This is an earlier version ofCybersecurity Regulations for Cloud Computing - 1442Switch to the new version

Cybersecurity Regulations for Cloud Computing - 1442

Traffic Light Protocol (TLP):

The Light Signal Protocol system was established to share the maximum amount of sensitive information and is widely used worldwide. There are four colors (light signals):

Red – Personal and confidential for the recipient only

The recipient is not entitled to share the classified information marked with the red signal with any individual, whether inside or outside the facility, beyond the specified scope of receipt.

Orange – Limited sharing

The recipient of the orange signal may share the information within the same facility only with concerned persons and those required to take action related to the information.

Green – Sharing within the same community

You may share it with others from your facility or another facility related to you or within the same sector, but it is not permitted to exchange or publish it through public channels.

White – Unlimited

1. Executive Summary

The tasks and competencies of the National Cybersecurity Authority have been established to address aspects of policy formulation, governance mechanisms, frameworks, standards, regulations, and guidelines related to cybersecurity, and to disseminate them to the relevant entities. This enhances the role and importance of cybersecurity and the urgent need for it amid increasing threats and security risks in the cyber space more than ever before.

Given that the topic of cloud computing has become more globally prevalent and that its adoption and implementation within the Kingdom are rapidly evolving, new cybersecurity challenges or threats have emerged. These necessitate the existence of cybersecurity regulations to manage cloud computing services in light of the best global practices in this field, serving as an extension of the fundamental cybersecurity regulations (2018:1 - ECC).

Accordingly, the Cybersecurity Controls for Cloud Computing document (2020:1 - CCC) was developed, aiming to reduce cybersecurity risks for service providers and subscribers. This document clarifies the objectives, scope of work, applicability, and the mechanism for compliance with these controls.

Service providers and subscribers must take the necessary measures to ensure continuous and ongoing compliance with these controls, in implementation of the provisions of paragraph three of Article Ten of the National Cybersecurity Authority’s Statute, as well as the provisions of the Royal Decree No. 57231 dated 10/11/1439 AH.

2. Introduction

The National Cybersecurity Authority (hereinafter referred to in this document as "the Authority") has issued the Cybersecurity Controls for Cloud Computing (2020: 1 - CCC) after studying several cybersecurity standards, frameworks, and controls prepared by local and international organizations and entities. Best practices and relevant experiences in the field of cybersecurity were also reviewed. A harmonization study was conducted with a number of international controls and standards, including: the American FedRAMP standard, which contains between 125 and 421 requirements; the Multi-Tier Cloud Security Standard for Singapore (MTCS SS), which contains 535 requirements; the Cloud Computing Compliance Control Catalogue (C5), which contains 114 requirements; the Cloud Controls Matrix (CCM), which contains 133 controls; and the ISO/IEC 27001 standard, which contains 114 controls. The details of this harmonization have been clarified in a special annexed document to the Cybersecurity Controls for Cloud Computing.

Components of Cybersecurity Regulations for Cloud Computing

The Cybersecurity Controls for Cloud Computing consist of the following components:

| For Service Providers | For Subscribers |
| 4 Main Domains | |
| 24 Subdomains | |
| 37 Main Controls | 18 Main Controls |
| 96 Subcontrols | 26 Subcontrols |

Figure 1. Components of Cybersecurity Controls for Cloud Computing

3. Objectives

  • As an extension of the Basic Cybersecurity Controls (2018:1 - ECC); this document has been developed to include Cybersecurity Controls for Cloud Computing (2020:1 - CCC) and to be subordinate and complementary to it.

  • This document aims to achieve higher levels of national cybersecurity objectives by focusing on cloud computing services from the perspective of service providers and subscribers, and by defining the cybersecurity requirements for cloud computing for them, contributing to enabling them to identify the security requirements for cloud computing services and work to achieve them to meet security needs and enhance their readiness against cyber risks across all cloud computing services.

  • Cybersecurity for cloud computing services requires service providers and subscribers to focus on three fundamental cybersecurity principles related to the data and information used by them, which are as follows:

    • ⏺ Confidentiality
    • ⏺ Integrity
    • ⏺ Availability
    • These controls take into account the four main pillars on which cybersecurity is based, which are:
    • ⏺ Strategy
    • ⏺ People
    • ⏺ Procedure
    • ⏺ Technology

4. Scope of Work and Applicability

Scope of the Cybersecurity Regulations for Cloud Computing

Cybersecurity regulations for cloud computing apply to service providers and subscribers, and these regulations represent the minimum cybersecurity requirements for cloud computing.

Service providers refer to any service provider offering cloud computing services to subscribers within the scope of work. Subscribers refer to any government entity in the Kingdom of Saudi Arabia, inside or outside the Kingdom (including ministries, authorities, institutions, and others), their affiliated entities and companies, and private sector entities that own, operate, or host sensitive national infrastructure, who currently use or plan to use any cloud computing services.

The Authority strongly encourages other entities in the Kingdom to benefit from these regulations to implement best practices regarding the enhancement and development of cybersecurity for cloud computing.

Examples of Cloud Service Providers Outside the Scope of Work

⏺ Service providers who offer cloud computing services to non-Saudi entities outside the Kingdom and do not provide services to subscribers within the scope of work.

⏺ Service providers who offer cloud computing services to individuals and private sector entities that do not own or operate sensitive national infrastructure or host it, and do not provide services to subscribers within the scope of work.

5. Execution and Obligation

In fulfillment of the provisions of paragraph three of Article Ten of the Authority's Statute, service providers and subscribers within the scope of these regulations must achieve continuous and ongoing compliance with the cybersecurity controls for cloud computing, according to the levels specified in Table No. (2) and Table No. (3) in the section "Annex (A): Levels of Cybersecurity Controls for Cloud Computing" of this document, taking into account the two rules below:

⏺ The controls pertaining to subscribers in this document complement the controls contained in the Basic Cybersecurity Controls document and are an extension thereof; accordingly, subscribers are obligated to continuously and consistently apply all controls contained in both documents.

⏺ The controls pertaining to service providers in this document complement the controls contained in the Basic Cybersecurity Controls document and are an extension thereof; accordingly, service providers, whether inside or outside the scope of the Basic Cybersecurity Controls, are obligated to continuously and consistently apply all controls contained in both documents.

The Authority shall grant a period for service providers and subscribers within the scope of the controls to comply (taking into account service providers and subscribers transitioning from outside to inside the scope) as deemed appropriate by the Authority. The Authority shall also evaluate the compliance of service providers and subscribers with the provisions of this document according to the mechanism it deems appropriate for that purpose, including but not limited to: self-assessment by service providers and subscribers and/or external compliance assessment by the Authority or its delegate.

Next section title

Next section content