RSM Global
Cybersecurity and Operational Resilience Framework Overview
Pages
11
Time to read
6 mins
Publication
Language
English
Pages
11
Time to read
6 mins
Publication
Language
English
This document is a technical report detailing the Cybersecurity and Operational Resilience Framework (CORF) introduced by the Central Bank of Kuwait (CBK) on December 3, 2025. The CORF is an evolution of the 2020 Cybersecurity Framework and aims to enhance cybersecurity and operational resilience across various regulated entities in response to emerging threats and regulatory requirements. The report outlines the structure of the CORF, which includes three baselines: Cyber Resilience, Operational Resilience, and Third Party Risk Management, along with a comprehensive set of controls totaling 876. It describes the tier-based assessment model used to categorize regulated entities based on their risk profiles and the frequency of assessments required. Additionally, the report emphasizes the importance of engaging independent assessors to conduct evaluations against the CORF and highlights the necessity for organizations to adopt advanced cybersecurity tools and practices to meet compliance standards. The document serves as a guide for organizations to understand the framework and implement necessary changes.