CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Markets/Bahrain

Market pack

Bahrain

A cloud-first public sector, a detailed central bank rulebook, and one of the region's earliest personal data protection laws. Compact market, high regulatory density.

PRIMARY AUTHORITIES
National Cyber Security Centre, CBB, PDPA
INSTRUMENTS IN THIS PACK
4 national and sector, plus 13 international standards
CONTRACTING
Served from our registered Gulf entities. A local entity will follow a client requirement.

Regulatory register

What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.

Bahrain — national and sector regulation
Authority or instrumentWhat it isWho it applies toWhat the platform does
National Cyber Security CentreNational cyber security strategy, standards and directivesGovernment entities and designated critical sectorsControl mapping, maturity position and evidence maintained against the national control set
Central Bank of BahrainCBB Rulebook — operational risk, cyber security, business continuity and outsourcing modulesLicensed banks, insurers, investment firms and payment providersRulebook obligations mapped to the unified control set, with outsourcing and continuity registers and incident reporting workflow
Law No. 30 of 2018Personal Data Protection LawControllers and processors in the KingdomProcessing records, notification and permit tracking, rights handling, transfer assessment, breach workflow
Information and eGovernment AuthorityGovernment information security and cloud standardsPublic sector entities and their suppliersStandards mapped alongside the national control set
International standards operating alongside the national regimes
StandardScopeHow it is used
ISO/IEC 27001:2022 and 27002Information security management system and control setCertification readiness, live Statement of Applicability, continuous gap position
ISO/IEC 27701Privacy information managementExtends the ISMS control set with privacy-specific controls and DPO workflow
ISO/IEC 27017 and 27018Cloud security and cloud personal dataApplied where the estate is cloud-hosted or cloud-delivered
ISO 22301Business continuity managementBIA, recovery objectives, plan currency and exercise evidence
ISO/IEC 42001:2023AI management systemAI inventory, impact assessment and model governance
NIST CSF 2.0Cybersecurity frameworkUsed as the neutral spine when several national regimes apply at once
NIST SP 800-53 Rev. 5Control catalogueDepth mapping where a client's control set is US-derived
CIS Controls v8Prioritised technical control setCommon baseline for technology teams
COBIT 2019Technology governanceUsed in the Govern pillar for IT and digital governance structures
SOC 2Service organisation controlsTrust services criteria for clients who serve enterprise customers
PCI DSS 4.0Payment card securityApplied where card data is in scope
IEC 62443Industrial automation and control systemsApplied to OT estates alongside the national OT controls
Open FAIRRisk quantification taxonomyThe quantification method used throughout the Anticipate pillar

Hosting and contracting

Settle residency before tenant design. It is the item most often left until too late.

Data residency

The national cloud-first position makes regional hosting workable for most workloads. CBB-licensed firms should test the position against the outsourcing module before tenant design.

Contracting entity

Served from our registered Gulf entities. A local entity will follow a client requirement, not precede it.

How Falconry360 is hosted and secured

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.