Reading time: ~ 2 min.

The Central Bank of Bahrain and the rulebook
📘 Common Volume
📘 Volume 1 (Conventional Banks)
📘 Volume 2 (Islamic Banks)
📘 Volume 3 (Insurance)
📘 Volume 4 (Investment Business)
📘 Volume 5 (Specialised Lincensees)
📘 Volume 6 (Capital Markets)
📘 Volume 7 (Collective Investment Undertakings)
In our article, we're going to take a closer look at the «Volume 1» on conventional banks.
The CBB Rulebook Volume 1 and its requirements
🔖OM-2 Outsourcing requirements
🔖OM-3 Electronic money and electronic bank activities
🔖OM-4 Business Continuity Management
🔖OM-5 Security measures for banks
🔖 OM-6 Books and records
🔖 Appendix A, B and C (Loss event type classification, Cyber security control guidelines)
How can we manage these Rulebook requirements for ICT resources? Our solution is a GRC Approach: let's take a closer look in the next lines.
The ISO standards applicable to the CBB Rulebook requirements for ICT Resources
We can support the management – in an integrated way – of the requirements for ICT resources set by the Central Bank of Bahrain with the GRC approach based in particular on these ISO standards:
✅ ISO 38500 on Governance
✅ ISO 31000 on Risk Management
✅ ISO 37301 on Compliance Management
We should keep in mind, in this case, that the focus is on the information security, business continuity and IT services.
With the GRC approach on the ICT resources requirements management we can take advantage also of the chance to adopt and integrate the reference standards available, as the ISO standards and NIST standards.
These are the main relevant standards:
📘 Information security standard: ISO 27001;
📘 Cybersecurity framework standard: ISO 27110 and NIST standard;
📘 Business Continuity standard: ISO 22301;
📘 IT services standard: ISO 20000-1.
Our infographic on CBB rulebook ICT resources requirements and related ISO standards

Our sponsors
A special thanks to our Advanced Sponsors:


