TrustPoint

CBO Cyber Security and Resilience Framework

The cyber security regulatory framework issued by the Central Bank of Oman for the institutions it supervises, and the second framework pack in the TrustPoint core library.

Publisher
Central Bank of Oman
Version
2023
Country
Oman
Availability
Included in the platform

What the framework is

The Cyber Security and Resilience Framework (CS&RF) is issued by the Central Bank of Oman and sets out the cyber security expectations placed on the financial institutions it supervises. It is a supervisory framework rather than a voluntary standard, which changes the character of the work: the audience for your evidence is a regulator with the power to act on what it finds.

The framework is structured around domains covering governance, risk, operations, resilience and third-party arrangements, and it is explicitly maturity-oriented. Rather than a binary implemented or not, an institution is expected to demonstrate a level of maturity for each area and to show that level improving over time.

Who it applies to

The framework applies to institutions licensed and supervised by the Central Bank of Oman. In practice that means banks and the wider licensed financial sector in the Sultanate, and it reaches their material outsourcing arrangements through the third-party expectations in the framework.

Institutions operating in Oman alongside other Gulf markets frequently carry the CBO framework, a Saudi control set and an international standard at the same time. That combination is exactly where the cost of running frameworks separately becomes visible.

The maturity model, and why it changes the work

A maturity-based framework asks a harder question than a checklist. It is not enough to have done the thing once; you have to show the practice is defined, applied consistently, measured, and improved. Each of those states needs different evidence.

The practical consequence is that maturity has to be tracked per area and per scope over time, not recalculated by hand the month before a supervisory review. An institution that can only produce its current position has already lost the argument about whether it is improving.

TrustPoint reports maturity as a perimeters-by-frameworks heatmap, and posture snapshots retain the point-in-time position so the trend is a record rather than a reconstruction.

How TrustPoint supports it

The CBO pack ships in the core library. You attach it to a perimeter, assess requirement by requirement with status, score, notes and evidence, and report maturity in the CBO-style levels the framework expects.

Because the framework carries strong expectations around third parties and around incident handling, the modules that matter most alongside the assessment are Third-Party Risk and Incidents. Vendor tiering drives assessment depth and cadence, questionnaire campaigns chase the responses, and the vendor-to-asset map means an incident at a supplier scopes against your own estate immediately.

On the incident side, statutory notification deadlines count down in the interface with escalating notifications, and each playbook step is timestamped as it is completed, which is the evidence a supervisor asks for after the fact.

Gaps become work items on a roadmap with owners. Board reporting is a template rather than a rebuild, and the OData v4 feed lets an existing Power BI board pack read the live register directly.

What it maps to, and what that saves

The CBO framework overlaps heavily with ISO/IEC 27001 and with the NCA ECC in the areas both cover, and with PCI DSS wherever card data is in scope.

The platform does not yet include a mapping set from CBO CS&RF to other frameworks, so these overlaps are not suggested automatically. You can attach the same evidence item to the requirements it supports in each framework you assess, and each assessment keeps its own status and its own gaps.

For a bank assessing CBO CS&RF and ISO 27001 at once, keeping each gap visible matters more than the saving. An efficiency that hides a gap is a finding deferred to the next supervisory cycle.

Common questions

Does TrustPoint report maturity in the levels the CBO framework uses?

Yes. Maturity is reported as a perimeters-by-frameworks heatmap using CBO-style maturity levels, and posture snapshots retain the historical position so improvement over time is evidenced rather than asserted.

Can our data stay inside Oman?

Yes. Alongside multi-tenant SaaS, TrustPoint deploys into your own private cloud subscription and region, or fully on-premises and air-gapped. In the on-premises shape the platform, its connectors and a local AI model all sit inside your network, and licence activation works fully offline.

How are third-party expectations handled?

Through the Third-Party Risk module. Vendors are tiered by criticality, which drives how deep and how often each is assessed. Questionnaire campaigns chase responses automatically, vendors answer in an external portal without needing an account in your tenant, and weak answers become findings tracked in the same model as audit findings.

Does the platform work in Arabic for a regulator submission?

Every module, report and email works in both Arabic and English with the layout fully mirrored. Framework codes, control references and numerals stay in Latin script so they match the source documents.

Is TrustPoint approved by the Central Bank of Oman?

No. TrustPoint is software for running and evidencing an assessment against the framework. Any approval, licensing or supervisory judgement is the Central Bank of Oman’s to make, and we do not represent otherwise.

Commonly mapped to

See TrustPoint assessed against CBO CS&RF.

A 45-minute working session focused on the frameworks and requirements that matter to your organization.