HomeFrameworksBahrain CBB OM-5.5
Central Bank of Bahrain (CBB) · Bahrain

CBB Rulebook Module OM-5.5 — Cyber Security Risk Management compliance software

CBB's binding cyber security module for every bank licensee in Bahrain — 171 controls across 17 domains, from board accountability to the Appendix C control guidelines, with the incident-reporting clocks tracked as their own indicator.

At a glance
  • RegulatorCentral Bank of Bahrain (CBB)
  • InstrumentRulebook Module OM-5.5 — effective 1 Jul 2021, amended to May 2026
  • Structure17 domains — 12 OM-5.5 headings + Appendix C's 5 NIST-style functions
  • Controls171 — 62 OM-5.5 rules, 109 Appendix C guidelines
Bahrain CBB OM-5.5Available
Overview

What Bahrain CBB OM-5.5 requires

Who it applies to

  • Conventional bank licensees under CBB Rulebook Volume 1
  • Islamic bank licensees under CBB Rulebook Volume 2
  • Group compliance functions overseeing both a conventional and an Islamic licensee
  • Risk and IT teams responsible for the CBB incident-reporting clock

Module OM-5.5, Cyber Security Risk Management, sits in Volume 1 (conventional banks) and Volume 2 (Islamic banks) of the Central Bank of Bahrain Rulebook, effective 1 July 2021 and most recently amended in May 2026. It binds every CBB-licensed bank, and the two volumes are textually near-identical — differing only in the entity noun used and, in one paragraph, the incident-report email address.

The module itself sets 62 numbered rules across twelve headings — the role of the Board and of Senior Management, strategy, policy, approach and methodology, prevention, risk identification and assessment, incident detection and management, recovery, insurance, training and reporting to CBB — and Appendix C adds 109 control guidelines organised into the five NIST-style functions: Identify, Protect, Detect, Respond, Recover. 171 controls in total across seventeen domains.

The reporting clocks are specific and unforgiving: CBB must be called within one hour of detecting a reportable incident and emailed within two hours, with a root-cause report due within ten calendar days and weekly updates until resolved. Penetration testing runs at least twice a year with the external tester rotated at least every two years, and SIEM logs must be retained at least five years. GRCLens carries every OM-5.5 rule and Appendix C guideline with its own deadline, so the reporting clock is a tracked control, not a note in a policy binder.

In the platform

How GRCLens supports Bahrain CBB OM-5.5

Bahrain CBB OM-5.5 runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

The reporting clock as an indicator

The one-hour call, two-hour email, ten-day root-cause report and weekly updates to CBB are tracked as their own readiness indicator — the duties that fail in public first.

Board and Senior Management duties, separated

OM-5.5's own headings for the Board and for Senior Management stay separate controls, matching how CBB actually assigns accountability rather than folding them into one governance bucket.

Appendix C mapped to NIST CSF

The 109 Appendix C guidelines carry the NIST CSF category codes CBB's own text implies but does not print, so evidence lines up with a NIST-aligned security programme already in place.

Conventional and Islamic, one model

A group with both a Volume 1 and a Volume 2 licensee runs both from the same control model, with the entity-noun and reporting-email differences carried per row.

Questions

Bahrain CBB OM-5.5 frequently asked questions

How quickly must a cyber incident be reported to CBB?

OM-5.5.57 requires a phone call to CBB within one hour of detection and an email to the relevant section within two hours; OM-5.5.58 then requires a root-cause report within ten calendar days, with weekly updates until the incident is resolved.

Do Islamic banks follow different rules from conventional banks?

The substance is the same — Volume 1 and Volume 2 differ only in the entity noun used and, in OM-5.5.57, the incident-report email address. GRCLens carries both, citing the volume on every control.

What does Appendix C add beyond the OM-5.5 rules?

109 control guidelines organised into the five functions of the NIST Cybersecurity Framework — Identify, Protect, Detect, Respond, Recover — which CBB's own text says the module aligns to.

Talk to us about Bahrain CBB OM-5.5

Security Solution Consultants provides Bahrain banking cyber security advisory alongside the platform, so you can combine tooling with hands-on expertise.