CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Markets/Kuwait

Market pack

Kuwait

A regulator-issued cyber security framework and a separate data privacy regulation, applied across a market where central bank expectations set the pace for the private sector.

PRIMARY AUTHORITIES
CITRA, Central Bank of Kuwait
INSTRUMENTS IN THIS PACK
5 national and sector, plus 13 international standards
CONTRACTING
Served from our registered Gulf entities. A local entity will follow a client requirement.

Regulatory register

What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.

Kuwait — national and sector regulation
Authority or instrumentWhat it isWho it applies toWhat the platform does
CITRACyber Security FrameworkGovernment entities, telecom operators and organisations within CITRA scopeControl mapping, compliance position and evidence per control
CITRAData Privacy Protection RegulationTelecom and IT service providers, and organisations handling personal data within scopeProcessing records, consent handling, rights workflow, transfer and breach provisions
CITRACloud computing regulatory framework and data classification rulesCloud tenants and providersClassification-driven hosting position and provider responsibility split
Central Bank of KuwaitCyber security framework, technology risk and business continuity instructionsLicensed banks and financial institutionsControl mapping, continuity evidence, outsourcing registers and incident reporting
Capital Markets AuthorityTechnology and operational requirements for licensed personsLicensed capital markets participantsSector obligations tracked in the same regulatory register
International standards operating alongside the national regimes
StandardScopeHow it is used
ISO/IEC 27001:2022 and 27002Information security management system and control setCertification readiness, live Statement of Applicability, continuous gap position
ISO/IEC 27701Privacy information managementExtends the ISMS control set with privacy-specific controls and DPO workflow
ISO/IEC 27017 and 27018Cloud security and cloud personal dataApplied where the estate is cloud-hosted or cloud-delivered
ISO 22301Business continuity managementBIA, recovery objectives, plan currency and exercise evidence
ISO/IEC 42001:2023AI management systemAI inventory, impact assessment and model governance
NIST CSF 2.0Cybersecurity frameworkUsed as the neutral spine when several national regimes apply at once
NIST SP 800-53 Rev. 5Control catalogueDepth mapping where a client's control set is US-derived
CIS Controls v8Prioritised technical control setCommon baseline for technology teams
COBIT 2019Technology governanceUsed in the Govern pillar for IT and digital governance structures
SOC 2Service organisation controlsTrust services criteria for clients who serve enterprise customers
PCI DSS 4.0Payment card securityApplied where card data is in scope
IEC 62443Industrial automation and control systemsApplied to OT estates alongside the national OT controls
Open FAIRRisk quantification taxonomyThe quantification method used throughout the Anticipate pillar

Hosting and contracting

Settle residency before tenant design. It is the item most often left until too late.

Data residency

CITRA classification and cloud rules determine where data can sit. Confirm classification before tenant design; it is the item most often left until too late.

Contracting entity

Served from our registered Gulf entities. A local entity will follow a client requirement, not precede it.

How Falconry360 is hosted and secured

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.