OSFI B-13
Cyber Security (5 NIST CSF Functions)

OSFI B-13 OSFIB13-3: Cyber Security: Identification, Protection, Detection, Response, Recovery

Operate cyber security per OSFI B-13 Domain 3 aligned with NIST Cybersecurity Framework 2.0 functions (Govern + Identify + Protect + Detect + Respond + Recover). Identification must (a) maintain asset inventory + business context + risk assessment + governance + (b) implement vulnerability management with KEV + vendor advisory + threat intelligence consumption. Protection must (a) implement identity and access management + multi-factor authentication for privileged + remote + administrative + (b) network segmentation + zero trust progression + (c) endpoint protection + EDR + (d) data protection including encryption + DLP + classification + (e) application security including SAST + DAST + dependency scanning + (f) configuration hardening + change management + (g) secure development lifecycle + (h) security awareness + training. Detection must (a) implement SIEM + UEBA + EDR + with correlation rules + (b) threat hunting capability + (c) integrate with threat intelligence + (d) maintain alert triage + investigation capability. Response must (a) maintain IR plan + tabletop annually + (b) coordinate with OSFI Technology and Cyber Incident reporting (within 24 hours of operationally relevant incidents) + (c) integrate with Financial Crime + AML + Privacy + Legal + Communications + Operations. Recovery must (a) maintain BCM + DR capability + (b) test annually + (c) coordinate with business continuity.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 343 controls across 84 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

NIST SP 800-53 Rev 5 · 11 controls

  • FFIEC-06 Network security and segmentation
  • FFIEC-07 Endpoint protection and detection
  • FFIEC-08 Application security controls
  • FFIEC-09 Encryption and key management
  • FFIEC-10 Secure configuration standards
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

BSI IT-Grundschutz · 7 controls

  • BSI-08 Cryptographic protection of data
  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
  • IM8-CLD.2 Cloud Security Controls
  • IM8-DSS.3 Secure Development Practices
  • IM8-RES.1 Business Continuity Planning
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.3 Incident Response
  • IM8-RES.4 Resilience Testing
  • IM8-SEC.3 Network Security

API 1164 · 6 controls

  • API1164-13 Business Continuity and Recovery
  • API1164-14 Physical Security
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • API1164-22 Configuration management for OT systems

FedRAMP Rev 5 · 6 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • FEDRAMP-CP-9 System Backup
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

IEC 62443 · 6 controls

  • IEC62443-13 Network security monitoring
  • IEC62443-14 System security hardening
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • IEC62443-22 Configuration management for OT systems

ISO/IEC 27019:2024 · 6 controls

  • ISO27019-13 Network security monitoring
  • ISO27019-14 System security hardening
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • ISO27019-22 Configuration management for OT systems

ISO/IEC 27031:2011 · 6 controls

  • 27031-7.1 IRBC Strategy
  • 27031-7.2 Resource Requirements
  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • 27031-D Developing performance criteria

ISO/IEC 27043:2015 · 6 controls

  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • ISO27043-23 Backup and recovery procedures
  • ISO27043-27 Network security management

ISO/SAE 21434 · 6 controls

  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • ISO21434-23 Backup and recovery procedures
  • ISO21434-27 Network security management

NIST SP 1800-32 · 6 controls

NIST SP 800-190 · 6 controls

South Korea ISMS-P · 6 controls

  • ISMSP-AC-04 Network Access Control
  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-01 System Hardening and Patch Management
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-05 Incident Response
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • AWWA-3.1 Network Segmentation
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.1 Malware Protection
  • AWWA-4.3 Configuration Management

ISO 22316 · 5 controls

  • ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience
  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities
  • ISO22316-14 Supply chain continuity
  • ISO22316-15 Communication strategy during disruption

ISO/TS 22317:2021 · 5 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-11 Continuity strategy development
  • ISO22317-12 Recovery strategy for critical activities
  • ISO22317-14 Supply chain continuity
  • ISO22317-15 Communication strategy during disruption

ISO/TS 22318:2021 · 5 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • ISO22318-13 Alternate site and resource planning
  • ISO22318-14 Supply chain continuity
  • ISO22318-15 Communication strategy during disruption
  • NFPA1600-4.1 Leadership and Commitment
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.2 Crisis Management and Communications
  • NFPA1600-6.3 Emergency Response Operations
  • NFPA1600-6.4 Continuity and Recovery

APPI · 4 controls

  • APPI-A31 Provision of Personally Referable Information
  • APPI-A34 Request for Correction, Addition or Deletion
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

Bahrain PDPL · 4 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

ISO/IEC 27010:2015 · 4 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-13.1 Communications Security
  • 27010-16.1 Continuity of Sharing
  • 27010-17.1 Compliance

ISO/IEC 27011:2024 · 4 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation
  • 27011-8.3 Cryptography and key management
  • 27011-8.6 Data protection and backup

ISO/IEC 27400:2022 · 4 controls

  • 27400-6.2 Device Identity and Authentication
  • 27400-6.3 Secure Update Mechanism
  • 27400-6.4 Default Configuration Security
  • 27400-6.5 Security monitoring and incident response
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • IS.AR.215 Information Security Incident Response
  • IS.D.OR.225 External Reporting of Information Security Events
  • IS.I.OR.225 External Reporting
  • CJIS-7 Configuration Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • CAT-D3-1 Preventative controls
  • CAT-D3-3 Corrective controls
  • CAT-D5-1 Incident planning and strategy
  • ISO-22313-5.2 Policy
  • ISO-22313-6.2 Business continuity objectives and plans to achieve them
  • ISO-22313-6.3 Planning changes to the BCMS

ISO 22320:2018 · 3 controls

  • ISO-22320-5.2 Incident management process
  • ISO-22320-B Annex B: Incident management plan structure
  • ISO-22320-C Annex C: Incident management task examples

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

OWASP ASVS · 3 controls

OWASP MASVS · 3 controls

OWASP Top 10:2025 · 3 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

OpenSSF Scorecard · 3 controls

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts
  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • D.3 Backup and Recovery
  • OB-OPS.4 Incident Management
  • OB-SEC.2 Transport Layer Security
  • OB-SEC.4 Certificate Management
  • CYB-3 Device Security Measures
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • CPS230-13 Board Accountability for Operational Risk Management
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • 4.4.7 Emergency and Incident Response
  • 4.4.8 Business Continuity and Recovery
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO28001-PS-01 Facility Security

ISO/IEC 20000-1:2018 · 2 controls

  • ISO20000-10 Configuration management
  • ISO20000-11 Incident management

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team

ITIL 4 · 2 controls

  • ITIL4-10 Configuration management
  • ITIL4-11 Incident management
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response

Privacy Act 2020 · 2 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-7 Notifiable Privacy Breach Scheme

South Korea PIPA · 2 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25
  • AS9100D-8.1 Operational Planning and Control
  • BS65000-RM-02 Integrated Approach
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue
  • DIQ-1 Data Integration and Interoperability

FIDO2 / WebAuthn · 1 control

  • 62351-9 Cyber security key management
  • ISO-15189-7.8 Continuity and emergency preparedness
  • ISO-26262-8-7 Configuration management
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PSPF24-1 Security Culture, Governance, Risk Management
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 343 it maps to, and the evidence behind each claim, over MCP and REST.