Understanding SAMA's Current Cyber Security Framework
The Saudi Central Bank (SAMA) Cyber Security Framework represents the regulatory baseline for all financial institutions operating in the Kingdom. Unlike voluntary frameworks, SAMA's requirements are binding and subject to on-site examination by the Banking Supervision Department. The Framework aligns with international standards—particularly NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022—while reflecting the unique operational and geopolitical context of Saudi Arabia's financial sector.
SAMA's Framework is organized around five core pillars: governance and risk management, asset management and data protection, access control and identity, detection and response, and business continuity and resilience. Each pillar contains specific control families, and each control has defined maturity levels (typically ranging from initial to optimized).
Key Evidence Requirements by Domain
Governance and Risk Management
SAMA expects documented evidence of board-level cyber oversight. This includes:
- Board minutes showing cyber risk discussion at least quarterly
- A board-approved Cyber Security Policy signed by the Chief Executive Officer
- Formal role definitions for the Chief Information Security Officer (CISO) or equivalent, with direct reporting line to the CEO or board committee
- A current risk register identifying cyber threats, inherent risk ratings, and mitigating controls
- Annual cyber risk assessments conducted by independent parties
- Incident response plan with defined escalation procedures and communication protocols
Regulators will request these documents during examination. Static policies are insufficient; evidence must show active governance—meeting minutes, decision logs, and sign-offs.
Asset Management and Data Protection
SAMA requires comprehensive asset inventory and data classification. Acceptable evidence includes:
- A complete, current inventory of hardware, software, and cloud assets with ownership and criticality ratings
- Data classification policy applied across the organization (e.g., public, internal, confidential, restricted)
- Encryption standards for data at rest and in transit, with audit logs showing enforcement
- Backup and recovery procedures tested at least annually, with documented results
- Data retention and disposal procedures aligned with the Saudi Personal Data Protection Law (PDPL)
SAMA examiners will sample assets and verify they are tracked and protected according to policy. Undocumented systems are treated as non-compliant.
Access Control and Identity
Identity and access management (IAM) is a high-priority domain. Required evidence:
- Multi-factor authentication (MFA) implemented for all administrative and remote access
- Privileged access management (PAM) solution logs showing who accessed what, when, and why
- User access reviews performed at least semi-annually, with documented approval and remediation
- Role-based access control (RBAC) policies defining permissions by job function
- Password policy enforcement (complexity, expiration, history) with technical controls
- Third-party access agreements and monitoring procedures
Detection and Response
SAMA expects a mature security operations capability. Evidence must demonstrate:
- Security Information and Event Management (SIEM) or equivalent log aggregation and monitoring
- Defined alert thresholds and escalation procedures
- Incident response exercises (tabletop or simulated) conducted at least annually
- Incident logs documenting detection time, response time, root cause, and remediation
- Threat intelligence integration and regular security awareness training records
Business Continuity and Resilience
Continuity planning must be tested and documented:
- Business continuity and disaster recovery plans covering critical systems
- Recovery time objective (RTO) and recovery point objective (RPO) definitions, aligned with business criticality
- Annual testing results with documented failover and recovery times
- Backup systems geographically separated from primary infrastructure
Practical Compliance Steps
To evidence SAMA compliance, security leaders should:
- Conduct a gap assessment against the current SAMA Framework, comparing your current state to each control's requirements.
- Prioritize high-risk gaps that directly affect customer data, payment systems, or critical services.
- Document everything. Policies, procedures, test results, meeting minutes, and audit logs are your evidence.
- Implement a compliance tracking system to monitor control implementation status and provide audit-ready dashboards.
- Engage external auditors to validate compliance before regulatory examination.
- Align with NCA ECC and PDPL requirements where they overlap with SAMA expectations, to avoid duplicative effort.
Conclusion
SAMA compliance is not a one-time project; it is an ongoing operational discipline. Regulators expect evidence that controls are not just documented but actively managed, tested, and improved. Organizations that treat compliance as a checkbox exercise face enforcement action. Those that embed SAMA requirements into their security operations and governance culture will demonstrate resilience and earn regulatory confidence.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment