Oman National Cybersecurity Framework
Governance and Risk

Oman National Cybersecurity Framework OMANCS-1: Cybersecurity Governance, Policy, and Risk Management

Establish cybersecurity governance + policy + risk management per Oman National Cybersecurity Framework administered by the Ministry of Transport + Communications and Information Technology (MTCIT) and the Oman National Computer Emergency Readiness Team (OmanCERT). Governance must (a) appoint accountable cybersecurity executives with documented decision authority + (b) maintain cybersecurity policy approved at senior level covering scope + roles + acceptable use + risk management + incident reporting + (c) align with Oman Vision 2040 cybersecurity programme + sectoral regulations (CBO for banking + TRA for telecom + CMA for capital markets + Ministry of Health) + international standards (ISO/IEC 27001 + NIST CSF). Risk management must apply NIST SP 800-30 or ISO 27005 methodology + maintain risk register + integrate with broader enterprise risk management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.