Information systems security maturity · COBAC IS security regulation
Your IS security assessed against COBAC requirements, turned into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
Information systems security maturity · COBAC IS security regulation
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One COBAC Regulation on information systems security for regulated institutions (Commission Bancaire de l’Afrique Centrale, CEMAC) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism, a level, the level above, and the action linking the two, is what turns a finding into a trajectory.
Are access rights to sensitive applications subject to periodic review?
- N1
No organised review. Rights are granted on joining and rarely revoked following internal moves or departures.
- N2
Reviews happen occasionally, prompted by a control mission or an incident. Scope and method vary.
- N3
A review is scheduled at a fixed interval for sensitive applications. Business owners validate their teams’ rights and gaps are corrected.
- N4
The review covers all applications, including privileged accounts and provider accounts. Results are logged and shared with permanent control.
- N5
Recurring gaps feed into the revision of access profiles and procedures, with documented tracking of revisions and indicators presented to the governing body.
Action to move from L2 to L3
Set a half-yearly review schedule covering the list of sensitive applications, appoint a business validator for each one, and put the gap readout on the agenda of the next internal control committee.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon COBAC.
What this framework covers
The COBAC regulation on information systems security requires regulated institutions in the CEMAC zone to operate a formalised IT risk control framework. It covers IS governance and the accountability of the governing body, security policy, asset and data classification, access and privilege management, infrastructure and application security, business continuity and disaster recovery, incident management and notification to the Banking Commission, and oversight of IT service providers. Periodic control and reporting to the supervisor complete the framework.
In practice, the requirement is easier to state than to run. Institutions in the sub-region often combine a legacy core banking system, outsourced card payment processing, recently launched digital banking channels and branches with uneven connectivity. Three questions come up time and again. Is the security policy genuinely applied across subsidiaries and branches, or only approved at head office? Are access rights reviewed on a fixed schedule, including provider accounts and privileged accounts? Has the continuity plan been tested against a real scenario, with a record usable by periodic control?
Two confusions are worth clearing up. The first is to equate compliance with the regulation to having an IT budget and a firewall in place: the text is about a control framework, meaning roles, procedures, evidence and reviews, not an inventory of equipment. The second is to treat IS security as a purely technical matter, when the regulation engages the governing body and connects with the internal control, operational risk and outsourcing frameworks already required by COBAC. The IT risk map needs to sit within the institution’s broader risk map.
A compliance audit ends with a binary verdict: the requirement is met or it is not. A maturity assessment answers a different question. It places each practice on a progressive scale, from ad hoc action to a governed and reviewed framework, and identifies the precise action that moves it up a level. This is the view a senior management team needs when arbitrating between several workstreams within a single year and justifying its priorities to the audit committee.
The framework is ready to use in Datamensio and remains fully adaptable. The AI adjusts themes, questions and levels to your profile, whether commercial bank, microfinance institution or payment institution, or builds a tailored version from your security policy and control reports. Gaps identified feed directly into a prioritised roadmap that can be consolidated across several entities of the group.
Reference standard: COBAC Regulation on information systems security for regulated institutions (Commission Bancaire de l’Afrique Centrale, CEMAC)
The themes assessed
Information system governance
Involvement of the governing and executive bodies, approved IS strategy, dedicated committee, roles and responsibilities, appointment and positioning of the security officer, resources allocated.
Security policy and documentation set
Formalised and approved security policy, implementation procedures, scope covered, distribution to entities and subsidiaries, review cycle.
Asset and IT risk mapping
Inventory of assets and applications, data classification, vulnerability identification, risk assessment, links with the operational risk map.
Identity and access management
Granting and revoking rights, segregation of duties, privileged accounts, provider accounts, authentication, periodic access review and traceability.
Infrastructure and application security
Network and endpoint security, segmentation, encryption, patch management, security of digital banking and card payment channels, penetration testing.
Operations and change management
Operating procedures, release management, separate test environments, verified backups and restores, logging and monitoring.
Business continuity and disaster recovery
Business continuity plan and IT disaster recovery plan, backup site, recovery objectives, tested scenarios, exercise reports, updates following tests.
Security incident management
Detection and classification, incident register, resolution timeframes, notification to the Banking Commission, root cause analysis, lessons learned.
IT service providers and outsourcing
Contractual security and audit clauses, reversibility, service levels, oversight of managed service and card payment providers, data location and access.
Control, reporting and continuous improvement
IS coverage by permanent and periodic control, indicators tracked, reporting to the governing body and the supervisor, follow-up on recommendations, staff awareness.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Does the COBAC IS security regulation lead to a certification?
No. It is a prudential regulation whose compliance is checked by the Commission Bancaire de l’Afrique Centrale, through reporting and inspection missions. Datamensio measures the maturity of your framework and prepares you for these milestones, it does not issue any certificate.
What is the difference between this assessment and a compliance audit?
An audit concludes requirement by requirement, met or not met. The assessment places each practice on a maturity scale and identifies the action that moves it up a level. The two complement each other: the assessment prepares for the mission and prioritises workstreams, the audit validates.
How long does the assessment take?
The short version can be completed in a single working session. The full version, run collaboratively with IT, the security officer and internal control, typically spans one to two weeks, most of the time being spent gathering evidence from teams.
Can the framework be adapted for a microfinance or payment institution?
Yes. Themes, questions and levels can be changed, and the AI produces a version tailored to your size and activity profile based on your internal documents. You remain the owner of your framework.
How do you handle several subsidiaries across different countries in the zone?
Each entity runs its assessment against the same framework. Scores can be compared by business unit and over time, and a cross-entity roadmap consolidates shared actions without duplicating them entity by entity.
Do you need technical expertise to answer?
The questions focus on the control framework, not on configurations. An internal control officer can answer a large share of the framework. Collaborative mode allows technical questions to be assigned to the right contact.
How does this assessment connect with internal control and operational risk?
The requirements overlap significantly: risk mapping, control framework, incident management, oversight of service providers. Assessments run on these frameworks come together in a single roadmap, avoiding the same action being addressed twice.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.



