xmodoxmodo

Frameworks · Middle East

CBUAE Technology Risk & Information Security

The Central Bank of the UAE sets technology risk and information security requirements through articles in its regulations. These cover banks, finance companies, payment and stored-value providers and other licensees, supported by best-practice guidance. There is no standalone cybersecurity framework. xmodo sets up these requirements as a single pack, with each obligation mapped to the article that imposes it.

Who it applies to

It applies to financial institutions licensed by the Central Bank of the UAE. The articles that apply depend on the licence type, and the pack is scoped to your licences when you adopt it.

Main requirements

Technology risk governance

The board and senior management are accountable for technology risk and policies, with an independent view of the control environment.

Information security controls

Controls cover access, data protection, network and system security, secure development and change management.

Outsourcing & cloud

Firms carry out due diligence, set contract terms, manage data location and meet the Central Bank's notification and approval expectations.

Incidents & continuity

Firms manage and report incidents, and test business continuity and recovery.

How xmodo supports it

  • 1

    Each requirement shows the regulation and article that imposes it, such as the Technology Risk and Information Security articles and the best-practice guidance annex. An examiner can trace any control to its source.

  • 2

    The pack is scoped by licence type when you adopt it, so a payment provider and a bank each see only the obligations that apply to them.

  • 3

    The pack sits beneath the Risk Management Regulation and shares its board reporting and group structure.

  • 4

    Mapping to ISO/IEC 27001, PCI DSS and NIST CSF 2.0 gives credit for the controls you already run.

Related frameworks

CBUAE Technology Risk & Information Security shares requirements with the frameworks below. Controls you already run for any of them count towards CBUAE Technology Risk & Information Security as well.

Frequently asked questions

Why is this not called the CBUAE Cybersecurity Framework?

No document with that title exists. The obligations are spread across licence-specific regulations and guidance. An examiner first asks where a requirement comes from, so the pack refers only to sources that exist.

Can we see the source article for each control?

Yes. Each requirement in the pack is tagged with its regulation and article, and the framework page in the product lists them. When the Central Bank amends an article, xmodo records a new version of the affected requirements.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo