SAMA Framework: Core Pillars and Current Expectations
The Saudi Central Bank's Cyber Security Framework (SAMA CSF) establishes binding requirements for all licensed financial institutions, payment service providers, and critical market infrastructure operators. Unlike aspirational guidance, the framework creates enforceable obligations across five primary domains: governance and risk management, asset management, access control, detection and response, and business continuity.
As of 2024–2025, SAMA expects institutions to align with international standards including ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0, while respecting the Saudi Personal Data Protection Law (PDPL) and its implementing regulations. Compliance is not optional; regulatory examinations now routinely assess evidence of control implementation, not merely the existence of policies.
Governance and Risk Management: Documentation Is Proof
SAMA requires a documented cybersecurity strategy approved by the board or equivalent governing body. This must include:
- A formal risk assessment covering all critical systems, data, and third-party dependencies, updated at least annually and after material changes.
- A risk appetite statement that defines acceptable risk levels for data confidentiality, integrity, and availability.
- A cybersecurity roadmap with measurable milestones, resource allocation, and accountability assignments.
- Board-level reporting on cybersecurity metrics, incidents, and remediation status—at least quarterly.
Evidence to maintain: Board minutes, risk register snapshots with dates, signed risk assessments, and cybersecurity committee meeting records. SAMA examiners will request these during on-site reviews and expect version control and approval trails.
Technical Controls and Continuous Monitoring
SAMA mandates implementation of controls aligned with the NCA Essential Cybersecurity Controls (ECC) and ISO 27001:2022 Annex A. Key areas include:
- Access Control: Multi-factor authentication (MFA) for all administrative accounts, role-based access control (RBAC), and quarterly access reviews with documented approval.
- Encryption: Data in transit (TLS 1.2 or higher) and at rest for sensitive information, with key management policies and audit logs.
- Logging and Monitoring: Centralized security information and event management (SIEM) with retention periods of at least one year; real-time alerting for anomalies.
- Vulnerability Management: Quarterly scans, annual penetration testing by independent third parties, and documented remediation timelines.
Evidence to maintain: Configuration baselines, SIEM dashboards with sample alerts, penetration test reports with remediation sign-offs, MFA enrollment rosters, and encryption inventory spreadsheets. SAMA will ask to see live system configurations and sample logs during examinations.
Incident Response and Business Continuity
SAMA requires a tested incident response plan that includes detection, containment, eradication, and recovery procedures. The plan must define:
- Incident classification criteria and escalation thresholds.
- Internal and external notification workflows, including SAMA notification timelines (typically within 24 hours for material incidents).
- Forensic preservation and investigation procedures.
- Annual tabletop exercises or simulations with documented outcomes and lessons learned.
Business continuity and disaster recovery plans must be tested at least annually, with recovery time objectives (RTOs) and recovery point objectives (RPOs) aligned to regulatory expectations.
Evidence to maintain: Signed incident response procedures, exercise reports with attendance rosters, SAMA incident notification records, business continuity test results with sign-offs, and RTO/RPO documentation.
Third-Party and Supply Chain Risk
SAMA now emphasizes third-party risk management. Institutions must:
- Conduct due diligence assessments of vendors with access to systems or data.
- Include cybersecurity clauses in contracts (right to audit, incident notification, data protection standards).
- Monitor third-party compliance through periodic reviews or attestations (SOC 2 Type II, ISO 27001 certificates, or equivalent).
Evidence to maintain: Vendor risk assessments, contract templates with security clauses, and vendor compliance attestations filed and dated.
Preparing for SAMA Examination
Create a compliance evidence repository organized by control domain. Ensure all policies are dated, approved, and version-controlled. Maintain a log of control implementation dates and any exceptions or waivers. Designate a single point of contact for SAMA inquiries and conduct an internal readiness assessment 6–12 months before your next examination cycle.
SAMA compliance is not a checkbox exercise—it is a demonstration of sustained, mature cybersecurity governance. Institutions that document, test, and continuously improve their controls will satisfy regulatory expectations and reduce operational risk.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment