Oman National Cybersecurity Framework
Network + Endpoint + SDLC

Oman National Cybersecurity Framework OMANCS-5: Network, Endpoint, System Development, and Configuration Security

Operate network security + endpoint protection + secure system development + configuration management per Oman framework. Network security must include segmentation + perimeter protection + intrusion detection + DLP + zero trust architecture aligned with maturity. Endpoint protection must include EDR + application allowlisting + USB control + patching + hardening. Secure system development must apply SDLC controls including threat modeling + secure coding + SAST + DAST + dependency scanning + secrets management + SBOM. Configuration management must maintain hardened baselines per asset class + automated compliance scanning + drift detection + remediation. Vulnerability and patch management must consume Oman CERT + ICS-CERT + vendor advisories + KEV + apply risk-based remediation + compensating controls.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 97 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)

API 1164 · 3 controls

  • API1164-13 Business Continuity and Recovery
  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems
  • AWWA-3.1 Network Segmentation
  • AWWA-4.1 Malware Protection
  • AWWA-4.3 Configuration Management

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory
  • FFIEC-06 Network security and segmentation
  • FFIEC-07 Endpoint protection and detection
  • FFIEC-10 Secure configuration standards

IEC 62443 · 3 controls

  • IEC62443-13 Network security monitoring
  • IEC62443-14 System security hardening
  • IEC62443-22 Configuration management for OT systems

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-13 Network security monitoring
  • ISO27019-14 System security hardening
  • ISO27019-22 Configuration management for OT systems

NIST SP 1800-32 · 3 controls

NIST SP 800-190 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-8.A Network Segmentation
  • CAT-D3-1 Preventative controls
  • CAT-D3-3 Corrective controls

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning

ISO/IEC 27011:2024 · 2 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

South Korea ISMS-P · 2 controls

  • ISMSP-AC-04 Network Access Control
  • ISMSP-SYS-01 System Hardening and Patch Management
  • AS9100D-8.1 Operational Planning and Control
  • Clause 10 Change and configuration management
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CJIS-7 Configuration Management
  • ISO-26262-8-7 Configuration management
  • ISO28001-PS-01 Facility Security
  • ISO20000-10 Configuration management

ISO/IEC 27010:2015 · 1 control

  • 27010-13.1 Communications Security

ISO/IEC 27043:2015 · 1 control

  • ISO27043-27 Network security management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.4 Default Configuration Security

ISO/SAE 21434 · 1 control

  • ISO21434-27 Network security management

ITIL 4 · 1 control

  • ITIL4-10 Configuration management
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • OWASPAPI-6 Security Misconfiguration and Secure API Design

OWASP ASVS · 1 control

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 97 it maps to, and the evidence behind each claim, over MCP and REST.