Understanding SAMA's Current Cyber Security Framework
The Saudi Central Bank (SAMA) Cyber Security Framework establishes binding security requirements for all licensed financial institutions operating in the Kingdom. Unlike advisory guidance, SAMA's framework carries regulatory weight: non-compliance exposes institutions to enforcement action, penalties, and operational restrictions. Security leaders must treat the framework not as aspirational but as a compliance baseline with measurable, auditable evidence requirements.
The framework aligns with international standards—particularly NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022—while embedding Saudi regulatory context. This dual approach means organisations must satisfy both global best practice and local supervisory expectations.
Core Pillars and Evidence Requirements
SAMA's framework rests on five interconnected pillars: governance and risk management, security operations, incident response and business continuity, third-party risk management, and emerging technology controls. Each pillar demands specific, documented evidence.
Governance and Risk Management
SAMA expects a documented cyber risk strategy approved by the board or senior management committee. Evidence includes:
- Board-level cyber risk policy and charter
- Annual cyber risk assessments aligned to business objectives
- Risk register with residual risk tolerance signed by leadership
- Documented roles, responsibilities, and escalation paths for cyber incidents
- Evidence of board or audit committee oversight (meeting minutes, reports)
Many institutions falter here: a policy document alone is insufficient. SAMA auditors verify that risk assessments are conducted annually, that findings drive investment decisions, and that senior management actively reviews and approves risk appetite.
Security Operations and Technical Controls
SAMA mandates a Security Operations Centre (SOC) or equivalent monitoring capability. Required evidence includes:
- SOC architecture documentation and staffing plans
- Endpoint detection and response (EDR) deployment across critical systems
- Network segmentation diagrams with compensating controls where segmentation is incomplete
- Encryption standards for data at rest and in transit (aligned to NIST or ISO standards)
- Multi-factor authentication (MFA) deployment logs for privileged and remote access
- Vulnerability management programme with scan schedules, remediation timelines, and closure evidence
Auditors will request proof of control execution: scan reports, patch deployment logs, access review sign-offs. A control is not "implemented" until it is actively monitored and documented.
Incident Response and Business Continuity
SAMA requires a tested incident response plan and business continuity strategy. Evidence must include:
- Documented incident response procedures with defined roles and communication trees
- Annual tabletop or full-scale incident response exercises with documented outcomes
- Business continuity and disaster recovery plans tested at least annually
- Recovery time objectives (RTO) and recovery point objectives (RPO) approved by business owners
- Incident logs with timeline, impact assessment, and remediation actions
Exercises must be realistic and documented. Simulated incidents that reveal gaps strengthen your compliance posture if remediation is tracked and completed.
Third-Party and Emerging Technology Risk
SAMA increasingly scrutinises vendor and supply-chain security, particularly for cloud and outsourced services. Required evidence:
- Vendor risk assessment questionnaires and security audit results
- Contractual security clauses and service level agreements (SLAs) with audit rights
- Monitoring logs for third-party access and data transfers
- Policies governing artificial intelligence (AI) and machine learning (ML) deployments, aligned to NIST AI Risk Management Framework
Practical Compliance Steps
Conduct a SAMA alignment audit. Map your current controls to the framework's requirements. Identify gaps and prioritise remediation by risk and regulatory weight.
Document everything. Policies, procedures, logs, test results, and sign-offs must be retained and readily retrievable for SAMA inspections.
Integrate with PDPL compliance. The Saudi Personal Data Protection Law (PDPL) and its implementing regulations overlap with SAMA's security requirements. Unified evidence management reduces duplication.
Engage the board. SAMA expects visible senior management commitment. Regular cyber risk reporting to the board or audit committee is non-negotiable.
Plan for evolution. SAMA's framework evolves as threats and technologies change. Subscribe to SAMA circulars and engage with industry forums to stay ahead of emerging expectations.
Conclusion
SAMA's Cyber Security Framework is not a checkbox exercise. It demands a mature, documented security programme with active governance, measurable controls, and continuous improvement. Security leaders who treat the framework as a strategic roadmap—not a compliance burden—will build resilience that protects both regulatory standing and institutional reputation.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment