SAMA's Cyber Security Framework: Current Scope and Mandatory Controls
The Saudi Central Bank (SAMA) Cyber Security Framework establishes binding expectations for all regulated financial institutions, including banks, insurance companies, and payment service providers. The framework mandates a risk-based approach aligned with international standards—particularly NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, and the National Cybersecurity Authority's Essential Cybersecurity Controls (NCA ECC).
Unlike prescriptive checklists, SAMA's framework emphasizes outcome-focused governance: institutions must demonstrate that cyber risk is managed at board level, that security investments align with business criticality, and that incident response is tested and effective. The framework covers five core domains: governance and risk management, asset management, access control, detection and response, and business continuity.
Key Evidence Requirements for Regulatory Compliance
1. Governance and Board Accountability
SAMA expects documented evidence that the board and senior management own cyber risk. This includes:
- Board-approved cyber risk policy and strategy, reviewed annually
- Minutes from board or audit committee meetings discussing cyber incidents, risk appetite, and investment decisions
- Defined roles and responsibilities for the Chief Information Security Officer (CISO) or equivalent, with direct reporting line to the board or CEO
- Cyber risk metrics and KPIs reported monthly or quarterly to governance bodies
2. Risk Assessment and Treatment Plans
Institutions must maintain current, documented risk assessments that identify threats to critical assets and systems. Evidence should include:
- Annual enterprise-wide cyber risk assessment, with methodology aligned to ISO/IEC 27005 or equivalent
- Asset inventory covering hardware, software, data, and cloud services
- Risk treatment plans with assigned owners, timelines, and budget allocation
- Evidence of remediation: closed tickets, configuration changes, and control testing results
3. Technical Controls and Configuration Management
SAMA expects institutions to implement and maintain baseline security controls across their technology estate. Auditable evidence includes:
- Hardened configurations for servers, network devices, and endpoints, documented and version-controlled
- Vulnerability management: scanning reports, patch schedules, and closure of critical and high-risk findings
- Access control logs showing who accessed what, when, and why—retained for at least 12 months
- Encryption of data in transit and at rest, with key management procedures documented
- Network segmentation diagrams and firewall rules aligned to the principle of least privilege
4. Incident Detection and Response
Institutions must demonstrate the ability to detect, investigate, and respond to cyber incidents. Required evidence:
- Security Operations Center (SOC) or equivalent monitoring capability, with defined escalation procedures
- Incident response plan, tested at least annually through tabletop exercises or simulations
- Log aggregation and analysis tools (SIEM or equivalent) with alerting rules tuned to your environment
- Records of past incidents: timeline, root cause analysis, remediation, and lessons learned
- Evidence of third-party notification and regulatory reporting (to SAMA, if required)
5. Third-Party Validation and Assurance
SAMA increasingly expects independent verification. Evidence should include:
- Annual penetration testing or red-team exercise, performed by qualified external firms
- SOC 2 Type II audit or equivalent assurance report for critical service providers
- ISO/IEC 27001:2022 certification, or a roadmap to certification with interim audit findings
- Vendor risk assessments for critical suppliers, documented and reviewed annually
Alignment with Saudi Data Protection Law and NCA Guidance
The Saudi Personal Data Protection Law (PDPL) and its implementing regulations require institutions to protect personal data through technical and organizational measures. SAMA's framework incorporates these obligations: institutions must evidence data classification, access controls, and breach notification procedures. The NCA ECC provides additional detail on baseline controls for critical information infrastructure, and many financial institutions fall within this scope.
Preparing for SAMA Assessment
Regulatory assessments typically involve document review, interviews with key personnel, and technical testing. To strengthen your position:
- Maintain a compliance register mapping SAMA requirements to your policies, procedures, and technical controls
- Conduct an internal audit or self-assessment against the framework, document gaps, and track remediation
- Ensure evidence is organized, current, and easily retrievable—auditors expect to see recent logs, test results, and meeting minutes
- Brief your board and senior management on cyber risk and compliance status quarterly
- Engage external consultants or auditors to validate your approach before formal SAMA assessment
SAMA's framework is not a one-time compliance exercise. It requires continuous monitoring, regular updates to policies and controls, and demonstrated commitment from leadership. By building a culture of cyber accountability and maintaining clear, auditable evidence of your controls, you reduce regulatory risk and strengthen your institution's resilience.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment