The Saudi Framework for Cybersecurity Cadres (SIOF)

Traffic Light Protocol (TLP)

This protocol is widely used worldwide and there are four colors (traffic signals):

Red (Personal and Confidential to the Recipient Only)

The recipient is not entitled to share the classified information marked with the red signal with any individual, whether inside or outside the entity; outside the specified scope of receipt.

Orange + Emphasized (Sharing within the Same Entity)

The recipient may share the information within the same entity only with the concerned persons.

Orange (Limited Sharing)

The recipient may share the information within the same entity only with the concerned persons and those who are required to take action related to the information.

Green (Sharing within the Same Community)

The recipient may share the information with others within the same entity, or with another related entity or within the same sector; exchange or dissemination through public channels is not permitted.

Transparent (Unlimited)

1. Introduction

The National Cybersecurity Authority works to protect the Kingdom's cyberspace, which requires qualified national cadres in the field of cybersecurity capable of carrying out all cybersecurity tasks. Pursuant to the Royal Order No. 6801, dated October 31, 2017, which included the competencies of the National Cybersecurity Authority, it stipulated: building specialized national capabilities in the fields of cybersecurity, participating in the preparation of its educational and training programs, preparing professional standards and frameworks, and building and implementing related professional standard measurements and tests. For this reason, the National Cybersecurity Authority developed the Saudi Cybersecurity Workforce Framework (SAYOF) to be a primary reference in this regard.

1.1 Overview

  • The Saudi Framework for Cybersecurity Cadres is concerned with classifying the work of cybersecurity cadres in the Kingdom of Saudi Arabia, defining the job roles for each category, and describing the requirements of each job role in terms of tasks, knowledge, and skills. The main objective of this framework is to provide a reference guide for preparing, developing, attracting, and managing cybersecurity cadres. The framework offers a unified reference to improve communication and develop content in the activities of qualifying and managing cadres. It also helps link the learning outcomes of education and training programs with the knowledge and skills required for the various job roles in the field of cybersecurity.
  • The Authority recommends that all entities adopt and use this framework to ensure the alignment of cadre structures and their activities with the national frameworks and guidelines in this field. This does not prevent each entity from making some modifications and additions to adapt this framework to its functional needs without compromising the basic structure of this framework.
  • Due to the constantly changing and evolving nature of cybersecurity, the contents of this framework will be reviewed and updated periodically.

2.1 Methodology and Structure

  • The Saudi Cybersecurity Workforce Framework has been developed based on the best global practices and robust international standards, enhancing its efficiency and quality in application, and aligning with the needs of cybersecurity personnel in the Kingdom of Saudi Arabia. This framework organizes cybersecurity work hierarchically, consisting of categories, specialty areas, and job roles. Below are definitions of job roles, specialty areas, and categories within the structure of this framework:

    • Job Role: A set of cybersecurity tasks required to be performed in a specific cybersecurity position. The job role is defined through a set of tasks to be performed within the context of this job role, as well as a list of knowledge and skills required for this role. ("Annex A") contains a list of all job roles in the Saudi Cybersecurity Workforce Framework.
    • Specialty Area: A group of job roles that serve a specific function within the cybersecurity field and share the required tasks, knowledge, and skills.
    • Category: A group of specialty areas and their associated job roles that serve a set of related cybersecurity functions.
  • This framework is limited to job roles related to cybersecurity. There are other job roles outside the scope of cybersecurity job roles that include some cybersecurity responsibilities or require some cybersecurity-specific knowledge and skills; most of these job roles relate to the field of information technology and are outside the scope of this framework. It is assumed that all employees and beneficiaries of information technology services possess an appropriate level of awareness of cybersecurity risks and best practices.

  • (Figure 1) illustrates the structure of the Saudi Cybersecurity Workforce Framework.

  • Figure 1: Structure of the Saudi Cybersecurity Workforce Framework

2. Classification of the Saudi Framework for Cybersecurity Personnel

2.2 Tasks, Knowledge, Skills, and Competency Areas in the Saudi Framework for Cybersecurity Personnel

  • The framework defines the essential elements for each job role in terms of tasks, knowledge, and skills:

    • • Task: A set of activities that must be completed as part of a specific job role.
    • • Knowledge: A set of data, facts, information, theories, concepts, and issues related to a particular subject.
    • • Skill: The ability to apply knowledge and use the necessary tools and methods to perform the task.
  • The task, knowledge, and skill data texts in the Saudi Cybersecurity Workforce Framework were prepared based on global best practices and refined to suit the needs of cybersecurity personnel in the Kingdom of Saudi Arabia; "Annex B" contains a complete list of the task, knowledge, and skill data in the Saudi Cybersecurity Workforce Framework.

  • This version of the Saudi Cybersecurity Workforce Framework also presents competency domains to enhance the framework by addressing important cybersecurity areas.

    • • Competency Domain: A set of related knowledge and skills, representing the ability to perform tasks within a specific domain.

    • Competency domains focus on aligning workforce capabilities with real-world challenges, ensuring that organizations and specialists can effectively respond to evolving cybersecurity needs. Competency domains will also help institutions to:

      • • Focus on specialized areas to address unique cybersecurity challenges
      • • Align workforce training programs and qualification certifications with sector requirements
      • • Support career development by providing structured pathways for professional growth
  • Although competency domains enrich the classification of the Saudi Cybersecurity Workforce Framework, it is not necessary for cybersecurity specialists to master all details in every competency domain related to their roles; these domains will serve as a guiding framework to focus on relevant expertise. A detailed description of competency domains and their associated job roles can be found in "Annex C"

Next section title

Next section content