Frameworks / OSFI B-13 / OSFIB13-3 OSFI B-13
Cyber Security (5 NIST CSF Functions)
OSFI B-13 OSFIB13-3: Cyber Security: Identification, Protection, Detection, Response, Recovery Operate cyber security per OSFI B-13 Domain 3 aligned with NIST Cybersecurity Framework 2.0 functions (Govern + Identify + Protect + Detect + Respond + Recover). Identification must (a) maintain asset inventory + business context + risk assessment + governance + (b) implement vulnerability management with KEV + vendor advisory + threat intelligence consumption. Protection must (a) implement identity and access management + multi-factor authentication for privileged + remote + administrative + (b) network segmentation + zero trust progression + (c) endpoint protection + EDR + (d) data protection including encryption + DLP + classification + (e) application security including SAST + DAST + dependency scanning + (f) configuration hardening + change management + (g) secure development lifecycle + (h) security awareness + training. Detection must (a) implement SIEM + UEBA + EDR + with correlation rules + (b) threat hunting capability + (c) integrate with threat intelligence + (d) maintain alert triage + investigation capability. Response must (a) maintain IR plan + tabletop annually + (b) coordinate with OSFI Technology and Cyber Incident reporting (within 24 hours of operationally relevant incidents) + (c) integrate with Financial Crime + AML + Privacy + Legal + Communications + Operations. Recovery must (a) maintain BCM + DR capability + (b) test annually + (c) coordinate with business continuity.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 343 controls across 84 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-04 User application hardening (Essential) ASD37-10 Server application hardening (Very Good) ASD37-11 Operating system hardening (Very Good) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASD37-17 TLS encryption between email servers (Limited) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-25 Software firewall - inbound (Very Good) ASD37-31 Hunt to discover incidents (Very Good) ASD37-33 Capture network traffic (Limited) ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) FFIEC-06 Network security and segmentation FFIEC-07 Endpoint protection and detection FFIEC-08 Application security controls FFIEC-09 Encryption and key management FFIEC-10 Secure configuration standards FFIEC-11 Business continuity planning and testing FFIEC-12 Disaster recovery procedures FFIEC-23 Regulatory reporting requirements FFIEC-24 Customer notification procedures FFIEC-25 Post-incident review and improvement BSI-08 Cryptographic protection of data BSI-18 Incident response planning and testing BSI-20 Incident reporting and notification BSI-21 Forensic analysis capabilities BSI-23 Baseline configuration establishment BSI-24 Configuration change control BSI-26 System component inventory NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-PR.PS-01 Configuration management practices are established and applied NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied IM8-CLD.2 Cloud Security Controls IM8-DSS.3 Secure Development Practices IM8-RES.1 Business Continuity Planning IM8-RES.2 Disaster Recovery IM8-RES.3 Incident Response IM8-RES.4 Resilience Testing IM8-SEC.3 Network Security API1164-13 Business Continuity and Recovery API1164-14 Physical Security API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface API1164-22 Configuration management for OT systems FEDRAMP-CM-1 Configuration Management Policy FEDRAMP-CM-2 Baseline Configuration FEDRAMP-CP-9 System Backup FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity IEC62443-13 Network security monitoring IEC62443-14 System security hardening IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents IEC62443-22 Configuration management for OT systems ISO27019-13 Network security monitoring ISO27019-14 System security hardening ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents ISO27019-22 Configuration management for OT systems 27031-7.1 IRBC Strategy 27031-7.2 Resource Requirements 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review 27031-D Developing performance criteria ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO27043-23 Backup and recovery procedures ISO27043-27 Network security management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management ISO21434-23 Backup and recovery procedures ISO21434-27 Network security management ISMSP-AC-04 Network Access Control ISMSP-PI-06 Personal Information Destruction ISMSP-SYS-01 System Hardening and Patch Management ISMSP-SYS-02 Encryption Implementation ISMSP-SYS-05 Incident Response ISMSP-SYS-06 Business Continuity and Disaster Recovery AWWA-3.1 Network Segmentation AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AWWA-4.1 Malware Protection AWWA-4.3 Configuration Management ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience ISO22316-08 Recovery time and point objectives ISO22316-12 Recovery strategy for critical activities ISO22316-14 Supply chain continuity ISO22316-15 Communication strategy during disruption ISO22317-08 Recovery time and point objectives ISO22317-11 Continuity strategy development ISO22317-12 Recovery strategy for critical activities ISO22317-14 Supply chain continuity ISO22317-15 Communication strategy during disruption ISO22318-08 Recovery time and point objectives ISO22318-12 Recovery strategy for critical activities ISO22318-13 Alternate site and resource planning ISO22318-14 Supply chain continuity ISO22318-15 Communication strategy during disruption NFPA1600-4.1 Leadership and Commitment NFPA1600-5.3 Resource Needs Assessment NFPA1600-6.2 Crisis Management and Communications NFPA1600-6.3 Emergency Response Operations NFPA1600-6.4 Continuity and Recovery APPI-A31 Provision of Personally Referable Information APPI-A34 Request for Correction, Addition or Deletion APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 27010-10.1 Cryptographic Protection 27010-13.1 Communications Security 27010-16.1 Continuity of Sharing 27010-17.1 Compliance 27011-6.3 Awareness and Training 27011-8.2 Network security and segregation 27011-8.3 Cryptography and key management 27011-8.6 Data protection and backup 27400-6.2 Device Identity and Authentication 27400-6.3 Secure Update Mechanism 27400-6.4 Default Configuration Security 27400-6.5 Security monitoring and incident response DSOMM-1 Culture, Organization, Education, and Governance DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing IS.AR.215 Information Security Incident Response IS.D.OR.225 External Reporting of Information Security Events IS.I.OR.225 External Reporting CJIS-7 Configuration Management CJIS-8 Media Protection CJIS-9 System and Communications Protection CAT-D3-1 Preventative controls CAT-D3-3 Corrective controls CAT-D5-1 Incident planning and strategy ISO-22313-5.2 Policy ISO-22313-6.2 Business continuity objectives and plans to achieve them ISO-22313-6.3 Planning changes to the BCMS ISO-22320-5.2 Incident management process ISO-22320-B Annex B: Incident management plan structure ISO-22320-C Annex C: Incident management task examples 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security D.1 Incident Response Planning D.2 Incident Reporting D.3 Backup and Recovery OB-OPS.4 Incident Management OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management CYB-3 Device Security Measures CYB-5 Cyber Incident Response Plan USMTSA-2 Cybersecurity Assessment and CSO Designation CPS230-13 Board Accountability for Operational Risk Management CPS230-26 Critical Operations Register, Continuity Plan and Activation CPS234-21 Implementation of Information Security Controls CPS234-25 Internal Audit Review of Information Security Controls 4.4.7 Emergency and Incident Response 4.4.8 Business Continuity and Recovery FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) IEC62304-4.1 Quality Management System IEC62304-5.1 Software Development Planning ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption ISO28001-PC-04 Supply Chain Continuity Planning ISO28001-PS-01 Facility Security ISO20000-10 Configuration management ISO20000-11 Incident management 30111-3 Terms and definitions 30111-5.2 Vulnerability handling team ITIL4-10 Configuration management ITIL4-11 Incident management NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-7 Notifiable Privacy Breach Scheme PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25 AS9100D-8.1 Operational Planning and Control BS65000-RM-02 Integrated Approach BB-DPA-20 Sections 50-60 - Registration and Responsibilities CA-12 Deploys Through Policies and Procedures CA-ITSG33-SC-01 Security Control Catalogue DIQ-1 Data Integration and Interoperability 62351-9 Cyber security key management ISO-15189-7.8 Continuity and emergency preparedness ISO-26262-8-7 Configuration management 29115-7.4 Level of Assurance 4 (LoA4) STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation OWASPAPI-6 Security Misconfiguration and Secure API Design PAKPDPB-5 Security of Processing and Personal Data Breach Notification PSPF24-1 Security Culture, Governance, Risk Management SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights CPSC-CS.1 Network Security for Connected Products USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VPSHR-3 Implementation Guidance and Reporting Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 343 it maps to, and the evidence behind each claim, over MCP and REST.