← Frameworks / Regulatory

NCA Essential Cybersecurity Controls (ECC-1:2018)

Saudi National Cybersecurity Authority mandatory controls for all government entities, government-affiliated organizations, and critical infrastructure operators. 5 domains: cybersecurity governance, defence, resilience, third-party and cloud computing, and ICS/OT cybersecurity. Designed referencing NIST CSF, NIST 800-53, and ISO 27001.

Clause Title SP 800-53 Controls
1-1 Cybersecurity Strategy
1-2 Cybersecurity Management
1-3 Cybersecurity Policies and Procedures
1-4 Cybersecurity Roles and Responsibilities
1-5 Cybersecurity Risk Management
1-6 Cybersecurity in Information Technology Projects
1-7 Compliance with Cybersecurity Standards, Laws, and Regulations
1-8 Periodical Cybersecurity Review and Audit
1-9 Cybersecurity in Human Resources
1-10 Cybersecurity Awareness and Training Program
1-11 Cybersecurity in Physical Security
2-1 Asset Management
2-2 Identity and Access Management
2-3 Information System and Information Processing Facilities Protection
2-4 Email Protection
2-5 Networks Security Management
2-6 Mobile Devices Security
2-7 Data and Information Protection
2-8 Cryptography
2-9 Backup and Recovery Management
2-10 Vulnerability Management
2-11 Penetration Testing
2-12 Cybersecurity Event Logs and Monitoring Management
2-13 Cybersecurity Incident and Threat Management
2-14 Web Application Security
3-1 Business Continuity Management Aspects of Cybersecurity
3-2 Disaster Recovery Aspects of Cybersecurity
4-1 Third-Party Cybersecurity
4-2 Cloud Computing and Hosting Cybersecurity
5-1 ICS/OT Cybersecurity