The Kingdom of Saudi Arabia’s vision 2030 aims to achieve a number of economic, development and security goals, thereby enhancing the performance of national organizations, and encouraging the diversification of the economy and the use of data-based services. National data is one of the most important assets contributing to the success of the strategic goals of Vision 2030 through decision support and is an economic resource to support competitiveness at the national level, where national organizations collect and process vast amounts of data that may be vulnerable to cyber threats and risks that negatively impact national security, the Kingdom’s economy, reputation, external relations, or critical infrastructures, which raises the urgency to put cybersecurity requirements to protect against such threats and risks.
The NCA’s mandate as per the Royal Decree number 6801, dated 11/2/1439H, makes NCA the cybersecurity regulator in the Kingdom and the national reference for anything related to cybersecurity. NCA’s mandate and duties fulfill the strategic and regulatory cybersecurity needs related to the development of cybersecurity national policies, governance mechanisms, frameworks, standards, controls and guidelines. The NCA’s mandate and duties also fulfill the need to continuously monitor the compliance of organizations to support the important role of cybersecurity, which has increased with the rise of security risks in cyberspace more than any time before. NCA’s mandate states that its responsibility for cybersecurity does not absolve any government, private or other organization from its own cybersecurity responsibilities as confirmed by Royal Decree number 57231, dated 10/11/1439H, which states that “all government organizations must improve their cybersecurity level to protect their networks, systems and data, and comply with NCA’s policies, framework, standards, controls and guidelines”. In order to reach a secure and reliable Saudi cyberspace that enables growth and prosperity and in addition to the Essential Cybersecurity Controls (ECC-1: 2018), NCA has developed Data Cybersecurity Controls (DCC-1: 2022) to set the minimum cybersecurity requirements to enable organizations to protect their data during its entire data lifecycle. This document highlights the details of the Data Cybersecurity Controls (DCC), objectives, scope of work, compliance and monitoring.