← Frameworks / Financial Regulation

SAMA Cyber Security Framework

Saudi Central Bank mandatory cybersecurity framework for all financial institutions regulated by SAMA. 4 domains covering cyber security leadership and governance, risk management and compliance, operations and technology, and third-party cyber security. Built on NIST CSF with augmentations from ISO 27001, NIST 800-53, PCI DSS, and SWIFT CSCF.

Clause Title SP 800-53 Controls
1.1 Cyber Security Governance
1.2 Cyber Security Policy
1.3 Compliance with Legal, Regulatory and Industry Standards
1.4 Cyber Security in Project Management
1.5 Cyber Security Roles and Responsibilities
1.6 Cyber Security Awareness and Training
1.7 Cyber Security in Human Resources
1.8 Cyber Security Risk Management
1.9 Cyber Security Review and Audit
2.1 Asset Management
2.2 Regulatory Compliance and Reporting
3.1 Identity and Access Management
3.2 Application Security
3.3 Infrastructure Security (Networks, Systems, Endpoints)
3.4 Cryptography
3.5 Secure Configuration and Patch Management
3.6 Cyber Security Event and Incident Management
3.7 Physical Security
3.8 Bring Your Own Device (BYOD)
3.9 Secure Disposal of Information Assets
4.1 Third Party Risk Management
4.2 Outsourcing Cyber Security Requirements
4.3 Cloud Computing Security