Artefacts

We aim to deliver sectorwide operational resilience improvements to benefit the safety and security of customers through trusted and effective collaboration

Welcome to the CMORG Artefact library

This brings together all CMORG outputs that are accessible to industry participants. You can register to access all of these here, but to receive a response, you must provide an industry email address and be a direct industry participant.

Filter by:

Resilience
Guidance for Firm Operational Resilience
Following on from the development of the original guidance produced in 2021, this document provides an update to firms on the guidance to implementing operational resilience.
Technology and cyber
Guidance for Post-Quantum Cryptography
This artefact emphasises the urgency of managing quantum risk and aligns with the UK National Cyber Security Centre’s (NCSC) guidance for the financial sector which is transitioning towards quantum-safe cryptographic practice.
Third Party
Third Party Information Security - Supplier Risk Assurance Framework
The Supplier Risk Assurance Framework was designed to develop a third-party assurance scale as a practical tool to help firms assess the cyber security risk of their third parties and ensure appropriate levels of risk-based control.
Third Party
Third Party Exit Plan Template
This artefact was formulated to establish a standardised template and associated guidance for exit strategies concerning material and high-impact suppliers as part of an organisation’s Third Party Risk Management framework and associated Business Continuity and Disaster Recovery measures.
Resilience
Dynamic Scenario Library (DSL)
The DSL is designed to be a shared resource which contains a catalogue of categorised and individually described scenarios, constructed using a common design methodology.
Technology and cyber
Security in the Cloud
This artefact was developed to promote good practice guidance on how to plan and implement security in the Cloud to optimise the approach undertaken by CMORG firms and support capability building across the wider sector.
Third Party
Third Party Lifecycle Management Guidance
Developed to provide industry expertise on managing resilience risks through the lifecycle of a third-party engagement, optimising the approaches undertaken by larger firms and supporting capability building across the wider sector.
Third Party
Collaborative Scenario Testing of Critical Third Parties
A common approach to scenario testing of critical third parties to address the challenge common providers have of multiple assurance engagements with diverse financial institutions.
Resilience
Sector Principles for Service Substitution
The principles in this artefact relate to the substitution of a business service.