Understanding SAMA's Current Cyber Security Framework
The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework remains the foundational standard for financial institutions operating in the Kingdom. As of 2024–2025, SAMA expects all regulated entities—banks, fintech platforms, and payment service providers—to implement controls aligned with the framework's five pillars: governance, risk management, technical controls, operational resilience, and incident response. The framework explicitly incorporates principles from NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022, creating a hybrid expectation that combines international best practice with Saudi regulatory intent.
Unlike prescriptive checklists, SAMA's approach emphasizes outcomes: institutions must demonstrate that their cyber posture protects confidentiality, integrity, and availability of critical financial systems and customer data. This principle-based design means compliance is not a one-time checkbox but an evolving commitment tied to your organization's risk appetite and threat landscape.
Core SAMA CSF Pillars and Evidence Requirements
Governance and Oversight
SAMA requires a documented cyber governance structure with clear accountability. Evidence includes:
- Board-level cyber risk reporting (minimum quarterly) with documented Board Cyber Committee charter
- Cyber risk policy framework approved by the Board, defining roles, responsibilities, and escalation paths
- Chief Information Security Officer (CISO) or equivalent with direct reporting line to the Chief Risk Officer or Board
- Documented cyber strategy aligned with business objectives and regulatory expectations
Auditors will request meeting minutes, policy version control records, and organizational charts demonstrating segregation of duties between IT operations, security, and audit functions.
Risk Management and Assessment
SAMA mandates annual cyber risk assessments covering all critical systems and third-party dependencies. Evidence must include:
- Formal risk assessment methodology (e.g., NIST RMF, ISO 31000) with documented scope, assumptions, and review cycles
- Risk register identifying threats, vulnerabilities, likelihood, impact, and residual risk post-mitigation
- Documented risk appetite statement and tolerance thresholds approved by the Board
- Third-party risk assessments for vendors handling sensitive data or managing critical infrastructure
Risk assessments must be refreshed annually or when material changes occur (system upgrades, new integrations, regulatory changes). Maintain evidence of remediation tracking and closure sign-off by risk owners.
Technical Controls
SAMA expects controls consistent with ISO/IEC 27001:2022 Annex A. Key evidence areas include:
- Access control policies with role-based access control (RBAC), multi-factor authentication (MFA) for all privileged accounts, and quarterly access reviews with documented approval
- Encryption standards for data at rest (AES-256 minimum) and in transit (TLS 1.2 or higher) with key management procedures
- Vulnerability management program: quarterly scans, patch management SLAs, and closure evidence
- Logging and monitoring: centralized Security Information and Event Management (SIEM) with 12-month retention, documented alerting rules, and incident investigation logs
Maintain configuration baselines, change logs, and evidence of testing before production deployment. Compliance auditors will request system architecture diagrams, control matrices, and test reports.
Operational Resilience and Business Continuity
SAMA requires documented incident response and continuity plans tested annually. Evidence includes:
- Incident Response Plan with defined roles, communication protocols, and escalation procedures
- Business Continuity and Disaster Recovery plans with Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) aligned to critical systems
- Annual tabletop exercises and full failover tests with documented results and lessons learned
- Backup and recovery procedures with regular restoration testing
Practical Steps to Evidence Compliance
Documentation and Governance: Maintain a cyber compliance register mapping SAMA requirements to policies, procedures, and evidence artifacts. Use version control and approval workflows for all cyber governance documents.
Audit Trail and Monitoring: Implement SIEM and log aggregation to capture all security-relevant events. Ensure logs are immutable and retained per regulatory timelines. Document alert tuning and investigation outcomes.
Third-Party Management: Require vendors to provide SOC 2 Type II reports or equivalent security attestations. Maintain vendor risk assessments and contractual cyber clauses requiring compliance with SAMA expectations.
Training and Awareness: Document annual security awareness training completion rates, phishing simulation results, and targeted training for high-risk roles. SAMA expects evidence of a security-conscious culture.
Internal Audit and Assurance: Conduct annual internal cyber audits using SAMA CSF or ISO 27001:2022 as the benchmark. Engage external auditors to validate control design and operating effectiveness. Share audit findings and remediation plans with the Board.
Alignment with Broader Regulatory Landscape
SAMA CSF compliance overlaps with the Saudi Personal Data Protection Law (PDPL) and National Cybersecurity Authority (NCA) Critical Infrastructure Protection guidelines. Ensure your evidence repository addresses all three frameworks cohesively. For example, data protection impact assessments (DPIAs) under PDPL align with SAMA's risk assessment requirement.
Institutions should view SAMA CSF compliance not as a regulatory burden but as a foundation for resilient, trustworthy financial operations that protect customers and shareholder value in an evolving threat environment.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment