Open Banking Security
Incident + BCM

Open Banking Security OPENBANK-8: Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

Operate incident detection + response + customer notification + post-incident review + BCM per scheme + applicable regulation. Incident detection and classification must (a) implement SIEM + EDR + fraud detection + with open banking-aware correlation rules + (b) classify incidents per scheme requirements (cyber + operational + customer impact + payment fraud + similar) + (c) integrate with broader security operations. Incident response and containment must (a) maintain IR plan with open banking scenarios (TPP compromise + API abuse + customer credential theft + transaction fraud + scheme infrastructure attack), (b) coordinate with scheme operator + national CERT + payment brand + regulator per applicable obligation. Regulatory reporting requirements must (a) report incidents within scheme + regulatory timeframes (varying 2 hours + 4 hours + 24 hours + 72 hours + 5 days per scheme + incident category), (b) provide complete + accurate + timely reports. Customer notification procedures must (a) notify affected customers per applicable regulation + (b) coordinate with TPPs for customer-facing communication + (c) maintain customer support capacity during incidents. Post-incident review and improvement must (a) conduct lessons-learned post-incident + (b) implement remediation tracking through closure + (c) feed lessons into broader open banking programme. Business continuity planning and testing must (a) maintain ISCP covering open banking services + (b) test annually with technical recovery + tabletop + (c) coordinate with scheme operator + TPPs. Disaster recovery procedures must (a) maintain DR capability per scheme RTO/RPO + (b) test recovery + (c) maintain alternate site + capacity.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 208 controls across 78 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

ISO/IEC 27031:2011 · 7 controls

  • 27031-7.1 IRBC Strategy
  • 27031-7.2 Resource Requirements
  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • 27031-B High availability embedded systems
  • 27031-D Developing performance criteria
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.1 Business Continuity Planning
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.3 Incident Response
  • IM8-RES.4 Resilience Testing
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • 4.4.7 Emergency and Incident Response
  • 4.4.8 Business Continuity and Recovery

ISO 22316 · 5 controls

  • ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience
  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities
  • ISO22316-14 Supply chain continuity
  • ISO22316-15 Communication strategy during disruption

ISO/TS 22317:2021 · 5 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-11 Continuity strategy development
  • ISO22317-12 Recovery strategy for critical activities
  • ISO22317-14 Supply chain continuity
  • ISO22317-15 Communication strategy during disruption

ISO/TS 22318:2021 · 5 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • ISO22318-13 Alternate site and resource planning
  • ISO22318-14 Supply chain continuity
  • ISO22318-15 Communication strategy during disruption
  • NFPA1600-4.1 Leadership and Commitment
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.2 Crisis Management and Communications
  • NFPA1600-6.3 Emergency Response Operations
  • NFPA1600-6.4 Continuity and Recovery

NIST SP 800-53 Rev 5 · 5 controls

APRA CPS 234 · 4 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • IS.AR.215 Information Security Incident Response
  • IS.D.OR.225 External Reporting of Information Security Events
  • IS.I.OR.225 External Reporting

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • ISO-22313-5.2 Policy
  • ISO-22313-6.2 Business continuity objectives and plans to achieve them
  • ISO-22313-6.3 Planning changes to the BCMS

ISO 22320:2018 · 3 controls

  • ISO-22320-5.2 Incident management process
  • ISO-22320-B Annex B: Incident management plan structure
  • ISO-22320-C Annex C: Incident management task examples

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 3 controls

South Korea ISMS-P · 3 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-05 Incident Response
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • D.3 Backup and Recovery
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • OB-OPS.4 Incident Management

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • CPS230-13 Board Accountability for Operational Risk Management
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • BS65000-RM-02 Integrated Approach
  • BS65000-RM-03 Leadership and Culture

Bahrain PDPL · 2 controls

  • CAT-D5-1 Incident planning and strategy
  • CAT-D5-4 Resilience planning and testing
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO/IEC 20000-1:2018 · 2 controls

  • ISO20000-03 Capacity and availability management
  • ISO20000-11 Incident management

ISO/IEC 27010:2015 · 2 controls

  • 27010-16.1 Continuity of Sharing
  • 27010-17.1 Compliance

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team

ITIL 4 · 2 controls

  • ITIL4-03 Capacity and availability management
  • ITIL4-11 Incident management

NIST SP 800-190 · 2 controls

  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience
  • PSPF24-1 Security Culture, Governance, Risk Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight

South Korea PIPA · 2 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25
  • CERT-1 RRA Certification to EPA
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue
  • DIQ-1 Data Integration and Interoperability
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup
  • ISO-15189-7.8 Continuity and emergency preparedness
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 1 control

  • ISO27043-23 Backup and recovery procedures

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ISO/SAE 21434 · 1 control

  • ISO21434-23 Backup and recovery procedures
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

OWASP ASVS · 1 control

  • DSOMM-1 Culture, Organization, Education, and Governance

OWASP MASVS · 1 control

  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response

Privacy Act 2020 · 1 control

  • NZPRV-7 Notifiable Privacy Breach Scheme
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 208 it maps to, and the evidence behind each claim, over MCP and REST.