GCC · Saudi Central Bank

SAMA Cyber Security Framework

The cyber security framework applying to institutions supervised by the Saudi Central Bank, structured around maturity levels.

Who it applies to

Banks, insurance and financing companies and other entities supervised by the Saudi Central Bank in the Kingdom of Saudi Arabia.

What it requires

  • Assessment against defined maturity levels rather than a binary implemented or not implemented judgement
  • Cyber security governance with clear board accountability
  • Third party and outsourcing risk management
  • Periodic self-assessment and reporting to the supervisor

What preparing for it involves

The maturity model structure rewards evidence of consistent operation over evidence of existence. An organisation that can show a control running the same way every month scores materially better than one that can show the control exists. Preparation therefore concentrates on operational discipline.

How it concludes

A maturity position reported to and examined by the supervisor, revisited periodically.

SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.

Cross-framework reuse

Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.