Quick Contact

Talk to our team

Social

fb-footer
instagram-footer
Twiiter
youtube-footer
linkedin-footer
Blog --------

SAMA Cybersecurity Framework Checklist

Share
sama cybersecurity framework checklist

The Saudi Arabian Monetary Authority was formed in 2017 to strengthen the organizationโ€™s resilience against cyber threats by implementing several security best practices and standards. It applies to all banks, financial institutions, insurance companies, etc.

SAMA Objectives aim to safeguard the following:

  • Electronic data
  • Physical details
  • Electronic devices
  • Applications
  • Computers and other electronic machines
  • Software used by a financial institute
  • Data storage equipment

What are the Maturity Levels as per SAMA?

There are six maturity levels according to SAMA. These are decided based on the existing security-maturity level in the organization. Look at the list below and decide where your organization belongs

  • Level 0 or non-existent:
    • ย No documentation to support the implementation of security controls,
    • No awareness of cybersecurity controls. (no implementation of awareness efforts)
  • Level 1 or Ad-hoc:
    • Null or partial pre-defined security controls
    • Non-standard cybersecurity controls
    • Poorly defined CSC that are incapable of complete risk mitigation
  • Level 2 or Repeatable but Informal
    • Unorganized Cybersecurity controls without formal adherence, frequently repeated controls with little scope to test the controls
    • Overlapping objectives for controls
  • Level 3 or Structured and Formalized
    • Well-defined, completely structured, and formally approved controls
    • Adopted on a large school
    • Implementation of GRC tools
    • Well-defined performance indicators
    • Regularly evaluated controls
  • Level 4 or Managed and Measurable
    • Implemented controls are regularly reviewed to check the efficacy
    • Controls are measured against the latest trends and indicators
    • Reviews and test results are used to make the controls more robust
  • Level 5 or Adaptive
    • Large-scale, enterprise-wide adoption of cybersecurity measures
    • Continued focus on compliance and CSC efficiency
    • Control effectiveness is measured against peer and sector data

What Are SAMA Control Domains?

The core of SAMA is based on four domains with several further subdomains, with each subdomain focusing on a specific topic. Three key subdomains are:

  • The Principal – The main reason why security control exists
  • The Objective – explains the goals of the principle and what a particular CSC aims to achieve
  • The Control Consideration – the mandatory control that must be considered for specific domains.

The Four levels of Control Consideration are as follows:

Cybersecurity Leadership and Governance

  • The governing body of members or a structured security committee must be responsible for maintaining a robust cybersecurity program
  • They must state the governance standards that are acceptable for cybersecurity review
  • Well-defined cybersecurity standards must be provided for members
  • A cybersecurity policy must be drafted
  • They must discover viable operational practices to improve the effectiveness of the controls
  • An independent cybersecurity function must be present to draft, maintain, and administer the policies implemented

Cybersecurity Risk Management and Compliance

  • Cybersecurity risk mitigation is a continual procedure. The authorities must:
  • Detect threats and risks early or predict them
  • Understand the probabilities of cybersecurity risk
  • Perform risk analysis regularly
  • Draft a viable, result-oriented response
  • Monitor risk treatment and examine the CSC effectiveness regularly
  • Adhere to the defined cybersecurity controls
  • Accurately define, approve, and deploy risk management procedures to protect the confidentiality and integrity of mission-critical details of the organization.
  • It is mandatory to adhere to globally accepted standards and the cybersecurity compliance process must be periodically conducted to update cybersecurity policy.

Cybersecurity Operations and Technology

  • SAMA mandates member institutes to safeguard critical operations and technology of employees, members, and third-party vendors along with their own.
  • Well-defined, thorough controls to ensure that technologies used at work are not introducing threats to the system.
  • Employees must be screened at the outset and appropriate measures must be adopted throughout their lifecycles
  • Ironclad security measures should be adopted to prevent security threats to physical assets
  • Eliminate the possibility of unauthorized access to memberโ€™s physical assets through adequate security controls via advanced monitoring and surveillance technology, environmental protection, protecting data center tools, supervision of data access, and analyzing access control measures.

Third-Party Cybersecurity

This control domain focuses on security control for third-party services. Member institutes are recommended the following controls to ensure security for third-party resources from cybersecurity threats:

  • Incorporate risk evaluation into procurement
  • Have well-defined security requirements
  • Test third-party vendor security controls
  • Follow SAMA regulations if you outsource technology or HR.
  • Get SAMA approval prior to using any cloud service
  • Ensure that the cloud service provider doesnโ€™t use data for personal purposes
  • Conduct cybersecurity audits for cloud providers regularly
  • Allow termination rights to member companies

While financial services entities in Saudi Arabia must adhere to SAMA compliance requirements and the requirements are stringent, itโ€™s not that difficult. Hereโ€™s how you can be compliant:

  • Know where your data is stored, how itโ€™s accessed and shared
  • Arrange and classify data according to priority and risk
  • Use the right data encryption software to protect your data.

A comprehensive data protection program is the best solution for your organization. It may not be possible for you to pull precious resources away from core tasks to focus on data protection. Entrust these activities to a compliance consultancy expert like Wattlecorp, ensure adherence to SAMA Compliance requirements, and continue doing what you do best – serving your customers and growing your business.

As an organization with in-depth expertise in compliance requirements and industry knowledge, Wattlecorp is your key to staying compliant with all required regulations.

Get a Custom SAMA Compliance Implementation Plan

Join 15,000+ Cybersecurity Innovators

Protect. Comply. Lead.

Secure your stack, stay compliant, and outpace threats with concise, fieldโ€‘tested guidance on VAPT, cloud security, and regional privacy laws delivered by Wattlecorpโ€™s
trusted advisors across the globe.

Leave a Comment

Your email address will not be published. Required fields are marked *

mobile application penetration testing qatar Mobile Application Penetration Testing for Qatar Government Digital Services: NCSA-ย Alignedย Securityย Assuranceย 

Key Takeaways: Mobile Application Penetration Testing Qatar must cover the app, device storage, APIs, authentication and third-party components. Qatarโ€™s NCSA assurance environment combines the National Information Assurance (NIA) Standard, the National Information Security Compliance Framework (NISCF) and accredited security assessment services. OWASP MASVS defines mobile security controls, while MASTG supplies practical test methods for Android […]

Read more >>
qatar data protection law Qatar Data Protection Law: Implementing PDPPL Data Subject Rights Processes for Businessesย 

Key Takeaways: The Qatar Data Protection Law (Law No. 13 of 2016) for Personal Data Privacy Protection, grants individuals specific rights such as right to access, correct, erase, object, withdraw consent, and right to be notified of processing or inaccurate disclosure. Beyond having a privacy policy, businesses or controllers, under Article 11 of Personal Data […]

Read more >>
AI governance india AI Governance for Indian Enterprises: Building Internal Controls Beforeย Keyย DPDPย Obligationsย Take Effectย 

Key Takeaways: The DPDP Act does not contain AI-specific provisions. Its requirements, however, apply in situations when an AI system processes digital personal data within its territorial and material scope. India is working on building a broader governance framework around safety, accountability, transparency and trust via programs like the IndiaAI Mission. Indian organizations should inventory […]

Read more >>
cloud security audit uae Cloud Security Audit for UAE Government Cloud Migration: NCAP and Security Requirements

Key Takeaways: A cloud security audit UAE helps government entities identify security, governance, configuration, access, data-protection and resilience gaps, before and after shifting critical workloads to the cloud. UAE National Cloud Security Policy has defined cloud governance, data security, data sovereignty, IAM, incident management, resilience, portability and cloud operations requirements. The National Cyber Accreditation Program […]

Read more >>
Data Privacy Consulting UAEย โ€“ย Building a PDPL-Compliant Data Governance Program

Key Takeaways: PDPL compliance requires ongoing operational governance that goes beyond policies to demonstrate how personal data is collected, used, protected, transferred, retained, and deleted. Data mapping helps businesses move from reactive compliance to proactive risk management by establishing a comprehensive inventory of the data ecosystem, helping build a mature data privacy and governance program. […]

Read more >>
critical systems cybersecurity controls Saudi Arabia’s Critical Systems Controls: What CSP-Linked Enterprises Must Comply With in 2026

Key Takeaways: The Critical Systems Cybersecurity Controls (CSCC) are more applicable to critical systems than to all IT assets owned or operated by an organization. To be in full compliance or to remain in full compliance with CSCC, organizations must maintain continuous adherence to NCA ECC. CSCC has 32 core controls and 73 sub-controls across […]

Read more >>