# Bank of Mauritius Guideline on Cyber and Technology Risk Management

Framework id: `bom_ctrm`. Financial Regulation. Publisher: Bank of Mauritius (BoM). Version: 2023. Region: Mauritius. Mapping licence: CC BY-SA 4.0.
Source text: https://www.bom.mu/

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (26, average coverage 78%)
- 1.1 Board and Senior Management Oversight: PM-01, PM-02, PM-03, PM-09, PM-13, PM-28, PM-29, PS-09, PL-09 (68%)
- 1.2 Roles and Responsibilities of the CISO: PM-02, PM-13, PS-01, PS-02, PS-06, PS-07, PS-09, PM-29 (65%)
- 1.3 Technology Strategy: PM-01, PM-07, PM-11, PL-01, PL-02, PL-08, SA-02, SA-03 (62%)
- 1.4 Cyber and Technology Risk Management Strategy and Framework: PM-01, PM-09, PM-28, RA-01, RA-02, RA-03, RA-04, RA-07, RA-09, PL-09, PL-10, PL-11, CA-05 (78%)
- 1.5 Control Functions (Three Lines of Defence): PM-14, CA-01, CA-02, CA-06, CA-07, CA-09, PM-04, PM-06, AU-01, AU-06, PM-30 (66%)
- 2.1 Identification of Cyber and Technology Risks: RA-01, RA-02, RA-03, RA-04, RA-05, RA-06, RA-07, RA-08, RA-09, PM-09, PM-11, PM-16, CM-08, CM-12, PM-05 (82%)
- 3.1 Control Implementation and Design: PL-01, PL-02, PL-08, PL-10, PL-11, SA-04, SA-08, SA-17, CM-01, CM-02, CM-06, CA-02, CA-07 (85%)
- 3.2 Network and Infrastructure Management: SC-07, SC-08, SC-20, SC-21, SC-22, SC-32, SC-39, SC-46, CM-02, CM-06, CM-07, CM-08, AC-04, AC-17, AC-18, AC-20, SI-04 (90%)
- 3.3 Logical Security Management: AC-01, AC-02, AC-03, AC-05, AC-06, AC-07, AC-08, AC-09, AC-10, AC-11, AC-12, AC-24, IA-01, IA-02, IA-03, IA-04, IA-05, IA-06, IA-07, IA-08, IA-09, IA-10, IA-11, IA-12 (92%)
- 3.4 Encryption and Cryptographic Materials: SC-12, SC-13, SC-08, SC-28, SC-17, SC-40 (87%)
- 3.5 Physical Security Management: PE-01, PE-02, PE-03, PE-04, PE-05, PE-06, PE-07, PE-08, PE-09, PE-10, PE-11, PE-12, PE-13, PE-14, PE-15, PE-17, PE-18 (88%)
- 3.6 Change and Patch Management: CM-03, CM-04, CM-05, CM-09, CM-11, SI-02, SI-07, SA-10, CM-14 (88%)
- 3.7 Technology Refresh Management: SA-22, CM-08, PM-07, RA-09, PL-08, SA-02, SA-03 (72%)
- 3.8 People Management: AT-01, AT-02, AT-03, AT-04, AT-05, AT-06, PS-01, PS-02, PS-03, PS-04, PS-05, PS-06, PS-07, PS-08, PM-13, PM-15 (80%)
- 3.9 Third-Party Service Providers: SA-04, SA-09, SR-01, SR-02, SR-03, SR-05, SR-06, SR-08, SA-21, PM-30, PS-07, CA-03 (72%)
- 3.10 Hosting of Customer Information Outside Mauritius: SA-09, PM-09, PT-01, PT-02, PT-03, PT-05, SC-08, SC-28, AC-04 (52%)
- 3.11 Secure Coding in Application Development: SA-03, SA-04, SA-08, SA-10, SA-11, SA-15, SA-16, SA-17, SA-20, SA-21, CM-14 (90%)
- 3.12 End-User Computing: CM-11, CM-07, AC-19, SC-42, SC-43, MP-07, SC-28 (70%)
- 3.13 Online Financial Services Security: SC-07, SC-08, SC-13, SC-23, SC-45, IA-02, IA-08, AC-17, AU-02, AU-03, SI-10 (73%)
- 4.1 Cyber and Technology Threat Intelligence: PM-16, RA-03, RA-05, RA-10, SI-04, SI-05, PM-15, SR-08 (80%)
- 4.2 Detection of Cyber Events and Monitoring: SI-04, AU-02, AU-03, AU-04, AU-05, AU-06, AU-07, AU-08, AU-09, AU-10, AU-12, AU-13, AU-14, CA-07, SC-26, SC-44, IR-04 (88%)
- 4.3 Vulnerability Assessment and Penetration Testing: CA-02, CA-08, RA-05, RA-06, RA-09, PM-14, CA-05 (85%)
- 5.1 Cyber Incident Management: IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-07, IR-08, IR-09, AU-06, SI-04, SI-05, PM-31 (82%)
- 5.2 Business Continuity and Response and Recovery Planning: CP-01, CP-02, CP-03, CP-04, CP-06, CP-07, CP-08, CP-09, CP-10, CP-11, CP-12, CP-13, SC-24, SI-17 (82%)
- 5.3 Situational Awareness, Learning and Evolving: PM-15, PM-16, IR-05, CA-07, PM-14, AT-02, AT-05, RA-07, SI-05 (75%)
- 5.4 Technology Audit: AU-01, CA-01, CA-02, CA-06, CA-07, CA-09, PM-04, PM-06, PM-14 (68%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=bom_ctrm
- Control-to-clause mappings as JSON: /api/v1/frameworks/bom_ctrm?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/bom-ctrm.json
- Page for people: /frameworks/bom-ctrm/
