OSFI B-13
Cyber Hygiene and Awareness

OSFI B-13 OSFIB13-5: Cyber Hygiene and Security Awareness

Operate cyber hygiene + security awareness per OSFI B-13 Domain 5. Cyber hygiene must (a) maintain patch management with risk-based prioritisation + KEV-driven remediation + (b) configuration management with hardened baselines + drift detection + (c) vulnerability scanning + remediation tracking + (d) credential hygiene including password policies + MFA + privilege management + (e) backup integrity + ransomware resilience + immutable backup. Security awareness and training must (a) baseline training all personnel + (b) role-specific training (developers + administrators + executives + customer-facing + finance + HR + procurement) + (c) phishing simulation with realistic scenarios + measurement + targeted reinforcement + (d) executive briefing on emerging threats + organisational risk + (e) maintain training records + completion + competency assessment.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.