Understanding SAMA's Current Expectations
The Saudi Central Bank (SAMA) Cyber Security Framework establishes mandatory controls and governance standards for all financial institutions operating under its supervision. Unlike advisory guidance, SAMA's framework carries regulatory force and is subject to examination and enforcement. Financial leaders must treat it not as aspirational but as a compliance baseline.
The framework aligns with international standards—including ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0—while reflecting Saudi Arabia's regulatory environment and the National Cybersecurity Authority (NCA) Enterprise Cybersecurity Controls (ECC). This convergence means institutions can often satisfy multiple frameworks through a single, well-designed control architecture.
Core Pillars and Evidence Requirements
1. Governance and Board Oversight
SAMA requires documented board-level accountability for cybersecurity. Evidence includes:
- Board charter or committee charter explicitly assigning cybersecurity responsibility
- Quarterly or semi-annual board reports on cyber risk, incidents, and remediation status
- Board approval of the cybersecurity strategy and annual risk appetite statement
- Documented board decisions on material cyber incidents and remediation investments
A Chief Information Security Officer (CISO) or equivalent must report directly to the board or audit committee, not buried within IT operations.
2. Risk Management and Assessment
SAMA mandates a formal, documented risk management process:
- Annual risk assessments: Comprehensive identification of cyber threats, vulnerabilities, and business impact. Assessments must be repeatable, documented, and traceable to control implementation.
- Risk register: A living inventory of identified risks, their rating, assigned owners, and mitigation plans with target completion dates.
- Third-party and supply-chain risk: Evidence of vendor assessment, contractual security clauses, and ongoing monitoring of critical service providers.
- Scenario planning: Documented business continuity and disaster recovery drills, with results reviewed by senior management.
3. Technical and Operational Controls
SAMA expects institutions to implement and evidence controls across:
- Access control: Role-based access policies, multi-factor authentication for critical systems, privileged account management, and periodic access reviews with documented approvals.
- Data protection: Encryption in transit and at rest, data classification, and retention policies aligned with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations.
- Monitoring and logging: Centralized security information and event management (SIEM) with retention periods meeting regulatory requirements, and documented procedures for alert investigation.
- Incident response: A tested, documented incident response plan with defined roles, escalation paths, and communication protocols. Evidence includes incident logs, post-incident reviews, and lessons learned.
4. Compliance and Audit
SAMA expects:
- Annual internal audit of the cybersecurity program, with findings and remediation tracked to closure
- External penetration testing and vulnerability assessments at least annually, with results and remediation documented
- Compliance assessment against SAMA's framework itself, with a gap analysis and remediation roadmap
- Documentation of all control testing, results, and evidence retained for examination
Practical Steps to Evidence Compliance
Establish a control matrix: Map each SAMA requirement to implemented controls, responsible parties, and evidence artifacts. Update quarterly.
Maintain a compliance repository: Centralize policies, procedures, assessment reports, board minutes, incident logs, and audit findings in a secure, auditable system.
Conduct a baseline assessment: Engage an independent assessor to evaluate current state against SAMA's framework and produce a detailed gap report. Use this to prioritize remediation.
Align with NCA ECC: The NCA's Enterprise Cybersecurity Controls provide a detailed technical reference. Ensure your control design and evidence collection align with both SAMA and NCA expectations to avoid duplication.
Embed PDPL compliance: Document how your data protection and privacy controls satisfy the Saudi Personal Data Protection Law, especially around consent, processing, and breach notification.
Looking Ahead
SAMA's framework is not static. Institutions should monitor NCA guidance, international standard updates, and SAMA circulars for evolving expectations. Cybersecurity is now a board-level business risk, not an IT checkbox. Financial leaders who treat evidence collection as integral to control design—rather than a retrospective compliance burden—will demonstrate genuine resilience and satisfy regulatory expectations sustainably.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment