Understanding SAMA CSF Compliance Obligations
The Saudi Arabian Monetary Authority's Cyber Security Framework (SAMA CSF) is the primary regulatory baseline for all financial institutions operating in the Kingdom. Unlike aspirational standards, SAMA CSF compliance is mandatory for banks, insurance companies, and payment service providers. Security leaders must understand that SAMA does not simply require tools or processes—it requires evidence of effective control implementation and continuous monitoring.
SAMA CSF aligns with international benchmarks including the NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022, but adds Saudi-specific governance and reporting expectations. The framework is structured around five core functions: Govern, Protect, Detect, Respond, and Recover. Each function contains specific control objectives that must be demonstrated through documented artifacts, not assertions alone.
Governance and Board Accountability
SAMA expects the board and senior management to own cyber risk as a strategic business risk, not a technical issue delegated entirely to IT. Security leaders must evidence:
- Cyber risk governance charter: A board-approved policy that defines roles, responsibilities, and escalation paths for cyber incidents.
- Risk appetite statement: Explicit tolerance levels for cyber risk, approved by the board, with metrics tied to business objectives.
- Board reporting cadence: Documented quarterly (or more frequent) cyber risk reports to the board, including KRIs (Key Risk Indicators) and incident summaries.
- Third-party oversight: Evidence of board-level review of vendor and supply-chain cyber risks, particularly for critical service providers.
SAMA auditors will request board minutes, risk committee charters, and cyber dashboards. Generic or infrequent reporting will not satisfy the expectation of informed, active board governance.
Risk Assessment and Asset Inventory
SAMA requires organizations to maintain a comprehensive, current inventory of critical assets and a documented risk assessment methodology. Security leaders should evidence:
- Asset register: A living inventory of hardware, software, data repositories, and network segments, classified by criticality and business function. This must be updated at least annually and following material changes.
- Risk assessment framework: A documented methodology (qualitative, quantitative, or hybrid) that identifies threats, vulnerabilities, and business impact. SAMA expects risk assessments for new systems before deployment and for existing systems on a defined cycle (typically every 2–3 years or after significant changes).
- Vulnerability management program: Evidence of regular scanning, remediation tracking, and prioritization based on risk. SAMA expects documented SLAs for patching critical and high-risk vulnerabilities.
- Data classification: A policy and implementation showing how sensitive data (customer information, transaction records, intellectual property) is classified and protected.
Incident Response and Resilience
SAMA mandates that organizations maintain tested incident response and business continuity plans. Security leaders must demonstrate:
- Incident response plan: A documented, board-approved plan with defined roles, communication protocols, and escalation procedures. SAMA expects this to be tested at least annually through tabletop exercises or simulations.
- Incident logging and reporting: Evidence that all security incidents are logged, investigated, and reported to SAMA within defined timeframes (typically 24–72 hours for material incidents, depending on severity).
- Business continuity and disaster recovery: Documented RTO (Recovery Time Objective) and RPO (Recovery Point Objective) targets, with evidence of annual testing and recovery drills.
- Lessons learned process: Documentation showing that post-incident reviews are conducted and findings are tracked to closure.
Practical Evidence Gathering
Security leaders should maintain a compliance evidence repository organized by SAMA CSF function and control. Include:
- Policy documents and approval records.
- Risk assessments and remediation plans.
- Audit reports (internal and external).
- Training and awareness records.
- Incident logs and investigation summaries.
- Board and audit committee meeting minutes.
- Third-party assessments (SOC 2, ISO 27001 certificates).
SAMA examinations are thorough and forward-looking. Organizations that demonstrate a mature, documented, and continuously improving cyber risk management program will satisfy compliance expectations and strengthen their resilience against evolving threats.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment