Cybersecurity Regulations for Data

Traffic Light Protocol (TLP):

  • Traffic Light Protocol (TLP):

    • This marking protocol is widely used around the world. It has four colors (traffic lights):

    • Red – Personal, Confidential, and for the Intended Recipient only

      • The recipient has no rights to share information classified in red with any person outside the defined range of recipients, either inside or outside the organization, beyond the scope specified for receipt.

    • Amber – Restricted Sharing

      • The recipient may share information classified in amber only with intended recipients inside the organization and with recipients who are required to take action related to the shared information.

    • Green – Sharing within the Same Community

      • The recipient may share information classified in green with other recipients inside the organization or outside it within the same sector or related to the organization. However, it is not allowed to exchange or publish this information on public channels.

    • White – No Restrictions

      • Document Classification: Public

Executive Summary

  • The Kingdom of Saudi Arabia’s vision 2030 aims to achieve a number of economic, development and security goals, thereby enhancing the performance of national organizations, and encouraging the diversification of the economy and the use of data-based services. National data is one of the most important assets contributing to the success of the strategic goals of Vision 2030 through decision support and is an economic resource to support competitiveness at the national level, where national organizations collect and process vast amounts of data that may be vulnerable to cyber threats and risks that negatively impact national security, the Kingdom’s economy, reputation, external relations, or critical infrastructures, which raises the urgency to put cybersecurity requirements to protect against such threats and risks.

  • The NCA’s mandate as per the Royal Decree number 6801, dated 11/2/1439H, makes NCA the cybersecurity regulator in the Kingdom and the national reference for anything related to cybersecurity. NCA’s mandate and duties fulfill the strategic and regulatory cybersecurity needs related to the development of cybersecurity national policies, governance mechanisms, frameworks, standards, controls and guidelines. The NCA’s mandate and duties also fulfill the need to continuously monitor the compliance of organizations to support the important role of cybersecurity, which has increased with the rise of security risks in cyberspace more than any time before. NCA’s mandate states that its responsibility for cybersecurity does not absolve any government, private or other organization from its own cybersecurity responsibilities as confirmed by Royal Decree number 57231, dated 10/11/1439H, which states that “all government organizations must improve their cybersecurity level to protect their networks, systems and data, and comply with NCA’s policies, framework, standards, controls and guidelines”. In order to reach a secure and reliable Saudi cyberspace that enables growth and prosperity and in addition to the Essential Cybersecurity Controls (ECC-1: 2018), NCA has developed Data Cybersecurity Controls (DCC-1: 2022) to set the minimum cybersecurity requirements to enable organizations to protect their data during its entire data lifecycle. This document highlights the details of the Data Cybersecurity Controls (DCC), objectives, scope of work, compliance and monitoring.

  • All organizations within the scope of these controls must implement all necessary measures to ensure continuous compliance with the DCC as per item 3 of article 10 of NCA’s mandate and as per the Royal Decree number 57231, dated 10/11/1439H.


Introduction

  • The National Cybersecurity Authority (referred to in this document, as "NCA") developed the Data Cybersecurity Controls (DCC-1: 2022) after conducting a comprehensive study of multiple national and international cybersecurity standards, frameworks and controls, studying related laws and regulations, reviewing cybersecurity best practices and analyzing cybersecurity risks, threats, previous incidents and attacks at the national level. These controls support organizations to counter the ever-increasing cybersecurity threats and minimize the negative impacts in order to protect the vital interests of the kingdom, national security, critical infrastructures, high priority sectors and governmental services and activities.

  • While developing the Data Cybersecurity Controls, the NCA carefully aligned the controls with the Essential Cybersecurity Controls (ECC-1: 2018), which are pre-request for compliance for organizations. Compliance with DCC cannot be achieved without achieving continuous compliance with ECC, where applicable as they are linked to relevant national legislative and regulatory requirements. Thus, based on the regulatory tools issued by the Saudi Data and Artificial Intelligence Authority (SDAIA), data is classified into four levels based on its sensitivity and protection needs, which are: Public, Confidential, Secret, and Top Secret.

  • The Data Cybersecurity Controls consist of the following:

    • 3 Main Domains.

    • 11 Subdomains.

    • 19 Main Controls

    • 47 Subcontrols

Objectives

  • The main objectives of the DCC are to:

    • Raise the level of cybersecurity in order to protect national data.

    • Support organizations’ cybersecurity throughout the data lifecycle in order to protect their data and information assets from cybersecurity threats and risks.

    • Raise the level of awareness on handling data securely.


Scope of Work and Applicability

DCC Statement of Applicability

  • These controls have been developed after taking into consideration the cybersecurity needs of organizations and sectors in the kingdom. Every organization within the scope of these controls must comply with all applicable controls in this document.

Implementation and Compliance

  • In order to comply with item 3 of article 10 of NCA’s mandate and as per the Royal Decree number (57231) dated 10/11/1439H, all organizations within the scope of these controls must implement whatever necessary to ensure continuous compliance with the controls, which cannot be achieved without achieving continuous compliance with the Essential Cybersecurity Controls (ECC – 1: 2018) where applicable.

  • NCA evaluates organizations’ compliance with the DCC through multiple means such as self-assessments by the organizations, and/or external assessments, in accordance with the mechanisms deemed appropriate by NCA.


Update and Review

  • NCA will periodically review and update (as needed) the DCC as per the cybersecurity requirements and related industry updates.


DCC Domains and Structure

Next section title

Next section content