This is an earlier version ofSaudi Framework for Cybersecurity Cadres (SIOF) - 2020Switch to the new version

Saudi Framework for Cybersecurity Cadres (SIOF) - 2020

Traffic Light Protocol (TLP):

The Light Signal Protocol system was established to share the maximum amount of sensitive information and is widely used worldwide. There are four colors (light signals):

Red – Personal and confidential for the recipient only

The recipient is not entitled to share the classified information marked with the red signal with any individual, whether inside or outside the facility, beyond the specified scope of receipt.

Orange – Limited sharing

The recipient with the orange signal can share the information within the same facility only with concerned persons and those required to take action related to the information.

Green – Sharing within the same community

Where you can share it with others from your facility or another facility related to you or within the same sector, and it is not allowed to exchange or publish it through public channels.

White – Unlimited

1. Introduction

The National Cybersecurity Authority works to protect the Kingdom's cyberspace. This requires qualified national cadres in the field of cybersecurity, capable of carrying out all cybersecurity tasks. Pursuant to the Royal Order No. 6801, dated 11/2/1439 AH, the competencies of the National Cybersecurity Authority include building specialized national capacities in the fields of cybersecurity, participating in the preparation of its educational and training programs, preparing professional standards and frameworks, and developing and implementing related professional standard measurements and tests. Therefore, the National Cybersecurity Authority developed the Saudi Cybersecurity Workforce Framework (Siyouf) to serve as a fundamental reference in this regard.

1-1 Overview

The Saudi Framework for Cybersecurity Cadres classifies the work of cybersecurity personnel in the Kingdom of Saudi Arabia, defines the job roles for each category, and describes the requirements for each job role in terms of tasks, knowledge, skills, and abilities.

The main objective of this framework is to provide a reference guide for preparing, developing, attracting, and managing cybersecurity cadres. The framework offers a unified reference to improve communication and develop content in the activities of qualifying and managing cadres. It also helps link the learning outcomes of education and training programs with the knowledge, skills, and abilities required for various job roles in the field of cybersecurity.

The Authority recommends that all entities adopt and use this framework to ensure alignment with national frameworks and guidelines in this field. This does not prevent each entity from making some modifications and additions to adapt this framework to its functional needs without compromising the basic structure of the framework.

Since the field of cybersecurity is constantly changing and evolving, the contents of this framework will be reviewed and updated periodically.

1-2 Methodology and Structure

The Saudi Cybersecurity Workforce Framework has been developed in accordance with the Cybersecurity Workforce Framework methodology of the National Initiative for Cybersecurity Education (NICE), issued by the U.S. National Institute of Standards and Technology (NIST). This framework organizes cybersecurity work hierarchically, consisting of categories, specialty areas, and work roles. It is important to note that the categories, specialty areas, and work roles included in the Saudi Cybersecurity Workforce Framework differ from those in the NICE Cybersecurity Workforce Framework, as they are designed to meet the needs of cybersecurity personnel in the Kingdom of Saudi Arabia. The following is a definition of the components of this framework’s structure.

• Work Role: A set of cybersecurity tasks required to be performed in a specific cybersecurity job. The work role is defined by a set of tasks to be performed within the context of that work role, as well as a list of knowledge, skills, and abilities necessary to perform those tasks. "Annex A" contains a list of all work roles in the Saudi Cybersecurity Workforce Framework.

• Specialty Area: A group of work roles that serve a specific function within the cybersecurity field and share the required tasks, knowledge, skills, and abilities.

• Category: A group of specialty areas that serve a number of related cybersecurity functions.

This framework is limited to work roles related to cybersecurity. There are other work roles outside the scope of cybersecurity work roles that include some cybersecurity responsibilities or require some cybersecurity-specific knowledge, skills, and abilities. Most of these work roles relate to the field of information technology and are outside the scope of this framework. It is assumed that all employees and beneficiaries of information technology services possess an appropriate level of awareness of cybersecurity risks and best practices.

(Figure 1) illustrates the structure of the Saudi Cybersecurity Workforce Framework.

(Figure 1): Structure of the Saudi Cybersecurity Workforce Framework

2. Classification of the Saudi Framework for Cybersecurity Personnel

2-1 Functional Roles in the Cybersecurity Architecture and Research and Development Category (CARD)

(Table 3) describes the functional roles in the Cybersecurity Architecture and Research & Development category.

(Table 3): Functional Roles in the Cybersecurity Architecture and Research & Development Category (CARD)

| No. | Specialization Field | Functional Role | Role Identifier | Description |
| 1 | Cybersecurity Architecture (CA) | Cybersecurity Architecture Designer | CARD-CA-001 | Designing cybersecurity systems and networks, supervising their configuration, development, and implementation. |
| 2 | Secure Cloud Computing Specialist | CARD-CA-002 | Designing, implementing, and operating secure cloud computing systems, along with developing secure cloud policies. | |
| 3 | Cybersecurity Research & Development (CRD) | Systems Security Development Specialist | CARD-CRD-001 | Designing, developing, testing, and evaluating information systems security at all stages of system development. |
| 4 | Cybersecurity Developer | CARD-CRD-002 | Developing cybersecurity software, applications, systems, and products. | |
| 5 | Secure Software Assessor | CARD-CRD-003 | Assessing the security of computer applications, software, codes, or programs, providing actionable results. | |
| 6 | Cybersecurity Researcher | CARD-CRD-004 | Conducting scientific research in the field of cybersecurity. | |
| 7 | Cybersecurity Data Science Specialist | CARD-CRD-005 | Using mathematical models, methodologies, and scientific processes to design and implement algorithms and systems to extract cybersecurity insights and knowledge from multiple sources for large-scale datasets. | |
| 8 | | Cybersecurity Artificial Intelligence Specialist | CARD-CRD-006 | Using artificial intelligence models and techniques (including machine learning methods) to design and implement algorithms and systems to automate and enhance the efficiency and effectiveness of cybersecurity tasks. |

2-2 Functional Roles in the Leadership and Workforce Development (LWD) Category

(Table 4) describes the functional roles in the Leadership and Workforce Development category.

(Table 4): Functional Roles in the Leadership and Workforce Development Category (LWD)

| No. | Specialization Field | Functional Role | Role Identifier | Description |
| 9 | Leadership (L) 
 
  | Head of Cybersecurity Department  | LWD-L-001 | Managing cybersecurity operations within the organization, setting the vision and direction regarding cybersecurity, related strategies, resources, and activities, and providing insights to the organization's leadership on effective management approaches for the organization's cybersecurity risks.  |
| 10 | Cybersecurity Manager  | LWD-L-002 | Managing cybersecurity for functions and information systems within the organization, and leading cybersecurity at the team, unit, or institutional function level.  | |
| 11 | Cybersecurity Consultant  | LWD-L-003 | Providing opinions and advice to the organization's leadership and cybersecurity leaders and teams on cybersecurity topics.  | |
| 12 | Workforce Development (WD) 
 
  | Cybersecurity Human Resources Manager  | LWD-WD-001 | Developing plans, strategies, and guidelines within the organization to support the development and management of cybersecurity workforce.  |
| 13 | Cybersecurity Curriculum Developer  | LWD-WD-002 | Developing, planning, coordinating, and evaluating cybersecurity education and training programs, curricula, contents, methods, and delivery approaches according to educational needs.  | |
| 14 | Cybersecurity Trainer  | LWD-WD-003 | Teaching, training, developing, and testing individuals in cybersecurity topics. | |

2-3 Functional Roles in the Governance, Risk, Compliance, and Legal (GRCL) Category

(Table 5) describes the functional roles in the Governance, Risk, Compliance, and Legal category.

(Table 5): Functional Roles in the Governance, Risk, Compliance, and Legal (GRCL) Category

| No. | Specialization Area | Functional Role | Role Identifier | Description |
| 15 | Governance, Risk, and Compliance (GRC) 
 
 
 
  | Cybersecurity Risk Specialist  | GRCL-GRC-001 | Identifying, assessing, and managing the organization's cybersecurity risks to protect its informational and technological assets in accordance with the organization's policies and procedures, as well as relevant laws and regulations.  |
| 16 | Cybersecurity Compliance Specialist  | GRCL-GRC-002 | Ensuring the organization's cybersecurity program complies with applicable requirements, policies, and standards.  | |
| 17 | Cybersecurity Policy Specialist  | GRCL-GRC-003 | Developing and updating cybersecurity policies to support and align with the organization's cybersecurity requirements.  | |
| 18 | Cybersecurity Controls Assessor  | GRCL-GRC-004 | Analyzing cybersecurity controls and evaluating their effectiveness.  | |
| 19 | Cybersecurity Auditor  | GRCL-GRC-005 | Designing, executing, and managing cybersecurity audit processes to assess the organization's compliance with applicable requirements, policies, standards, and controls, and preparing and presenting audit reports to authorized parties.  | |
| 20 | Legal and Data Protection (LDP) 
  | Cybersecurity Legal Specialist  | GRCL-LDP-001 | Providing legal services related to cybersecurity laws and regulations.  |
| 21 | Privacy and Data Protection Specialist  | GRCL-LDP-002 | Studying the structure of personal data and applicable privacy laws and regulations, analyzing privacy risks, developing the organization's program to align with privacy and data protection controls and internal policies, supervising their implementation, and supporting the organization's response to privacy or data protection incidents. | |

2-5 Functional Roles in the Industrial Control Systems and Operational Technologies (OT/ICS) Category

(Table 7) describes the functional roles in the Industrial Control Systems and Operational Technologies category.

(Table 7): Functional Roles in the Industrial Control Systems and Operational Technologies (OT/ICS) Category

| No. | Specialization Field | Functional Role | Role Identifier | Description |
| 36 | Industrial Control Systems and Operational Technologies (OT/ICS) | Cybersecurity Architecture Designer for Industrial Control Systems and Operational Technologies | ICSOT- ICSOT-001 | Designing cybersecurity systems and networks in the Industrial Control Systems and Operational Technologies environment, supervising their configuration, development, and implementation. |
| 37 | Cybersecurity Infrastructure Specialist for Industrial Control Systems and Operational Technologies | ICSOT- ICSOT-002 | Inspecting, installing, and maintaining hardware and software used to defend and protect systems and networks from cyber threats in the Industrial Control Systems and Operational Technologies environment, operating and supervising them. | |
| 38 | Cybersecurity Defense Analyst for Industrial Control Systems and Operational Technologies | ICSOT- ICSOT-003 | Utilizing data collected from a variety of cybersecurity tools to analyze incidents occurring in the Industrial Control Systems and Operational Technologies environment to detect and respond to cybersecurity threats. | |
| 39 | Cybersecurity Risk Specialist for Industrial Control Systems and Operational Technologies | ICSOT- ICSOT-004 | Identifying, assessing, and managing cybersecurity risks in the Industrial Control Systems and Operational Technologies environment, evaluating and analyzing the effectiveness of existing cybersecurity controls, and providing feedback and recommendations based on those assessments. | |
| 40 | Cybersecurity Incident Response Specialist for Industrial Control Systems and Operational Technologies | ICSOT- ICSOT-005 | Managing, analyzing, and responding to cybersecurity incidents in the Industrial Control Systems and Operational Technologies environment. | |

Next section title

Next section content