The SAMA Cyber Security Framework: Scope and Core Pillars
The Saudi Central Bank (SAMA) Cyber Security Framework sets binding expectations for all licensed banks, insurance companies, payment service providers, and other regulated financial institutions operating in the Kingdom. The framework aligns with international best practice while reflecting Saudi Arabia's strategic priorities under Vision 2030 and the National Cybersecurity Strategy.
The framework rests on four primary pillars: governance and risk management, technical and operational controls, incident response and business continuity, and third-party and supply chain security. Each pillar carries specific, auditable requirements that regulators expect institutions to meet and evidence continuously.
Governance and Risk Management: Documentation as Evidence
SAMA expects a board-level cyber risk committee with clearly defined charter, meeting frequency, and documented decision records. Security leaders must maintain:
- A current cyber risk policy approved by the board, reviewed annually, and aligned with the institution's risk appetite statement.
- A formal risk assessment methodology (aligned with ISO/IEC 27005 or equivalent) applied at least annually to all critical systems, with documented findings and remediation tracking.
- A cyber risk register updated quarterly, showing residual risk ratings and management approval of accepted risks.
- Evidence of board reporting on cyber risk metrics, including breach attempts, control failures, and remediation progress.
Regulators will request these documents during examinations. Institutions without current, signed board minutes confirming cyber risk oversight face supervisory findings. The expectation is not perfection but demonstrable, proportionate governance.
Technical Controls: Baseline Standards and Assessment Evidence
SAMA references ISO/IEC 27001:2022 and the NIST Cybersecurity Framework 2.0 as benchmarks. Institutions must evidence:
- Access control policies: Multi-factor authentication for all privileged accounts, documented segregation of duties, and quarterly access reviews with sign-off by business owners.
- Data protection: Encryption of sensitive data in transit and at rest, key management procedures, and a data classification policy applied to all systems.
- Network security: Firewalls, intrusion detection/prevention systems, and segmentation of critical systems, with change management logs and vulnerability scan reports.
- Vulnerability management: Quarterly vulnerability assessments (internal and external), documented remediation timelines, and evidence of patching within defined SLAs.
- Security monitoring: A Security Operations Center (SOC) or equivalent capability with 24/7 coverage, logged alerts, and documented incident triage procedures.
Evidence takes the form of audit reports, configuration baselines, patch deployment logs, and SOC dashboards showing alert volume and response times. Third-party assessments (e.g., ISO 27001 certification, NIST CSF assessments) strengthen the institution's position.
Incident Response and Business Continuity
SAMA mandates a documented incident response plan, tested at least annually through tabletop or full-scale exercises. Evidence includes:
- A current incident response playbook with defined roles, escalation paths, and communication templates.
- Records of incident response drills with documented lessons learned and corrective actions.
- A business continuity and disaster recovery plan tested annually, with recovery time and recovery point objectives approved by senior management.
- Logs of all security incidents (even minor ones) in a centralized incident tracking system, with root cause analysis for significant events.
Institutions must report significant cyber incidents to SAMA within defined timeframes (typically 24–72 hours depending on severity). Regulators review incident reports for adequacy of response and transparency.
Third-Party and Supply Chain Security
SAMA expects institutions to assess and monitor the cyber posture of critical service providers, including cloud vendors, payment processors, and software suppliers. Evidence includes:
- A vendor risk assessment framework applied before engagement.
- Service level agreements (SLAs) that include cyber security requirements and audit rights.
- Annual vendor security assessments (via questionnaire, on-site audit, or third-party attestation such as SOC 2 Type II).
- A register of critical vendors and their residual risk ratings.
Alignment with the Saudi Personal Data Protection Law
The Saudi Personal Data Protection Law (PDPL) and its implementing regulations reinforce SAMA's expectations by requiring organizations to safeguard personal data through technical and organizational measures. Compliance evidence overlaps: data protection policies, access logs, and breach notification procedures satisfy both SAMA and PDPL audits.
Practical Steps for Evidence Gathering
Security leaders should conduct a gap assessment against the SAMA framework and ISO/IEC 27001:2022, prioritize remediation by risk, and establish a documentation calendar. Regular board reporting, audit trails, and third-party validation build credibility with regulators. The goal is not to achieve a perfect score but to demonstrate a mature, proportionate, and continuously improving security posture aligned with the institution's business model and risk profile.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment