The tasks and competencies of the National Cybersecurity Authority have been established to address aspects of policy formulation, governance mechanisms, frameworks, standards, regulations, and guidelines related to cybersecurity, and to disseminate them to the relevant entities; thereby enhancing cybersecurity, its importance, and the urgent need for it, amid increasing threats and security risks in the cyber space more than ever before.
The world is witnessing continuous development in operational systems and industrial control systems, accompanied by a continuous increase in cyber threats to these systems. This has demonstrated the need for cybersecurity regulations to address these threats and protect critical infrastructures in light of the best global practices in this field.
Accordingly, the Cybersecurity Controls for Operational Technology Systems document (OTCC-1: 2022) was issued, aiming to reduce cyber risks for the relevant entities. This document clarifies the objectives of the controls, their scope of work, applicability, and compliance mechanism; thus serving as an extension of and complementary to the Basic Cybersecurity Controls (ECC-1:2018). Industrial control systems include all devices, systems, and networks used to operate and/or automate industrial processes.
All entities within the scope of these controls are required to implement measures that ensure continuous and ongoing compliance with these controls, in fulfillment of the provisions of paragraph three of Article Ten of the National Cybersecurity Authority Statute, as well as the provisions of the Royal Order No. (57231) dated 10/11/1439 AH.