Understanding SAMA's Current Cyber Security Framework
The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework establishes mandatory control baselines for all financial institutions operating under its jurisdiction. Unlike earlier guidance that emphasized principles, the current framework defines specific technical and organizational requirements aligned with international standards—principally ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0.
SAMA expects institutions to demonstrate that controls are not theoretical but operationally embedded. This shift from compliance-as-documentation to compliance-as-evidence fundamentally changes how security leaders approach governance and audit readiness.
Core Control Domains and Evidence Requirements
Governance and Risk Management
SAMA mandates a documented cyber risk management strategy approved by the board or equivalent governing body. Evidence must include:
- Board-level cyber risk policy signed and dated within the last 12 months
- Documented risk assessment methodology aligned with ISO/IEC 27005 principles
- Annual risk assessments with signed-off findings and remediation plans
- Evidence of board or audit committee review of cyber incidents and remediation status
Security leaders should maintain a centralized risk register that maps identified risks to specific controls, with clear ownership, target remediation dates, and executive sign-off trails.
Incident Response and Business Continuity
SAMA requires a documented incident response plan tested at least annually. Acceptable evidence includes:
- Formal incident response procedures covering detection, containment, eradication, and recovery
- Tabletop or live exercise records demonstrating team readiness
- Log files or system records proving detection and alerting mechanisms function
- Post-incident review documentation for any real incidents, with lessons learned
Business continuity plans must be tested and updated annually, with evidence of recovery time objective (RTO) and recovery point objective (RPO) validation.
Technical Controls and Monitoring
SAMA expects continuous monitoring of critical systems. Auditable evidence includes:
- System configuration baselines documented and version-controlled
- Security event logs retained for a minimum period (typically 90 days for real-time, 12 months for archival)
- Vulnerability scanning reports with remediation tracking
- Access control matrices showing who has permissions to what systems and why
- Encryption inventory for data in transit and at rest
A functional Security Operations Center (SOC) or equivalent monitoring capability must demonstrate active threat detection, not passive log storage.
Alignment with Broader Saudi Regulatory Landscape
SAMA's framework sits within a broader ecosystem. The National Cybersecurity Authority (NCA) Enterprise Cybersecurity Center (ECC) publishes sector-wide guidance; the Saudi Personal Data Protection Law (PDPL) and its implementing regulations impose additional data-handling obligations; and ISO/IEC 42001 (AI Risk Management) increasingly applies to institutions deploying AI in critical functions.
Security leaders must ensure controls evidence satisfies all overlapping requirements. For instance, data classification controls required by SAMA must also support PDPL compliance, and AI governance controls must address both SAMA and ISO/IEC 42001 expectations.
Practical Steps to Evidence Compliance
1. Audit Trail Infrastructure: Implement centralized logging and SIEM tools that capture all security-relevant events. Ensure logs are immutable and retained per regulatory timelines.
2. Control Testing Schedule: Define a quarterly or semi-annual control testing calendar. Document each test, its results, and any gaps. Maintain evidence in a centralized repository.
3. Third-Party Validation: Consider annual independent security assessments or penetration tests. External validation strengthens evidence credibility during regulatory review.
4. Documentation Discipline: Policies, procedures, and evidence must be current, signed, and dated. Outdated or undated documents weaken compliance posture.
5. Board Engagement: Ensure cyber risk is a standing agenda item for the board or audit committee. Document attendance, discussion points, and decisions.
Conclusion
SAMA's Cyber Security Framework is not a checklist to tick; it is a mandate to operate secure, resilient financial infrastructure with demonstrable controls. Security leaders who shift from compliance theater to evidence-based governance will not only pass regulatory scrutiny but build genuine organizational resilience. The time to begin documentation and testing is now—regulators increasingly expect maturity, and the financial sector's criticality means no margin for shortcuts.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment