Telework Cybersecurity Controls

Traffic Light Protocol (TLP):

This protocol is widely used worldwide and there are four colors (traffic signals):

Red – Personal and Confidential for the Recipient Only

The recipient is not entitled to share the classified information marked with the red signal with any individual, whether inside or outside the entity, beyond the specified scope of receipt.

Orange – Limited Sharing

The recipient may share the information within the same entity only with concerned persons and those who are required to take action related to the information.

Green – Sharing within the Same Community

The recipient may share the information with others within the same entity or another related entity or within the same sector, but it is not permitted to exchange or publish it through public channels.

White – Unlimited

Executive Summary

  • With the continuous technical advancements that coincide with developments in the workforce market, flexible technical options are available to enable a remote work environment. This technology enables employees to perform many functions and tasks without the need to be physically present in the workplace. This contributes to promoting economic development and new job opportunities, as well as increasing productivity and performance. There is no doubt that the increasing dependence of some entities on telework increases threats and cyber risks to telework systems, which requires setting cybersecurity requirements to reduce these threats and risks.

  • Under the Royal Decree number 6801, dated 11/2/1439 H, The National Cybersecurity Authority has become the sole authority in the Kingdom of Saudi Arabia for cybersecurity, and the National Reference in its affairs. These include development, update and dissemination of policies, governance mechanisms, frameworks, cybersecurity standards, controls and guidelines to national organisations as well as monierting their compliance. Thereby enhancing the role of cybersecurity and its importance; and the urgent need for it that has increased with the rapid increase of threats and cyber risks more than Ever.

  • NCA’s mandate states that its responsibility for cybersecurity does not absolve any public, private or other organization from its own cybersecurity responsibilities as confirmed by the Royal Decree number 57231, dated 10/11/1439 H, which states that “all government organizations must improve their cybersecurity level to protect their networks, systems and data, and comply with NCA’s policies, framework, standards, controls and guidelines”

  • From this national perspective towards teleworking, with the purpose to achieve a secure and reliable Saudi cyber space enabling growth and prosperity, the NCA developed the Telework Cybersecurity Controls (TCC-1: 2021) to set the minimum cybersecurity requirements to enable national organizations to perform telework in a secure manner, in addition to the Essential Cybersecurity Controls (ECC1:2018). This document highlights the details of these controls, goals, scope, statement of applicability, compliance approach and monitoring, taking into consideration, Critical Systems Cybersecurity Controls (CSCC – 1:2019) in cases where critical systems are used in telework.

  • All national organizations must implement all necessary measures to ensure continuous compliance with the TCC as per item 3 of article 10 of NCA’s mandate and as per the Royal Decree number 57231, dated 10/11/1439H.

Introduction

  • In today’s world, the work environment is witnessing many changes due to the impact of modern technologies. The acceleration of emerging technologies such as artificial intelligence and virtual reality are increasing the partnership between man and technology. Among other things, this convergence is leading to the further development of the concept of telework that is significantly reducing the links between geography and the actual work being performed.

  • Because of these changes, the Kingdom has started to move towards enhancing flexibility in work-place to enable business to perform remotely to achieve a number of economic, development and security goals in accordance with the Kingdom’s Vision 2030. This type of telework requires the presence of cybersecurity controls that are aimed at helping businesses and consumers avoid and mitigate cyber threats and to resolved them with minimal impact on the vital interests of the state, its national security, sensitive infrastructure, priority sectors, government services and activities.

  • The National Cybersecurity Authority (referred to in this document as “The Authority” or “NCA”) developed the Telework Cybersecurity Controls (TCC – 1: 2021) after:

    • • Conducting a comprehensive study of multiple national and international cybersecurity frameworks and standards.

    • • Studying related national decisions, law and regulatory requirements.

    • • Reviewing and leveraging cybersecurity best practices.

    • • Analyzing previous cybersecurity incidents and attacks on government and other critical organizations.

    • • Surveying and considering opinions of multiple national organizations

  • The NCA has aligned the TCC with the ECC. Compliance with the ECC is a prerequisite for the TCC. Continuous compliance with both is required to be compliant with the relevant national, international and legislative, regulatory requirements. The Telework Cybersecurity Controls consist of the following:

    • • 3 Main Domains

    • • 16 Subdomains

    • • 21 Main Controls

    • • 42 Subcontrols

Objectives

  • he Telework Cybersecurity Controls aim to:

    • • Enabling an organization’s work to be performed remotely in a secure manner and adapt to the changes in the business environment and in telework systems.

    • • Enhancing the organization’s cybersecurity capabilities and resilience in cases where telework is exposed to cyber threats that could result in negative impacts and costly losses.

    • • Contributing to raising the level of cybersecurity at the national level.

Scope of Work and Applicability

TCC Scope of Work

  • These controls are applicable to government organizations in the Kingdom of Saudi Arabia including ministries, authorities, establishments and others and companies and entities, as well as private sector organizations owning, operating or hosting Critical National Infrastructure (CNIs), which are all referred to herein as “The Organization”.

  • The NCA strongly encourages all other organizations in the Kingdom to leverage these controls to implement these best practices to improve and enhance their cybersecurity.

TCC Scope of Work

  • These controls have been developed after taking into consideration the cybersecurity needs of all organizations and sectors in the Kingdom of Saudi Arabia. Every organization that allows telework must comply with all applicable controls in this document.

  • Applicability to implement these cybersecurity controls depends on the organization’s business and its use of certain technologies. For example:

    • • Controls in subdomain 3-1 (Cloud Computing and Hosting Cybersecurity) are applicable and must be implemented by organizations currently using or planning to use cloud computing and hosting services.

Implementation and Compliance

  • To comply with item 3 of article 10 of NCA’s mandate and as per the Royal Decree number 57231 dated 10/11/1439H, all organizations within the scope of these controls must implement whatever is necessary to ensure continuous compliance with the controls. This can only be accomplished by achieving continuous compliance with the ECC (ECC – 1:2018) where applicable.

  • NCA evaluates organizations’ compliance with the TCC through multiple means such as selfassessments by the organizations, and/or External Compliance Assessment.

Update and Review

  • NCA will periodically review and update the TCC as per the cybersecurity requirements and related industry updates. NCA will communicate and publish the updated version of TCC for implementation and compliance.

TCC Domains and Structure

Next section title

Next section content