Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct
Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
BMA Code Section V: Identification of Assets and Risks
Board and Senior Management Oversight. The board of directors and senior management team must have oversight of cyber risk and of the operational cyber risk management programme (para 14).
- Board/committee minutes evidencing oversight of cyber risk
- Cyber risk reporting to the board and senior management
- Defined board accountability for the programme
- No board oversight of cyber risk
- Cyber risk not reported to the board
- Accountability undefined
Asset Inventory. An asset inventory detailing all information assets must be put in place and maintained (para 25).
- Information asset inventory with owners and criticality
- Process for keeping the inventory current
- Linkage of assets to risk assessments
- Asset inventory incomplete or stale
- No asset owners assigned
- Critical assets not identified
Cyber Insurance. RLEs should consider the benefits of purchasing a cyber insurance policy as part of their risk transfer strategy (para 24).
- Assessment of cyber insurance need and coverage
- Cyber insurance policy documentation where held
- Linkage of residual risk to risk-transfer decisions
- Cyber insurance not considered
- Coverage not matched to risk profile
- Policy exclusions not understood
Operational Cyber Risk Management Programme. The objectives of the cyber risk policy must be delivered by an operational cyber risk management programme that defines, documents and communicates policies, processes and procedures (paras 15-16).
- Board-approved cyber risk policy
- Documented operational cyber risk management programme (policies, processes, procedures)
- Evidence of communication of the programme across the organisation
- No documented programme delivering the policy
- Policy not approved or communicated
- Programme not maintained/reviewed
Chief Information Security Officer (CISO). A CISO with the necessary experience and competencies must be appointed to deliver the operational cyber risk management programme (paras 17-18).
- CISO appointment record, job description and reporting line
- Evidence of CISO competencies/experience
- CISO reports to the board/senior management on cyber risk
- No CISO appointed or role unfilled
- CISO lacks authority/independence
- CISO not reporting to the board
Three Lines of Defence. Cyber risk governance should follow a three lines of defence model (operational management; risk and compliance oversight; internal audit) (para 19).
- Documented three-lines-of-defence model for cyber risk
- Defined responsibilities for each line
- Independence of the third line (IT audit)
- Lines of defence not defined or overlapping
- No independent third line
- Risk oversight conflated with operations
Risk Assessment Process. The programme must include a risk assessment process; assessments must be documented and retained for at least five years, and the control environment continuously monitored and evaluated (paras 20-22).
- Documented cyber risk assessment methodology and results
- Evidence assessments are retained for at least five years
- Continuous monitoring and evaluation of the control environment
- Risk assessments not documented or retained 5 years
- Control environment not continuously monitored
- Assessment not updated when risk changes
IT Audit Plan. The third line of defence, IT audit, should provide the audit committee of the board (or equivalent) with independent assurance over the cyber risk programme through a risk-based IT audit plan (para 23).
- Risk-based IT audit plan covering cyber risk
- IT audit reports to the audit committee
- Tracking of audit findings to remediation
- No IT audit coverage of cyber risk
- Audit not independent of operations
- Findings not remediated
Third-Party, Outsourcing and Cloud Risk. Outsourced functions must be governed by service agreements with compliance terms; cloud services must be risk-assessed; end-user-developed systems and critical new projects must be assessed (paras 26-32).
- Inventory of outsourced/third-party and cloud services
- Service agreements with security and compliance terms
- Cloud and end-user-computing risk assessments
- Technology risk assessment for critical new projects
- Third-party/cloud services not risk-assessed
- Service agreements lacking security terms
- End-user-developed or critical-project systems unassessed
BMA Code Section VI: Detect and Protect Controls
Threat Intelligence and Vulnerability Alerting. RLEs should use threat intelligence and vulnerability alerting services to obtain information about new cyber threats and vulnerabilities to inform protective measures (para 34).
- Subscription to threat intelligence / vulnerability alerting sources
- Process for actioning threat and vulnerability information
- Records of protective measures taken in response
- No threat-intelligence input to defence
- Vulnerability alerts not actioned
- Threat information not integrated into risk decisions
IT Incident Management. An incident management process must be in place to restore normal IT service following an unexpected disruption, with minimal impact to business operations (para 35).
- Documented IT incident management process
- Incident tickets with timelines and resolution
- Service-restoration objectives
- No formal incident management process
- Incidents not logged or timed
- No restoration objectives
IT Security Incident Management. A formal IT security incident response process must be established, with consideration of a computer security incident response team, post-incident root-cause review, defined crisis escalation, and annual tabletop exercises (paras 36-40).
- Documented security incident response process and CSIRT arrangements
- Post-incident review reports with root cause and remedial actions
- Crisis escalation criteria and communications plan
- Annual tabletop exercise records
- No formal security incident response process
- Post-incident reviews not performed
- No tabletop exercises
- Crisis escalation undefined
Notification of Cyber Reporting Events to the Authority. RLEs must report cyber reporting events that result in significant adverse impact to the BMA, consult the Authority when in doubt, and maintain logs of all cybersecurity incidents with timelines (paras 41-44).
- Procedure for assessing and reporting cyber reporting events to the BMA
- Records of notifications made to the Authority within required timeframes
- Log of all cybersecurity incidents with timelines
- Reportable events not notified to the BMA
- No criteria for significant adverse impact
- Incident logs not maintained
Access Management and Segregation of Duties. Procedures must manage the allocation of access rights to information systems, and roles and areas of responsibility should be segregated to minimise the risk of unauthorised or unintentional modification or misuse (paras 45-46).
- Access provisioning/de-provisioning procedures and approvals
- Periodic access reviews
- Segregation-of-duties matrix and conflict monitoring
- Access rights not reviewed
- No segregation of duties
- Privileged access uncontrolled
Staff Cyber Risk Awareness Training. Staff cyber risk awareness training must be completed at least annually, with additional training for staff in roles responsible for cyber risk (para 47).
- Annual security awareness training programme and completion records
- Role-specific training for cyber-risk personnel
- Phishing/awareness assessment results
- Annual training not completed by all staff
- No role-specific training
- Effectiveness not measured
Data Classification and Security. Information must be classified and protected commensurate with its sensitivity, and data classified as non-public must be protected by an appropriate level of security (paras 48, 52, 54).
- Data classification scheme and labelling
- Protective controls mapped to classification levels
- Inventory of non-public data and its protections
- No data classification scheme
- Non-public data not adequately protected
- Classification not applied consistently
Data Protection, Governance and Loss Prevention. RLEs must have Data Loss Prevention controls for primary business data, assess compliance with applicable data protection/privacy laws, and document data governance controls (paras 49-51).
- DLP controls and monitoring for primary business data
- Data protection/privacy compliance assessment per jurisdiction
- Documented data governance controls
- No DLP controls
- Data-protection compliance not assessed
- Data governance undocumented
Malicious Code Controls. Controls to detect and block malicious code (or suitable mitigating controls) must be deployed at both endpoint and network level, covering viruses, ransomware, spyware, worms and trojans (para 53).
- Anti-malware/EDR deployment at endpoint and network
- Malware signature/behavioural update process
- Detection and response records for malicious code
- Anti-malware not deployed at all layers
- Definitions/behaviour models not updated
- No response process for detections
Security Testing Programme. RLEs must assess their risk and determine a suitable security testing programme (for example vulnerability assessment and penetration testing) commensurate with that risk (para 56).
- Risk-based security testing programme (VA/penetration testing schedule)
- Test reports and remediation tracking
- Retesting evidence for closed findings
- No security testing programme
- Testing not risk-based
- Findings not remediated/retested
Patch Management. RLEs must have patch management procedures that define the identification, categorisation, prioritisation and timely deployment of patches (para 57).
- Patch management policy and SLAs by severity
- Patch deployment records and exceptions
- Evidence of timely remediation of critical patches
- No patch management SLAs
- Critical patches delayed
- Exceptions not tracked or risk-accepted
Data Deletion, Sanitisation and Disposal. RLEs must have documented procedures for the deletion, sanitisation and disposal of all storage media and data (para 58).
- Media sanitisation/disposal procedures and certificates
- Asset disposal records
- Verification of sanitisation before reuse/disposal
- Media not sanitised before disposal/reuse
- No disposal records
- Cryptographic erasure not verified
Network Security Management. Network security standards must be documented in a formal document, and network segregation should be applied to limit the spread of compromise (para 59).
- Documented network security standards
- Network architecture/segmentation diagrams
- Firewall and boundary control configurations and reviews
- No documented network standards
- Flat network without segmentation
- Boundary controls not reviewed
Use of Cryptography. RLEs must protect information using appropriate cryptography, including encryption of non-public data at rest and in transit, with documented key management.
- Cryptography standard and approved algorithms
- Encryption of non-public data at rest and in transit
- Key management policy and procedures
- Sensitive data not encrypted
- Weak/unapproved algorithms
- No key management
IT Services Management. IT service management processes must support stable services, covering configuration management, change management, software release management, incident and problem management, and performance and capacity management (para 33).
- Documented configuration and change management processes
- Software release and problem management records
- Capacity/performance management evidence
- Changes made without change control
- No configuration baseline
- Capacity not managed
BMA Code Section VII: Response and Recovery Controls
Business Continuity and Disaster Recovery Planning. RLEs must implement effective BCP and DR policies and procedures, including regular documented business impact analysis and BCP/DR plans tested at least annually with issues tracked to remediation (para 66).
- BCP and DR policies and plans
- Documented business impact analysis
- Annual BCP/DR test results with issues tracked to remediation
- BCP/DR plans untested
- No business impact analysis
- Test issues not remediated
BMA Code Sections III-IV: Interpretation and Proportionality
Interpretation. Section III defines how the Code is to be read, including the regulated licensed entities (RLEs) in scope and the meaning of operational cyber risk for the purposes of the Code.
- Confirmation of RLE status and which sector code applies
- Scoping document identifying systems and operations subject to the Code
- RLE status or scope misidentified
- Code obligations not mapped to the entity's operations
Proportionality Principle. Section IV requires that the operational cyber risk management framework be proportionate to the nature, scale and complexity of the RLE's business and its cyber risk profile.
- Documented proportionality assessment linking control depth to business scale and risk
- Board rationale for the chosen maturity of the programme
- Controls not scaled to risk/complexity
- No documented proportionality rationale
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.