Understanding SAMA's Current Cyber Security Framework
The Saudi Central Bank (SAMA) Cyber Security Framework establishes a baseline of mandatory security controls for all financial institutions, payment service providers, and critical infrastructure operators under its jurisdiction. Unlike voluntary frameworks, SAMA CSF compliance is a regulatory requirement enforced through regular supervisory reviews and examinations.
The framework aligns with international standards—particularly ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0—while addressing the specific risk environment and operational context of the Saudi financial system. Entities must demonstrate not only that controls exist, but that they are effective, documented, and continuously monitored.
Core Pillars and Compliance Evidence
1. Governance and Risk Management
SAMA expects a documented cyber risk governance structure with clear accountability. Evidence includes:
- Board-approved cyber security strategy and annual risk assessments aligned with business objectives
- Defined roles for Chief Information Security Officer (CISO) or equivalent, with direct board reporting lines
- Documented risk appetite statement specific to cyber threats
- Third-party risk assessments for critical vendors and service providers
Auditors will request board meeting minutes, governance charters, and evidence that cyber risk is reviewed at least quarterly at senior management level.
2. Technical Controls and Asset Management
SAMA mandates baseline technical hygiene: access control, encryption, network segmentation, and endpoint hardening. Compliance evidence must include:
- Inventory of all IT assets (hardware, software, cloud services) with classification by criticality
- Encryption standards applied to data at rest and in transit, with key management procedures documented
- Multi-factor authentication (MFA) enforced for all privileged accounts and remote access
- Vulnerability management program with defined scan frequency, remediation timelines, and closure evidence
- Configuration baselines and change management logs showing approval and testing
Maintain centralized logs of all control changes and evidence of periodic penetration testing or red-team exercises conducted by qualified third parties.
3. Incident Response and Business Continuity
SAMA requires a tested incident response plan and business continuity strategy. Auditors will examine:
- Documented incident response procedures with clear escalation paths and communication protocols
- Evidence of annual tabletop exercises or simulations involving senior management
- Recovery time objectives (RTO) and recovery point objectives (RPO) for critical systems, approved by the board
- Backup and disaster recovery testing results, with documented recovery success rates
- Incident logs showing detection, response, and closure for a representative sample of events
4. Compliance with NCA ECC and PDPL
The National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) and the Saudi Personal Data Protection Law (PDPL) overlap with SAMA CSF. Entities must demonstrate:
- Data classification and handling procedures compliant with PDPL requirements
- Privacy impact assessments for new systems or data processing activities
- Breach notification procedures aligned with PDPL timelines (72 hours to NCA; without undue delay to affected individuals)
- Alignment of access controls and data retention policies with both SAMA and PDPL expectations
Audit Readiness: Practical Steps
Documentation First: Compile a centralized control register mapping each SAMA requirement to your implemented control, responsible party, and evidence location.
Automate Evidence Collection: Use Security Information and Event Management (SIEM) systems, vulnerability scanners, and privileged access management (PAM) tools to generate audit trails automatically. Manual spreadsheets are insufficient.
Regular Self-Assessment: Conduct internal assessments at least semi-annually using the same criteria SAMA examiners will apply. Identify and remediate gaps before supervisory reviews.
Engage Third Parties Wisely: Retain qualified external auditors to validate your control environment. SAMA respects independent assessments and will factor them into supervisory judgments.
Key Takeaway
SAMA compliance is not a checkbox exercise. The framework demands a mature, documented, and continuously improving security posture. Security leaders must ensure that every control is not only in place but also auditable—with clear evidence of design, implementation, testing, and effectiveness. Organizations that treat compliance as an opportunity to strengthen their security posture will find themselves better positioned to resist emerging threats and maintain stakeholder trust.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment