National Cyber Security Centre Approves Cybersecurity Standards and Programmes for Critical Sectors

Manama: The National Cyber Security Centre (NCSC) has announced a significant decision to approve Cyber Security Standards for Critical Sectors, along with the National Programme for Measuring Cyber Security Maturity and the National Programme for Assessing Cyber Security Risks. This initiative is part of a broader strategy to fortify the national cyber security infrastructure, enhancing protection and preparedness across critical sectors.

According to Bahrain News Agency, the decision aligns with the implementation of initiatives under the National Cyber Security Strategy, aiming to develop unified national cybersecurity frameworks. These frameworks are designed to assist entities in enhancing cyber governance, measuring maturity and preparedness, identifying and assessing cyber risks, and prioritizing their mitigation. This approach supports risk-based decision-making, thereby enhancing the protection and continuity of critical systems and services.

Shaikh Abdullah bin Mohamed bin Abdulwahab Al Khalifa, Deputy CEO for Cybersecurity Operations at the NCSC, emphasized that the adoption of this framework marks a crucial step forward in advancing national cybersecurity efforts. He explained that integrating cybersecurity standards with maturity measurement and risk assessment programmes provides entities with a clear and systematic framework to identify security requirements, measure their implementation and development, and prioritize based on cyber risks.

Further, Shaikh Abdullah bin Mohamed noted that the framework aims to establish a unified national approach to cybersecurity, focusing on risk, measurement, and continuous improvement. This framework will enable entities to understand their level of cyber maturity, identify strengths and areas for development, and direct efforts and resources toward priority risks.

He added that the development of these frameworks in collaboration with regulators and representatives of critical sectors ensures alignment with each sector's nature and needs, thereby enhancing cybersecurity preparedness and resilience at the national level.

The decision establishes cybersecurity standards for critical sectors as a national reference framework, applicable to entities within those sectors. Developed in coordination with sector regulators and representatives, these standards align security requirements with each sector's risks and operational needs, enhancing cybersecurity protection and resilience nationwide.

Additionally, the National Programme for Measuring Cyber Security Maturity introduces a unified and measurable national methodology for assessing entities' cyber maturity. It establishes four maturity levels-"Practitioner," "Progressive," "Professional," and "Expert"-allowing entities to determine their current maturity, identify improvement areas, and establish clear paths for advancing cybersecurity practices.

The decision also adopts the National Programme for Assessing Cyber Security Risks, which establishes a unified methodology for identifying, analyzing, and assessing cyber risks and exposure levels. It prioritizes mitigation efforts based on the level of risk and potential impact, aiming to enhance entities' ability to manage risks proactively and limit their potential impact on critical systems and services.

Overall, the adoption of these standards and programmes marks an essential step towards building an integrated national cybersecurity framework. This framework combines security requirements, maturity measurement, and risk management, enhancing the ability to systematically measure cybersecurity levels, identify development priorities, and support continuous improvement among concerned entities.

The NCSC continues its commitment to developing the national cybersecurity framework, enhancing cyber governance, risk management, preparedness, and resilience, in alignment with the National Cyber Security Strategy. These efforts are crucial for safeguarding Bahrain's digital environment and ensuring the security and continuity of critical services.