Cybersecurity Governance (ECC Domain 1)
ECC-1Definition
The first domain of the NCA Essential Cybersecurity Controls framework that establishes requirements for cybersecurity leadership, strategy, policies, and organizational structure. This domain ensures that organizations have proper governance mechanisms including board-level oversight, defined roles and responsibilities, cybersecurity policies aligned with business objectives, and adequate resources allocated to cybersecurity programs.
التعريف بالعربية
المجال الأول من إطار الضوابط الأساسية للأمن السيبراني الصادر عن الهيئة الوطنية للأمن السيبراني والذي يضع متطلبات لقيادة الأمن السيبراني والاستراتيجية والسياسات والهيكل التنظيمي. يضمن هذا المجال أن المؤسسات لديها آليات حوكمة مناسبة بما في ذلك الإشراف على مستوى مجلس الإدارة والأدوار والمسؤوليات المحددة وسياسات الأمن السيبراني المتوافقة مع أهداف العمل والموارد الكافية المخصصة لبرامج الأمن السيبراني.
Practical Example
A Saudi energy company establishes a Cybersecurity Steering Committee chaired by a C-level executive, develops a three-year cybersecurity strategy approved by the board, and allocates 8% of its IT budget to cybersecurity initiatives to comply with ECC Domain 1 requirements.