RSM Global
Cybersecurity and Operational Resilience Framework Overview
Pages
9
Time to read
6 mins
Publication
Language
English
Pages
9
Time to read
6 mins
Publication
Language
English
This document is a technical report that outlines the Cybersecurity and Operational Resilience Framework (CORF) introduced by the Central Bank of Kuwait (CBK) on December 3, 2025. The CORF evolves from the 2020 Cybersecurity Framework (CSF) to enhance cybersecurity and operational resilience in response to emerging threats and regulatory demands. It aligns with international standards such as NIST and ISO27001, advocating for the adoption of advanced cybersecurity tools and practices. The report details the structure of the CORF, which includes three baselines and a total of 876 controls, compared to the previous framework's 291 controls. It describes the tier-based assessment model used to categorize regulated entities based on their risk profiles, compliance testing, and maturity evaluations. Additionally, the document emphasizes the importance of engaging independent assessors for compliance assessments and outlines potential next steps for organizations to enhance their resilience frameworks.