Kuwait National Cybersecurity Framework
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Detect + Monitoring + SIEM + SOC + Threat Intel
Kuwait NCF Detect function. Security Monitoring and Logging: comprehensive logging (Identity + Network + Endpoint + Cloud + Application + Database + Privileged Access + Network Devices + Cloud Trail + Container + IoT/OT) + centralised log management + Security Information and Event Management (SIEM) + log retention minimum 1 year (longer for CNI + KDPPR) + tamper-evident storage + log integrity + Kuwait NCSC log aggregation requirements + correlation rules + use cases + UEBA (User and Entity Behavior Analytics). Security Operations Centre (SOC): 24/7/365 monitoring (mandatory for CNI sectors) + Tier 1/2/3 analyst structure + playbooks + runbooks + escalation procedures + SOAR (Security Orchestration Automation and Response) + EDR (Endpoint Detection and Response) + XDR (Extended) + MDR (Managed Detection and Response) + NDR (Network) + Cloud Detection and Response (CDR) + Threat Hunting
- SIEM deployment + use cases
- SOC 24/7 evidence
- EDR/XDR deployment
- Threat intelligence feeds + MITRE ATT and CK mapping
- SOAR playbooks
- NCSC threat intel sharing records
- Log retention 1 year minimum
- No 24/7 SOC
- Insufficient log coverage
- No EDR/XDR
- No threat intelligence programme
- No MITRE ATT and CK mapping
- No threat hunting
Govern + Strategy + Policy + Compliance Assurance
Kuwait National Cybersecurity Framework (NCF) Govern function. Issued and maintained by Kuwait National Cybersecurity Centre (NCSC) under Council of Ministers Resolution. Aligned with NIST Cybersecurity Framework 2.0 (Govern + Identify + Protect + Detect + Respond + Recover) + ISO/IEC 27001 ISMS + GCC Cybersecurity convergence + Kuwait Vision 2035. Govern function establishes: National Cybersecurity Strategy (approved by Cabinet) + cybersecurity policy hierarchy (national + sector + organisational) + roles + responsibilities (Cybersecurity Steering Committee + CISO designation + Board-level cybersecurity ownership + DPO coordination per KDPPR) + risk appetite + risk tolerance statements + cybersecurity programme charter + budget allocation + reporting cadence + Board oversight + executive sponsorship + governance forums. Compliance Assurance: regular independent assessment + audit (inter
- National Cybersecurity Strategy
- Cybersecurity policy hierarchy
- CISO designation
- Board cybersecurity charter
- Annual compliance attestation
- NIST CSF 2.0 tier alignment
- Independent audit reports
- No formal cybersecurity strategy
- CISO not at executive level
- No Board reporting
- Missing NCSC compliance attestation
- No maturity assessment
Identify + Asset + Risk
Kuwait NCF Identify function. Asset Identification and Classification: comprehensive Configuration Management Database (CMDB) covering hardware + software + data + cloud assets + IoT + OT/ICS + virtual + container + identity + business processes + suppliers. Asset classification by criticality (Crown Jewels + business-critical + standard + low risk) + sensitivity (Top Secret + Secret + Confidential + Internal + Public) + Kuwait NCSC Critical National Infrastructure (CNI) sectoral designation (energy + oil + gas + water + electricity + telecommunications + ICT + banking + finance + healthcare + government + transportation + defense). Risk Assessment and Treatment: ISO 27005 + NIST SP 800-30/37 + FAIR + structured taxonomy of threats (cyber + insider + supply chain + nation-state APT + ransomware + DDoS + social engineering + physical) + vulnerabilities + impact + likelihood + risk registe
- CMDB covering hardware + software + data + cloud + OT
- Asset criticality classification
- Crown Jewels list
- NCSC CNI sector designation
- Risk register (ISO 27005 + NIST 800-30)
- Threat taxonomy + risk treatment plan
- Incomplete CMDB
- No Crown Jewels identification
- Missing CNI designation
- No documented risk methodology
- Risks not tied to controls
Kuwait NCF: Cybersecurity Governance
Develop organizational cybersecurity strategy aligned with Kuwait's national cybersecurity strategy. Establish comprehensive security policies.
- National cybersecurity strategy alignment record
- Organisational policy
- Approval evidence
- Annual review
- Alignment unclear
- Policy stale
- Review absent
Designate a CISO or equivalent with direct reporting to senior leadership. Establish cybersecurity committees and define accountability structures.
- Organisational structure
- Accountability statements
- Role descriptions
- Reporting lines
- Structure unclear
- Accountability blurred
- Reporting weak
Implement a risk management framework covering asset identification, threat assessment, vulnerability management, and risk treatment.
- Risk management framework
- Risk register
- Treatment plan
- Annual review
- Framework absent
- Register stale
- Treatment weak
Assess and manage cybersecurity risks from third-party vendors and service providers. Include security requirements in contracts.
- Third-party security policy
- Vendor inventory
- Due diligence records
- Monitoring program
- Inventory incomplete
- Due diligence weak
- Monitoring absent
Protect + Access Control + IAM
Kuwait NCF Protect function (Access). Access Control and Identity Management aligned with NIST SP 800-53 AC family + ISO 27001 A.9 + Zero Trust principles. Identity Lifecycle Management: provisioning (joiner) + entitlement review (mover) + deprovisioning (leaver) + service accounts + non-human identities + machine identities. Authentication: Multi-Factor Authentication (MFA) mandatory for privileged + remote + cloud admin + Internet-facing administrative + Kuwait Bayan unified identity integration + federation via SAML/OIDC + FIDO2 passkeys for high-assurance + biometric for sensitive transactions. Authorisation: Role-Based Access Control (RBAC) + Attribute-Based Access Control (ABAC) for fine-grained + least privilege + segregation of duties + just-in-time access + break-glass procedures. Privileged Access Management (PAM): vault + session recording + privileged session monitoring + eph
- IAM solution deployment
- PAM vault + session recording
- MFA enforcement evidence
- Joiner/mover/leaver process records
- Access review records (quarterly)
- Service account inventory
- Federation configuration (SAML/OIDC)
- No MFA for admin/remote
- No PAM
- Stale entitlements
- No periodic access review
- Service accounts unmanaged
Protect + Data + Encryption + Cryptography
Kuwait NCF Protect function (Data). Data Protection and Encryption aligned with NIST SP 800-53 SC family + ISO 27001 A.10 cryptography + A.13 communications security + KDPPR CITRA data protection coordination. Data Classification scheme (Top Secret + Secret + Confidential + Internal + Public) + Kuwait NCSC handling standards by classification + labelling + watermarking + DRM for sensitive content. Encryption: at-rest (full-disk + file + database + tokenisation + format-preserving) using AES-256 minimum + in-transit (TLS 1.3 + IPsec + MACsec) + in-use (homomorphic + confidential computing where applicable). Cryptographic standards: FIPS 140-3 modules (or equivalent) + Suite B + Commercial National Security Algorithm Suite (CNSA) + Kuwait NCSC-approved algorithms. Key Management: Hardware Security Modules (HSM) + Key Management Service (KMS) + customer-managed keys (CMK) for cloud + key ro
- Encryption at-rest and in-transit configuration
- HSM/KMS deployment
- Cryptographic standards policy (FIPS 140-3)
- PKI charter + cert lifecycle
- DLP policy + deployment
- Post-quantum migration plan
- Unencrypted Personal Data + Sensitive Data
- No HSM/KMS
- Manual key management
- No DLP
- No PQC readiness plan
Protect + Network + Configuration + SDLC + Physical
Kuwait NCF Protect function (Infrastructure). Network Security and Segmentation: defense in depth + perimeter (firewall + WAF + DDoS mitigation) + internal segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection + secure remote access (VPN with MFA + SASE + Secure Web Gateway SWG + CASB) + DNS security + DNSSEC + network detection and response (NDR) + DMZ architecture + cloud network security (VPC + security groups + NACL). Secure Configuration and Vulnerability Management: configuration baselines (CIS Benchmarks + DISA STIG + vendor guidance) + golden images + Infrastructure-as-Code (IaC) + drift detection + configuration management + vulnerability scanning (network + application + container + cloud + database) + patch management SLAs by severity + emergency patch procedures + virtual patching (WAF) + zero-day response + bug bounty program
- Network segmentation diagram
- Configuration baselines (CIS/STIG)
- Vulnerability scan reports
- Patching SLA evidence
- DevSecOps pipeline with SAST/DAST/SCA
- SBOM evidence
- Data centre security audit
- Flat network
- No baselines or drift detection
- Long patch cycles
- No SDLC security gates
- Missing SBOM
- Inadequate physical security
Respond + Incident Response + Recover + BC
Kuwait NCF Respond and Recover functions. Incident Response and Reporting: documented Incident Response Plan + Computer Security Incident Response Team (CSIRT) + 24/7 incident hotline + Incident classification (severity + impact + urgency) + Triage + Containment + Eradication + Recovery (NIST SP 800-61) + Post-Incident Review and Lessons Learned + tabletop exercises (annual minimum + quarterly for CNI) + functional exercises + full-scale red team exercises + Purple Team coordination. Kuwait NCSC mandatory reporting: significant cybersecurity incidents within timeframes specified by sector (typically 24-72 hours) + CNI sector immediate notification + coordination with Kuwait CERT + Ministry of Interior + General Department for Combating Cybercrime + KDPPR CITRA breach notification for personal data + cross-sector coordination + GCC CERT escalation for transnational incidents. Business Con
- IRP and CSIRT charter
- Tabletop exercise reports (annual)
- NCSC notification records + timing
- BIA + BCP + DRP
- RTO/RPO documentation
- Immutable backup evidence
- Crisis comms playbook
- No CSIRT
- No tabletop exercises
- Late NCSC notification
- No tested DRP
- Backups not immutable
- No crisis comms plan
Supply Chain + Third Party + Awareness + Workforce
Kuwait NCF cross-cutting Supply Chain + People. Third Party and Supply Chain Security: vendor risk management programme + onboarding due diligence + cybersecurity questionnaire (SIG + CAIQ + custom) + right-to-audit + SOC 2 Type II + ISO 27001 + ISMS-P + Kuwait NCSC accreditation requirements + cybersecurity clauses in contracts + Service Level Agreements (SLA) for security + Subprocessor authorisation + Cloud provider classification per CITRA Cloud First Policy + Cloud Security Alliance (CSA) CCM + AWS/Azure/GCP shared responsibility model + Software-as-a-Service (SaaS) risk assessment + open-source software (OSS) risk + Software Bill of Materials (SBOM) + Supply chain attack mitigation (SolarWinds + Kaseya + log4j precedents) + ongoing vendor monitoring + concentration risk analysis + termination + offboarding + data return + deletion. Operational Technology (OT) + Industrial Control S
- Vendor risk assessment library (SIG/CAIQ)
- Cloud provider Cloud First classification
- SBOM for OSS
- OT/ICS security architecture (IEC 62443)
- Annual training records
- Phishing simulation results
- Certification register (CISSP + CISM + GIAC)
- No vendor risk programme
- Cloud workloads unclassified
- No SBOM
- OT/IT not segmented
- No phishing simulation
- No certification programme
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Kuwait National Cybersecurity Framework framework page.