Back to Frameworks

Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct

Bermuda (BMA)
v2020
4 domains
27 controls

The Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct (2020) establishes cybersecurity expectations for BMA-regulated entities including insurers, reinsurers, banks, and trust companies. Bermuda is a major international insurance and reinsurance hub. The Code covers cyber risk governance, risk management, incident response, third-party management, and reporting. Proportionate approach based on entity size, complexity, and cyber risk profile. Compliance monitored through BMA supervisory reviews and examinations.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

BMA Code Section V: Identification of Assets and Risks

9 controls
Controls in the BMA Code Section V: Identification of Assets and Risks domain of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct9 controls
CodeTitle
BMA-12Board and Senior Management Oversight
BMA-13Asset Inventory
BMA-27Cyber Insurance
BMA-3Operational Cyber Risk Management Programme
BMA-4Chief Information Security Officer
BMA-5Three Lines of Defence
BMA-6Risk Assessment Process
BMA-7Information Technology Audit Plan
BMA-8Third-Party, Outsourcing and Cloud Risk

BMA Code Section VI: Detect and Protect Controls

15 controls
Controls in the BMA Code Section VI: Detect and Protect Controls domain of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct15 controls
CodeTitle
BMA-10Threat Intelligence and Vulnerability Alerting
BMA-11Information Technology Incident Management
BMA-14IT Security Incident Management and Response Team
BMA-15Notification of Cyber Reporting Events to the Authority
BMA-16Access Management and Segregation of Duties
BMA-17Staff Cyber Risk Awareness Training
BMA-18Data Classification and Security
BMA-19Data Protection, Governance and Loss Prevention
BMA-20Malicious Code Controls
BMA-21Security Testing Programme
BMA-22Patch Management
BMA-23Data Deletion, Sanitisation and Disposal
BMA-24Network Security Management
BMA-25Use of Cryptography
BMA-9Information Technology Services Management

BMA Code Section VII: Response and Recovery Controls

1 controls
Controls in the BMA Code Section VII: Response and Recovery Controls domain of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct1 controls
CodeTitle
BMA-26Business Continuity and Disaster Recovery Planning

BMA Code Sections III-IV: Interpretation and Proportionality

2 controls
Controls in the BMA Code Sections III-IV: Interpretation and Proportionality domain of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct2 controls
CodeTitle
BMA-1Interpretation
BMA-2Proportionality Principle

Your Compliance Coverage

If you comply with Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, you already cover:

Maps to 94 other frameworks

27 total controls
NIST Cybersecurity Framework 2.0
22 source controls mapped|15 target controls covered
81%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
4 source controls mapped|5 target controls covered
15%
API 1164
4 source controls mapped|5 target controls covered
15%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
4 source controls mapped|4 target controls covered
15%
ISO/IEC 27011:2024
3 source controls mapped|5 target controls covered
11%
TNFD Recommendations
3 source controls mapped|4 target controls covered
11%
AASB S2 Climate-related Disclosures
3 source controls mapped|4 target controls covered
11%
ASIS SPC.1-2009 - Organizational Resilience Standard
3 source controls mapped|4 target controls covered
11%
ISO/IEC 27031:2011
3 source controls mapped|4 target controls covered
11%
ISO/IEC 38500:2024 - Governance of IT
3 source controls mapped|5 target controls covered
11%
AWS Well-Architected Security Pillar
3 source controls mapped|5 target controls covered
11%
Azure Security Benchmark
3 source controls mapped|5 target controls covered
11%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
3 source controls mapped|3 target controls covered
11%
AS9100D - Aerospace Quality Management System
3 source controls mapped|2 target controls covered
11%
ISO/IEC 27003:2017
3 source controls mapped|2 target controls covered
11%
SQF Code Edition 9 - Safe Quality Food
3 source controls mapped|3 target controls covered
11%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
3 source controls mapped|9 target controls covered
11%
NIST AI Risk Management Framework (AI RMF 1.0)
3 source controls mapped|5 target controls covered
11%
AML/CTF Act 2006 (Australia)
3 source controls mapped|2 target controls covered
11%
ISO/IEC 27400:2022
2 source controls mapped|4 target controls covered
7%
OWASP Top 10:2025
2 source controls mapped|2 target controls covered
7%
IEC 62351 - Power Systems Communication Security
2 source controls mapped|3 target controls covered
7%
ISO/IEC 27007:2020
2 source controls mapped|2 target controls covered
7%
Serbia Law on Personal Data Protection (2018)
2 source controls mapped|3 target controls covered
7%
Portugal Law No. 58/2019 - Data Protection Implementation Act
2 source controls mapped|4 target controls covered
7%
Oman Personal Data Protection Law (Royal Decree 6/2022)
2 source controls mapped|2 target controls covered
7%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
2 source controls mapped|2 target controls covered
7%
BRCGS Global Standard for Food Safety Issue 9
2 source controls mapped|4 target controls covered
7%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
2 source controls mapped|2 target controls covered
7%
7%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
2 source controls mapped|5 target controls covered
7%
ISO/IEC 29134:2023
2 source controls mapped|5 target controls covered
7%
ISO/IEC 27014:2020
2 source controls mapped|4 target controls covered
7%
ISO/IEC 29147:2018
2 source controls mapped|4 target controls covered
7%
Union Customs Code (UCC) - Regulation (EU) No 952/2013
2 source controls mapped|3 target controls covered
7%
Barbados Data Protection Act 2019
2 source controls mapped|2 target controls covered
7%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
2 source controls mapped|4 target controls covered
7%
Saudi PDPL
2 source controls mapped|2 target controls covered
7%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
2 source controls mapped|3 target controls covered
7%
IEC 60601-1 - Medical Electrical Equipment Safety
2 source controls mapped|4 target controls covered
7%
Aged Care Quality Standards (Australia)
2 source controls mapped|1 target controls covered
7%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
2 source controls mapped|1 target controls covered
7%
Singapore Model AI Governance Framework (2nd Edition)
2 source controls mapped|1 target controls covered
7%
US NRC 10 CFR 73.54 - Cyber Security for Nuclear Power Plants
1 source controls mapped|1 target controls covered
4%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|1 target controls covered
4%
Tunisia Organic Law on Personal Data Protection (Law No. 2004-63)
1 source controls mapped|1 target controls covered
4%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|1 target controls covered
4%
WCO Authorised Economic Operator (AEO) Framework
1 source controls mapped|2 target controls covered
4%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|2 target controls covered
4%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
1 source controls mapped|1 target controls covered
4%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
4%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|2 target controls covered
4%
Bahrain PDPL
1 source controls mapped|1 target controls covered
4%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|2 target controls covered
4%
Telecommunications Sector Security Reforms (TSSR)
1 source controls mapped|2 target controls covered
4%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|2 target controls covered
4%
APPI
1 source controls mapped|1 target controls covered
4%
Privacy Act 1988 (Australia)
1 source controls mapped|1 target controls covered
4%
ISO/IEC 30111:2019
1 source controls mapped|3 target controls covered
4%
4%
ISO/IEC 27050 - Electronic Discovery (Parts 1-4)
1 source controls mapped|1 target controls covered
4%
21 CFR Part 58 - Good Laboratory Practice (GLP)
1 source controls mapped|2 target controls covered
4%
SWIFT CSCF
1 source controls mapped|2 target controls covered
4%
SWIFT CSCF v2024
1 source controls mapped|3 target controls covered
4%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|2 target controls covered
4%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
4%
Regulation (EU) 2019/1239 on the Maritime Single Window (MSW)
1 source controls mapped|1 target controls covered
4%
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)
1 source controls mapped|1 target controls covered
4%
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
1 source controls mapped|2 target controls covered
4%
Turkey Personal Data Protection Law (KVKK - Law No. 6698)
1 source controls mapped|1 target controls covered
4%
Uzbekistan Law on Personal Data (No. ZRU-547)
1 source controls mapped|1 target controls covered
4%
Panama Law on Personal Data Protection (Law No. 81 of 2019)
1 source controls mapped|1 target controls covered
4%
Uruguay Personal Data Protection Act (Law No. 18.331)
1 source controls mapped|3 target controls covered
4%
Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)
1 source controls mapped|3 target controls covered
4%
Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016)
1 source controls mapped|1 target controls covered
4%
UNCITRAL Model Law on Electronic Commerce (1996, updated 2005)
1 source controls mapped|1 target controls covered
4%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|2 target controls covered
4%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
4%
South Korea Credit Information Act
1 source controls mapped|1 target controls covered
4%
ISO 20000-1
1 source controls mapped|2 target controls covered
4%
ISO 14001
1 source controls mapped|1 target controls covered
4%
ISO 45001:2018
1 source controls mapped|1 target controls covered
4%
ISO 9001:2015
1 source controls mapped|2 target controls covered
4%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
4%
ISO 19011
1 source controls mapped|3 target controls covered
4%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
4%
ISO 13485
1 source controls mapped|1 target controls covered
4%
ISO 13485:2016
1 source controls mapped|1 target controls covered
4%
OWASP ASVS
1 source controls mapped|1 target controls covered
4%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
4%
ISO 31000:2018
1 source controls mapped|1 target controls covered
4%
Paraguay Law on Protection of Personal Data (Law No. 6534/2020)
1 source controls mapped|1 target controls covered
4%

Frequently Asked Questions

What is Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct?

Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct is a compliance framework from Bermuda (BMA) with 4 domains and 27 controls. The Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct (2020) establishes cybersecurity expectations for BMA-regulated entities including insurers, reinsurers, banks, and trust companies. Bermuda is a major international insurance and reinsurance hub. The Code covers cyber risk governance, risk management, incident response, third-party management, and reporting. Proportionate approach based on entity size, complexity, and cyber risk profile. Compliance monitored through BMA supervisory reviews and examinations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct have?

Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct has 27 controls organised across 4 domains. The largest domains are BMA Code Section VI: Detect and Protect Controls (15 controls), BMA Code Section V: Identification of Assets and Risks (9 controls), BMA Code Sections III-IV: Interpretation and Proportionality (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct map to?

Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct maps to 94 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (81% coverage), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (15% coverage), API 1164 (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct compliance?

Start your Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 27 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required