Understanding the Current SAMA Cyber Security Framework
The Saudi Arabian Monetary Authority (SAMA) has established a comprehensive Cyber Security Framework that sets mandatory expectations for all financial institutions operating in the Kingdom. Unlike prescriptive checklists, the framework emphasizes outcomes: institutions must demonstrate that their cyber defenses are proportionate to risk, continuously monitored, and capable of detecting and responding to threats in real time.
The framework aligns with international standards—particularly NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022—but is tailored to Saudi Arabia's regulatory environment and the specific threat landscape facing financial services. SAMA expects institutions to move beyond compliance theater and prove that controls are not merely documented but actively effective.
Core Pillars and Evidence Requirements
Governance and Accountability
SAMA requires a clearly defined cyber governance structure with board-level oversight. Evidence must include:
- Board-approved cyber security strategy and annual risk assessment
- Named Chief Information Security Officer (CISO) with direct reporting to the Chief Risk Officer or equivalent
- Documented roles, responsibilities, and escalation procedures
- Board minutes and management committee records showing regular cyber risk review (at minimum quarterly)
Risk Management and Assessment
Institutions must conduct annual enterprise-wide cyber risk assessments and maintain a live risk register. SAMA expects evidence of:
- Documented risk assessment methodology aligned with ISO/IEC 27005 principles
- Risk scoring and prioritization tied to business impact
- Risk treatment plans with assigned owners and timelines
- Regular reassessment following significant changes (system upgrades, mergers, regulatory changes)
Technical Controls and Monitoring
SAMA mandates continuous monitoring and logging across all critical systems. Proof of compliance includes:
- Security Information and Event Management (SIEM) logs retained for a minimum period defined in your data retention policy
- Network segmentation and access control matrices documented and tested
- Encryption standards for data in transit and at rest, with key management procedures
- Vulnerability assessment reports (at least quarterly) and remediation tracking
- Penetration testing results (annual minimum for critical systems)
Incident Response and Resilience
A tested incident response plan is non-negotiable. SAMA requires:
- Written incident response procedure with clear notification timelines
- Evidence of tabletop exercises or simulations conducted at least annually
- Incident log with classification, timeline, root cause, and remediation
- Notification to SAMA within the prescribed timeframe for material incidents
- Business continuity and disaster recovery plans with documented recovery time objectives (RTO) and recovery point objectives (RPO)
Alignment with the Saudi PDPL
The Saudi Personal Data Protection Law (PDPL) reinforces SAMA's expectations by imposing strict requirements on data handling, breach notification, and individual rights. Institutions must demonstrate that cyber controls protect personal data throughout its lifecycle. This includes:
- Data inventory and classification
- Documented data processing agreements with third parties
- Evidence of data subject rights fulfillment (access, correction, deletion)
- Breach notification procedures aligned with PDPL timelines
How to Evidence Compliance
Regulatory examinations now focus on control effectiveness, not mere existence. Prepare:
- Control testing reports: Quarterly or semi-annual evidence that controls are operating as designed
- Audit trails: System logs, access reviews, and configuration change records
- Training records: Proof that staff understand cyber policies and incident procedures
- Third-party assessments: SOC 2 Type II reports, ISO 27001 certificates, or independent security audits
- Metrics and KPIs: Mean time to detect (MTTD), mean time to respond (MTTR), patch compliance rates, and security awareness metrics
Key Takeaway
SAMA's framework is not a one-time compliance exercise. It demands a mature, risk-driven approach to cyber security with continuous measurement and improvement. Financial institutions that treat cyber security as a strategic business function—with adequate budget, skilled personnel, and board attention—will find evidence gathering straightforward and regulatory relationships constructive.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment