Cybersecurity Regulations for Operational Systems

Traffic Light Protocol (TLP):

This protocol is widely used worldwide and there are four colors (traffic signals):

Red – Personal and Confidential for the Recipient Only

The recipient is not entitled to share the classified information marked with red with any individual, whether inside or outside the entity, beyond the specified scope of receipt.

Orange – Limited Sharing

The recipient may share the information within the same entity only with concerned persons, and those who are required to take action related to the information.

Green – Sharing within the Same Community

The recipient may share the information with others within the same entity or another related entity or within the same sector, but it is not permitted to exchange or publish it through public channels.

White – Unlimited

Executive Summary

The tasks and competencies of the National Cybersecurity Authority have been established to address aspects of policy formulation, governance mechanisms, frameworks, standards, regulations, and guidelines related to cybersecurity, and to disseminate them to the relevant entities; thereby enhancing cybersecurity, its importance, and the urgent need for it, amid increasing threats and security risks in the cyber space more than ever before.

The world is witnessing continuous development in operational systems and industrial control systems, accompanied by a continuous increase in cyber threats to these systems. This has demonstrated the need for cybersecurity regulations to address these threats and protect critical infrastructures in light of the best global practices in this field.

Accordingly, the Cybersecurity Controls for Operational Technology Systems document (OTCC-1: 2022) was issued, aiming to reduce cyber risks for the relevant entities. This document clarifies the objectives of the controls, their scope of work, applicability, and compliance mechanism; thus serving as an extension of and complementary to the Basic Cybersecurity Controls (ECC-1:2018). Industrial control systems include all devices, systems, and networks used to operate and/or automate industrial processes.

All entities within the scope of these controls are required to implement measures that ensure continuous and ongoing compliance with these controls, in fulfillment of the provisions of paragraph three of Article Ten of the National Cybersecurity Authority Statute, as well as the provisions of the Royal Order No. (57231) dated 10/11/1439 AH.

Introduction

The National Cybersecurity Authority (referred to in this document as the "Authority") has issued these regulations after studying several cybersecurity standards, frameworks, and regulations prepared by local and international organizations and entities. It has also reviewed best practices and relevant experiences in the field of cybersecurity. A harmonization study was conducted with a number of international standards and regulations.

The cybersecurity regulations for operational systems consist of:

⏺ 4 Main Domains.

⏺ 23 Subdomains.

⏺ 47 Main Controls.

⏺ 122 Subcontrols.

Objectives

These regulations aim to contribute to raising the levels of cybersecurity at the national level by focusing on industrial control systems, defining the cybersecurity requirements for them, and contributing to enabling the relevant entities to work on achieving these requirements to meet security needs, protect critical infrastructures, and enhance their readiness against cyber risks.

These regulations take into account the four fundamental pillars on which cybersecurity relies, which are:

⏺ Strategy.

⏺ People.

⏺ Process.

⏺ Technology.

Scope of Work and Applicability

Scope of the Regulations

These regulations apply to industrial control systems existing in sensitive facilities – according to the standards mentioned in the document – by the owning, operating, or hosting entities of these facilities, whether they are governmental entities (including ministries, authorities, institutions, and others) or private sector entities that own or operate sensitive national infrastructures ("CNIs" CRITICAL NATIONAL INFRASTRUCTURES), or host them within the Kingdom of Saudi Arabia; or outside it, (all of which are referred to in this document as the "Entity"). Sensitive facilities are defined as facilities whose disruption or unauthorized alteration of their systems has a negative impact on the availability of services, the operations of the public entity, or causes significant economic, security, or social adverse effects at the national level. Industrial control systems include all devices, systems, and networks used to operate or automate industrial processes.

The Authority also strongly encourages other entities in the Kingdom to benefit from these regulations to apply best practices regarding raising and developing the level of cybersecurity within the entity.

Execution and Obligation

Assessment and Compliance Measurement Tool

The Authority issues the tool (OTCC-1:2022 ASSESSMENT AND COMPLIANCE TOOL) to regulate the process of assessing the extent of entities' compliance with the cybersecurity regulations for operational systems.

Tool for Inventory and Determination of Facility Level

The Authority issues the tool (OTCC-1:2022 FACILITY LEVEL IDENTIFICATION TOOL) to regulate the process of inventory and identification of sensitive facility levels, which include industrial control systems.

Next section title

Next section content