01
Document overview
A unified cyber-risk framework covering governance and roles, asset inventory and protection, access and identity, secure development, third parties, monitoring, response, recovery, testing and CBO reporting.
02
Scope and exclusions
Applies to
Applies to CBO-licensed institutions, with controls calibrated to institution type, systems, data, services and risk.
Limitations and exclusions
Does not replace incident-notification, cloud, data-protection, bank-secrecy, outsourcing or payment-infrastructure requirements; those operate cumulatively.
04
Official source
CBO Circular BM 1194 · Central Bank of Oman
September 13, 2026
Open official source ↗