Oman National Cybersecurity Framework
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Asset Management
Operate asset management + information classification per Oman National Cybersecurity Framework. Maintain inventory of information systems + networks + endpoints + applications + data with documented owners + classification + criticality + protection requirements. Apply data classification taxonomy aligned with Oman national classification scheme + sector requirements + organisational policy. Cover the asset lifecycle from procurement through commissioning + operation + change + decommissioning + secure disposal aligned with NIST SP 800-88 sanitisation guidance.
- Oman National Cybersecurity Framework alignment evidence for OMANCS-2
- framework adoption nominal not operational
BC and DR
Operate business continuity + disaster recovery + resilience per Oman framework + sectoral requirements. Apply NIST SP 800-34 methodology including Business Impact Analysis + recovery strategies + ISCP development + testing + maintenance. Implement backup + alternate site + recovery procedures with documented RTO / RPO per system aligned to mission criticality. Test annually via tabletop + biennially via technical recovery exercise. Maintain alignment with broader enterprise risk + insurance + crisis management.
- Oman National Cybersecurity Framework alignment evidence for OMANCS-7
- framework adoption nominal not operational
Data Protection + Crypto
Operate data protection + cryptography + privacy alignment per Oman framework + Oman Personal Data Protection Law (Royal Decree 6/2022 effective 13 February 2023). Implement encryption at rest + in transit + with cryptographic key management lifecycle + HSM where appropriate + FIPS 140-2 / 140-3 validated modules. Apply data minimisation + purpose limitation + retention + secure deletion per PDPL. Implement DLP + classification-based protection + cross-border transfer mechanism per PDPL Article 36 (regulator approval required for transfer + adequacy / safeguards / consent). Maintain data subject rights handling + breach notification per PDPL Article 35 (72 hour notification to MTCIT regulator + affected individuals).
- Oman National Cybersecurity Framework alignment evidence for OMANCS-4
- framework adoption nominal not operational
Governance and Risk
Establish cybersecurity governance + policy + risk management per Oman National Cybersecurity Framework administered by the Ministry of Transport + Communications and Information Technology (MTCIT) and the Oman National Computer Emergency Readiness Team (OmanCERT). Governance must (a) appoint accountable cybersecurity executives with documented decision authority + (b) maintain cybersecurity policy approved at senior level covering scope + roles + acceptable use + risk management + incident reporting + (c) align with Oman Vision 2040 cybersecurity programme + sectoral regulations (CBO for banking + TRA for telecom + CMA for capital markets + Ministry of Health) + international standards (ISO/IEC 27001 + NIST CSF). Risk management must apply NIST SP 800-30 or ISO 27005 methodology + maintain risk register + integrate with broader enterprise risk management.
- Oman National Cybersecurity Framework alignment evidence for OMANCS-1
- framework adoption nominal not operational
IAM
Implement identity and access management + authentication + privileged access per Oman framework. Apply role-based access + multi-factor authentication for privileged + remote + and administrative access + just-in-time access + session recording + credential vaulting for privileged accounts + automated joiner-mover-leaver workflow. Apply identity federation where appropriate + maintain audit logs of authentication and authorisation events.
- Oman National Cybersecurity Framework alignment evidence for OMANCS-3
- framework adoption nominal not operational
Monitoring + IR + Notification
Operate security monitoring + incident detection + response + OmanCERT notification per Oman framework + Royal Decree 12/2011 (Personal Data Protection) + sectoral incident reporting requirements. Monitoring must include SIEM + EDR + UEBA + threat intelligence + with O-RAN-aware + sector-aware detection where applicable. Incident response must align with NIST SP 800-61 methodology + maintain IR plan + tabletop exercises annually + technical drills + forensic readiness. Notification must (a) report eligible incidents to OmanCERT within sector-specific timeframes + (b) report data breaches to MTCIT regulator within 72 hours per Oman PDPL Article 35 + (c) notify affected individuals per applicable law + (d) coordinate with sectoral regulators (CBO + TRA + CMA + Ministry of Health) per their requirements.
- Oman National Cybersecurity Framework alignment evidence for OMANCS-6
- framework adoption nominal not operational
Network + Endpoint + SDLC
Operate network security + endpoint protection + secure system development + configuration management per Oman framework. Network security must include segmentation + perimeter protection + intrusion detection + DLP + zero trust architecture aligned with maturity. Endpoint protection must include EDR + application allowlisting + USB control + patching + hardening. Secure system development must apply SDLC controls including threat modeling + secure coding + SAST + DAST + dependency scanning + secrets management + SBOM. Configuration management must maintain hardened baselines per asset class + automated compliance scanning + drift detection + remediation. Vulnerability and patch management must consume Oman CERT + ICS-CERT + vendor advisories + KEV + apply risk-based remediation + compensating controls.
- Oman National Cybersecurity Framework alignment evidence for OMANCS-5
- framework adoption nominal not operational
Third-Party + Training + Physical + Audit
Operate third-party + supply chain risk + awareness training + physical security + compliance audit per Oman framework. Third-party risk must apply NIST SP 800-161 SCRM tailored to Oman context including vendor qualification + contract requirements + ongoing monitoring + with attention to nationality + sanction screening + geopolitical risk. Awareness and training must cover all personnel with role-specific content + annual refresher + phishing simulation + Arabic language localisation. Physical and environmental security must protect data centres + offices + remote work locations + with appropriate access control + monitoring + environmental controls. Compliance + audit + reporting must align with MTCIT + sectoral regulator requirements + internal audit + external assurance + with documented findings + remediation tracking through closure.
- Oman National Cybersecurity Framework alignment evidence for OMANCS-8
- framework adoption nominal not operational
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Oman National Cybersecurity Framework framework page.