Skip to content

Evidence request lists

Kuwait National Cybersecurity Framework

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Detect + Monitoring + SIEM + SOC + Threat Intel

KNCF-Detect-Monitoring-SIEM-SOC-Threat-Intel-CTI-MITRE-ATT-CK-EDR-XDR-MDR-24-7-Continuous
Kuwait NCF Detect + Monitoring + SIEM + SOC + Threat Intel + EDR + XDR + 24/7

Kuwait NCF Detect function. Security Monitoring and Logging: comprehensive logging (Identity + Network + Endpoint + Cloud + Application + Database + Privileged Access + Network Devices + Cloud Trail + Container + IoT/OT) + centralised log management + Security Information and Event Management (SIEM) + log retention minimum 1 year (longer for CNI + KDPPR) + tamper-evident storage + log integrity + Kuwait NCSC log aggregation requirements + correlation rules + use cases + UEBA (User and Entity Behavior Analytics). Security Operations Centre (SOC): 24/7/365 monitoring (mandatory for CNI sectors) + Tier 1/2/3 analyst structure + playbooks + runbooks + escalation procedures + SOAR (Security Orchestration Automation and Response) + EDR (Endpoint Detection and Response) + XDR (Extended) + MDR (Managed Detection and Response) + NDR (Network) + Cloud Detection and Response (CDR) + Threat Hunting

Artefacts an auditor will ask for
  • SIEM deployment + use cases
  • SOC 24/7 evidence
  • EDR/XDR deployment
  • Threat intelligence feeds + MITRE ATT and CK mapping
  • SOAR playbooks
  • NCSC threat intel sharing records
  • Log retention 1 year minimum
Where this commonly fails
  • No 24/7 SOC
  • Insufficient log coverage
  • No EDR/XDR
  • No threat intelligence programme
  • No MITRE ATT and CK mapping
  • No threat hunting

Govern + Strategy + Policy + Compliance Assurance

KNCF-Govern-Strategy-Policy-NCSC-NIST-CSF-2-0-ISO-27001-Council-of-Ministers-Compliance-Assurance
Kuwait NCF Govern + Strategy + Policy + NCSC + NIST CSF 2.0 + ISO 27001 + Compliance Assurance

Kuwait National Cybersecurity Framework (NCF) Govern function. Issued and maintained by Kuwait National Cybersecurity Centre (NCSC) under Council of Ministers Resolution. Aligned with NIST Cybersecurity Framework 2.0 (Govern + Identify + Protect + Detect + Respond + Recover) + ISO/IEC 27001 ISMS + GCC Cybersecurity convergence + Kuwait Vision 2035. Govern function establishes: National Cybersecurity Strategy (approved by Cabinet) + cybersecurity policy hierarchy (national + sector + organisational) + roles + responsibilities (Cybersecurity Steering Committee + CISO designation + Board-level cybersecurity ownership + DPO coordination per KDPPR) + risk appetite + risk tolerance statements + cybersecurity programme charter + budget allocation + reporting cadence + Board oversight + executive sponsorship + governance forums. Compliance Assurance: regular independent assessment + audit (inter

Artefacts an auditor will ask for
  • National Cybersecurity Strategy
  • Cybersecurity policy hierarchy
  • CISO designation
  • Board cybersecurity charter
  • Annual compliance attestation
  • NIST CSF 2.0 tier alignment
  • Independent audit reports
Where this commonly fails
  • No formal cybersecurity strategy
  • CISO not at executive level
  • No Board reporting
  • Missing NCSC compliance attestation
  • No maturity assessment

Identify + Asset + Risk

KNCF-Identify-Asset-Risk-Management-CMDB-Classification-Crown-Jewels-CNI-NCSC-Sector-Designation
Kuwait NCF Identify + Asset Management + Risk + CNI + Crown Jewels

Kuwait NCF Identify function. Asset Identification and Classification: comprehensive Configuration Management Database (CMDB) covering hardware + software + data + cloud assets + IoT + OT/ICS + virtual + container + identity + business processes + suppliers. Asset classification by criticality (Crown Jewels + business-critical + standard + low risk) + sensitivity (Top Secret + Secret + Confidential + Internal + Public) + Kuwait NCSC Critical National Infrastructure (CNI) sectoral designation (energy + oil + gas + water + electricity + telecommunications + ICT + banking + finance + healthcare + government + transportation + defense). Risk Assessment and Treatment: ISO 27005 + NIST SP 800-30/37 + FAIR + structured taxonomy of threats (cyber + insider + supply chain + nation-state APT + ransomware + DDoS + social engineering + physical) + vulnerabilities + impact + likelihood + risk registe

Artefacts an auditor will ask for
  • CMDB covering hardware + software + data + cloud + OT
  • Asset criticality classification
  • Crown Jewels list
  • NCSC CNI sector designation
  • Risk register (ISO 27005 + NIST 800-30)
  • Threat taxonomy + risk treatment plan
Where this commonly fails
  • Incomplete CMDB
  • No Crown Jewels identification
  • Missing CNI designation
  • No documented risk methodology
  • Risks not tied to controls

Kuwait NCF: Cybersecurity Governance

KUWAIT-GOV-01
Cybersecurity Strategy and Policy

Develop organizational cybersecurity strategy aligned with Kuwait's national cybersecurity strategy. Establish comprehensive security policies.

Artefacts an auditor will ask for
  • National cybersecurity strategy alignment record
  • Organisational policy
  • Approval evidence
  • Annual review
Where this commonly fails
  • Alignment unclear
  • Policy stale
  • Review absent
KUWAIT-GOV-02
Organizational Structure and Accountability

Designate a CISO or equivalent with direct reporting to senior leadership. Establish cybersecurity committees and define accountability structures.

Artefacts an auditor will ask for
  • Organisational structure
  • Accountability statements
  • Role descriptions
  • Reporting lines
Where this commonly fails
  • Structure unclear
  • Accountability blurred
  • Reporting weak
KUWAIT-GOV-03
Risk Management Framework

Implement a risk management framework covering asset identification, threat assessment, vulnerability management, and risk treatment.

Artefacts an auditor will ask for
  • Risk management framework
  • Risk register
  • Treatment plan
  • Annual review
Where this commonly fails
  • Framework absent
  • Register stale
  • Treatment weak
KUWAIT-GOV-04
Third-Party Security Management

Assess and manage cybersecurity risks from third-party vendors and service providers. Include security requirements in contracts.

Artefacts an auditor will ask for
  • Third-party security policy
  • Vendor inventory
  • Due diligence records
  • Monitoring program
Where this commonly fails
  • Inventory incomplete
  • Due diligence weak
  • Monitoring absent

Protect + Access Control + IAM

KNCF-Protect-Access-Control-IAM-Privileged-MFA-Zero-Trust-Identity-Lifecycle-IAG-PAM
Kuwait NCF Protect + Access Control + IAM + Privileged + MFA + Zero Trust + Identity Lifecycle

Kuwait NCF Protect function (Access). Access Control and Identity Management aligned with NIST SP 800-53 AC family + ISO 27001 A.9 + Zero Trust principles. Identity Lifecycle Management: provisioning (joiner) + entitlement review (mover) + deprovisioning (leaver) + service accounts + non-human identities + machine identities. Authentication: Multi-Factor Authentication (MFA) mandatory for privileged + remote + cloud admin + Internet-facing administrative + Kuwait Bayan unified identity integration + federation via SAML/OIDC + FIDO2 passkeys for high-assurance + biometric for sensitive transactions. Authorisation: Role-Based Access Control (RBAC) + Attribute-Based Access Control (ABAC) for fine-grained + least privilege + segregation of duties + just-in-time access + break-glass procedures. Privileged Access Management (PAM): vault + session recording + privileged session monitoring + eph

Artefacts an auditor will ask for
  • IAM solution deployment
  • PAM vault + session recording
  • MFA enforcement evidence
  • Joiner/mover/leaver process records
  • Access review records (quarterly)
  • Service account inventory
  • Federation configuration (SAML/OIDC)
Where this commonly fails
  • No MFA for admin/remote
  • No PAM
  • Stale entitlements
  • No periodic access review
  • Service accounts unmanaged

Protect + Data + Encryption + Cryptography

KNCF-Protect-Data-Encryption-Classification-Cryptography-Key-Management-DLP-PKI-Quantum-Resistant
Kuwait NCF Protect + Data + Encryption + Classification + Cryptography + Key Management + DLP

Kuwait NCF Protect function (Data). Data Protection and Encryption aligned with NIST SP 800-53 SC family + ISO 27001 A.10 cryptography + A.13 communications security + KDPPR CITRA data protection coordination. Data Classification scheme (Top Secret + Secret + Confidential + Internal + Public) + Kuwait NCSC handling standards by classification + labelling + watermarking + DRM for sensitive content. Encryption: at-rest (full-disk + file + database + tokenisation + format-preserving) using AES-256 minimum + in-transit (TLS 1.3 + IPsec + MACsec) + in-use (homomorphic + confidential computing where applicable). Cryptographic standards: FIPS 140-3 modules (or equivalent) + Suite B + Commercial National Security Algorithm Suite (CNSA) + Kuwait NCSC-approved algorithms. Key Management: Hardware Security Modules (HSM) + Key Management Service (KMS) + customer-managed keys (CMK) for cloud + key ro

Artefacts an auditor will ask for
  • Encryption at-rest and in-transit configuration
  • HSM/KMS deployment
  • Cryptographic standards policy (FIPS 140-3)
  • PKI charter + cert lifecycle
  • DLP policy + deployment
  • Post-quantum migration plan
Where this commonly fails
  • Unencrypted Personal Data + Sensitive Data
  • No HSM/KMS
  • Manual key management
  • No DLP
  • No PQC readiness plan

Protect + Network + Configuration + SDLC + Physical

KNCF-Protect-Network-Configuration-Vulnerability-Physical-Secure-SDLC-Hardening-Patching-Drift
Kuwait NCF Protect + Network + Configuration + Vulnerability + Physical + Secure SDLC

Kuwait NCF Protect function (Infrastructure). Network Security and Segmentation: defense in depth + perimeter (firewall + WAF + DDoS mitigation) + internal segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection + secure remote access (VPN with MFA + SASE + Secure Web Gateway SWG + CASB) + DNS security + DNSSEC + network detection and response (NDR) + DMZ architecture + cloud network security (VPC + security groups + NACL). Secure Configuration and Vulnerability Management: configuration baselines (CIS Benchmarks + DISA STIG + vendor guidance) + golden images + Infrastructure-as-Code (IaC) + drift detection + configuration management + vulnerability scanning (network + application + container + cloud + database) + patch management SLAs by severity + emergency patch procedures + virtual patching (WAF) + zero-day response + bug bounty program

Artefacts an auditor will ask for
  • Network segmentation diagram
  • Configuration baselines (CIS/STIG)
  • Vulnerability scan reports
  • Patching SLA evidence
  • DevSecOps pipeline with SAST/DAST/SCA
  • SBOM evidence
  • Data centre security audit
Where this commonly fails
  • Flat network
  • No baselines or drift detection
  • Long patch cycles
  • No SDLC security gates
  • Missing SBOM
  • Inadequate physical security

Respond + Incident Response + Recover + BC

KNCF-Respond-Incident-Response-Reporting-Recover-Business-Continuity-Cyber-Resilience-NCSC-Notification
Kuwait NCF Respond + Incident Response + Reporting + Recover + BC + Cyber Resilience + NCSC

Kuwait NCF Respond and Recover functions. Incident Response and Reporting: documented Incident Response Plan + Computer Security Incident Response Team (CSIRT) + 24/7 incident hotline + Incident classification (severity + impact + urgency) + Triage + Containment + Eradication + Recovery (NIST SP 800-61) + Post-Incident Review and Lessons Learned + tabletop exercises (annual minimum + quarterly for CNI) + functional exercises + full-scale red team exercises + Purple Team coordination. Kuwait NCSC mandatory reporting: significant cybersecurity incidents within timeframes specified by sector (typically 24-72 hours) + CNI sector immediate notification + coordination with Kuwait CERT + Ministry of Interior + General Department for Combating Cybercrime + KDPPR CITRA breach notification for personal data + cross-sector coordination + GCC CERT escalation for transnational incidents. Business Con

Artefacts an auditor will ask for
  • IRP and CSIRT charter
  • Tabletop exercise reports (annual)
  • NCSC notification records + timing
  • BIA + BCP + DRP
  • RTO/RPO documentation
  • Immutable backup evidence
  • Crisis comms playbook
Where this commonly fails
  • No CSIRT
  • No tabletop exercises
  • Late NCSC notification
  • No tested DRP
  • Backups not immutable
  • No crisis comms plan

Supply Chain + Third Party + Awareness + Workforce

KNCF-Supply-Chain-Third-Party-Awareness-Workforce-Capability-Vendor-Risk-Cloud-OT-IoT-Training
Kuwait NCF Supply Chain + Third Party + Awareness + Workforce + Vendor Risk + Cloud + OT/IoT

Kuwait NCF cross-cutting Supply Chain + People. Third Party and Supply Chain Security: vendor risk management programme + onboarding due diligence + cybersecurity questionnaire (SIG + CAIQ + custom) + right-to-audit + SOC 2 Type II + ISO 27001 + ISMS-P + Kuwait NCSC accreditation requirements + cybersecurity clauses in contracts + Service Level Agreements (SLA) for security + Subprocessor authorisation + Cloud provider classification per CITRA Cloud First Policy + Cloud Security Alliance (CSA) CCM + AWS/Azure/GCP shared responsibility model + Software-as-a-Service (SaaS) risk assessment + open-source software (OSS) risk + Software Bill of Materials (SBOM) + Supply chain attack mitigation (SolarWinds + Kaseya + log4j precedents) + ongoing vendor monitoring + concentration risk analysis + termination + offboarding + data return + deletion. Operational Technology (OT) + Industrial Control S

Artefacts an auditor will ask for
  • Vendor risk assessment library (SIG/CAIQ)
  • Cloud provider Cloud First classification
  • SBOM for OSS
  • OT/ICS security architecture (IEC 62443)
  • Annual training records
  • Phishing simulation results
  • Certification register (CISSP + CISM + GIAC)
Where this commonly fails
  • No vendor risk programme
  • Cloud workloads unclassified
  • No SBOM
  • OT/IT not segmented
  • No phishing simulation
  • No certification programme
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Kuwait National Cybersecurity Framework framework page.