Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct
The Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct (2020) establishes cybersecurity expectations for BMA-regulated entities including insurers, reinsurers, banks, and trust companies. Bermuda is a major international insurance and reinsurance hub. The Code covers cyber risk governance, risk management, incident response, third-party management, and reporting. Proportionate approach based on entity size, complexity, and cyber risk profile. Compliance monitored through BMA supervisory reviews and examinations.
Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct is a compliance framework from Bermuda (BMA) with 4 domains and 27 controls that map to 46 other frameworks. The largest domains are BMA Code Section VI: Detect and Protect Controls (15 controls), BMA Code Section V: Identification of Assets and Risks (9 controls), BMA Code Sections III-IV: Interpretation and Proportionality (2 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
BMA Code Section V: Identification of Assets and Risks
| Code | Title |
|---|---|
| BMA-12 | Board and Senior Management Oversight |
| BMA-13 | Asset Inventory |
| BMA-27 | Cyber Insurance |
| BMA-3 | Operational Cyber Risk Management Programme |
| BMA-4 | Chief Information Security Officer |
| BMA-5 | Three Lines of Defence |
| BMA-6 | Risk Assessment Process |
| BMA-7 | Information Technology Audit Plan |
| BMA-8 | Third-Party, Outsourcing and Cloud Risk |
BMA Code Section VI: Detect and Protect Controls
| Code | Title |
|---|---|
| BMA-10 | Threat Intelligence and Vulnerability Alerting |
| BMA-11 | Information Technology Incident Management |
| BMA-14 | IT Security Incident Management and Response Team |
| BMA-15 | Notification of Cyber Reporting Events to the Authority |
| BMA-16 | Access Management and Segregation of Duties |
| BMA-17 | Staff Cyber Risk Awareness Training |
| BMA-18 | Data Classification and Security |
| BMA-19 | Data Protection, Governance and Loss Prevention |
| BMA-20 | Malicious Code Controls |
| BMA-21 | Security Testing Programme |
| BMA-22 | Patch Management |
| BMA-23 | Data Deletion, Sanitisation and Disposal |
| BMA-24 | Network Security Management |
| BMA-25 | Use of Cryptography |
| BMA-9 | Information Technology Services Management |
BMA Code Section VII: Response and Recovery Controls
| Code | Title |
|---|---|
| BMA-26 | Business Continuity and Disaster Recovery Planning |
Your Compliance Coverage
If you comply with Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, you already cover:
NIST Cybersecurity Framework 2.0
81%
22 controls mapped
Compare →NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
15%
4 controls mapped
Compare →API 1164
15%
4 controls mapped
Compare →+ 43 more: ISO 31000:2018 (11%), ASIS SPC.1-2009 - Organizational Resilience Standard (11%)
See all 46 mapped frameworks ↓Maps to 46 other frameworks
If I already comply with another framework, how much of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct do I already cover?
Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct maps to 46 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (81% coverage), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (15% coverage), API 1164 (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required