4 APP 10-11 Quality, Security of Personal Information IM8-CLD.2 Cloud Security Controls ISMSP-SYS-02 Encryption Implementation TURKEYKVKK-2 Information Notice and Data Subject Rights Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 98 it maps to, and the evidence behind each claim, over MCP and REST.