OSFI B-13
Cyber Security (5 NIST CSF Functions)

OSFI B-13 OSFIB13-3: Cyber Security: Identification, Protection, Detection, Response, Recovery

Operate cyber security per OSFI B-13 Domain 3 aligned with NIST Cybersecurity Framework 2.0 functions (Govern + Identify + Protect + Detect + Respond + Recover). Identification must (a) maintain asset inventory + business context + risk assessment + governance + (b) implement vulnerability management with KEV + vendor advisory + threat intelligence consumption. Protection must (a) implement identity and access management + multi-factor authentication for privileged + remote + administrative + (b) network segmentation + zero trust progression + (c) endpoint protection + EDR + (d) data protection including encryption + DLP + classification + (e) application security including SAST + DAST + dependency scanning + (f) configuration hardening + change management + (g) secure development lifecycle + (h) security awareness + training. Detection must (a) implement SIEM + UEBA + EDR + with correlation rules + (b) threat hunting capability + (c) integrate with threat intelligence + (d) maintain alert triage + investigation capability. Response must (a) maintain IR plan + tabletop annually + (b) coordinate with OSFI Technology and Cyber Incident reporting (within 24 hours of operationally relevant incidents) + (c) integrate with Financial Crime + AML + Privacy + Legal + Communications + Operations. Recovery must (a) maintain BCM + DR capability + (b) test annually + (c) coordinate with business continuity.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.