SAMA Cyber Security Framework: The Current Landscape
The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework represents the regulatory baseline for all financial institutions and critical infrastructure operators in the Kingdom. Unlike prescriptive checklists, the SAMA CSF is principles-based, requiring organisations to demonstrate how they meet core objectives across five pillars: governance and risk management, security controls, operational resilience, third-party risk, and incident response.
As of 2024–2025, SAMA expects financial institutions to align with international standards—particularly ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0—while embedding Saudi-specific requirements such as data residency under the Personal Data Protection Law (PDPL) and alignment with the National Cybersecurity Authority (NCA) Essential Cyber Controls (ECC).
Five Core Pillars and Evidence Requirements
1. Governance and Risk Management
SAMA mandates a documented governance structure with board-level cyber oversight. Evidence must include:
- Board charter or committee terms of reference explicitly assigning cyber accountability
- Risk appetite statement signed by senior management
- Cyber risk register updated at least quarterly, with documented review and approval
- Annual cyber risk assessments performed by independent third parties
Many institutions fail here by treating cyber as an IT function rather than a business risk. SAMA auditors look for evidence that the board understands and actively monitors cyber exposure.
2. Security Controls and Architecture
SAMA expects baseline technical controls aligned with NCA ECC. Evidence includes:
- Documented security architecture and data flow diagrams
- Baseline configuration standards for all asset classes (servers, endpoints, network devices)
- Access control matrices showing role-based permissions and segregation of duties
- Encryption standards for data in transit and at rest, with key management procedures
- Vulnerability management reports showing discovery, remediation, and closure timelines
Organisations must prove not just that controls exist, but that they are consistently applied and monitored. Configuration drift and unpatched systems are common compliance gaps.
3. Operational Resilience
SAMA requires business continuity and disaster recovery capability. Evidence must demonstrate:
- Tested backup and recovery procedures with documented RTO and RPO targets
- Annual disaster recovery drills with signed completion reports
- Incident response playbooks covering ransomware, data breach, and availability scenarios
- Security operations centre (SOC) logs and alerting procedures
Tabletop exercises and simulations count as evidence; untested plans are not acceptable.
4. Third-Party and Supply Chain Risk
SAMA requires vendor risk management aligned with PDPL principles. Document:
- Vendor assessment questionnaires and security evaluation criteria
- Contracts with explicit cyber and data protection clauses
- Ongoing monitoring reports (e.g., quarterly vendor security audits)
- Incident notification procedures for third-party breaches
Data processors handling customer data must comply with PDPL; evidence includes data processing agreements and proof of data residency in Saudi Arabia where required.
5. Incident Response and Reporting
SAMA mandates rapid detection and reporting of cyber incidents. Evidence includes:
- Documented incident response procedures with clear escalation paths
- Incident log showing detection time, classification, and resolution
- Breach notification records (to SAMA, NCA, and affected individuals within PDPL timelines)
- Post-incident reviews with root cause analysis and corrective actions
Practical Evidence-Gathering Approach
Start with a gap assessment. Compare your current state against the SAMA CSF and NCA ECC. Identify missing policies, controls, or documentation.
Build a control matrix. Map each SAMA requirement to your policies, procedures, and technical controls. Assign ownership and target completion dates.
Maintain audit trails. Ensure all security events, configuration changes, and access logs are retained for at least 12 months and indexed for audit retrieval.
Schedule regular reviews. SAMA expects evidence of ongoing monitoring, not a one-time compliance snapshot. Quarterly board reports and annual independent assessments are standard.
Engage external auditors early. Internal and external audit findings must be documented and tracked to closure. Auditors will ask for evidence of remediation.
Key Takeaway
SAMA compliance is not a project; it is a continuous control environment. Evidence is built through daily operations—logging, monitoring, testing, and review. Organisations that embed cyber governance into their risk management culture will find compliance demonstration straightforward. Those that treat it as a checkbox exercise will struggle under regulatory scrutiny.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment