SAMA Cyber Security Framework
Saudi Central Bank mandatory cybersecurity framework for all financial institutions regulated by SAMA. 4 domains covering cyber security leadership and governance, risk management and compliance, operations and technology, and third-party cyber security. Built on NIST CSF with augmentations from ISO 27001, NIST 800-53, PCI DSS, and SWIFT CSCF.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| 1.1 | Cyber Security Governance | |
| 1.2 | Cyber Security Policy | |
| 1.3 | Compliance with Legal, Regulatory and Industry Standards | |
| 1.4 | Cyber Security in Project Management | |
| 1.5 | Cyber Security Roles and Responsibilities | |
| 1.6 | Cyber Security Awareness and Training | |
| 1.7 | Cyber Security in Human Resources | |
| 1.8 | Cyber Security Risk Management | |
| 1.9 | Cyber Security Review and Audit | |
| 2.1 | Asset Management | |
| 2.2 | Regulatory Compliance and Reporting | |
| 3.1 | Identity and Access Management | |
| 3.2 | Application Security | |
| 3.3 | Infrastructure Security (Networks, Systems, Endpoints) | |
| 3.4 | Cryptography | |
| 3.5 | Secure Configuration and Patch Management | |
| 3.6 | Cyber Security Event and Incident Management | |
| 3.7 | Physical Security | |
| 3.8 | Bring Your Own Device (BYOD) | |
| 3.9 | Secure Disposal of Information Assets | |
| 4.1 | Third Party Risk Management | |
| 4.2 | Outsourcing Cyber Security Requirements | |
| 4.3 | Cloud Computing Security |