The National Framework for Cybersecurity Risk Management

Traffic Light Protocol (TLP)

This protocol is widely used worldwide and there are four colors (traffic signals):

Red (Personal and Confidential to the Recipient Only)

The recipient is not entitled to share the classified information marked with the red signal with any individual, whether inside or outside the entity; outside the specified scope of receipt.

Orange + Emphasized (Sharing Within the Same Entity)

The recipient may share the information within the same entity only with the concerned persons.

Orange (Limited Sharing)

The recipient may share the information within the same entity only with the concerned persons and those who are required to take action related to the information.

Green (Sharing Within the Same Community)

The recipient may share the information with others within the same entity, or with another related entity or within the same sector; exchange or dissemination through public channels is not permitted.

Transparent (Unlimited)

1. Introduction

The National Cybersecurity Authority, pursuant to its statute issued by the Royal Order No. (6801) dated 11/2/1439 AH, is the competent authority in the Kingdom for cybersecurity and the national reference in its affairs. It aims to enhance cybersecurity to protect the vital interests of the state, its national security, critical infrastructure, priority sectors, services, and governmental activities. The Authority’s competencies and tasks include, without limitation, setting policies, governance mechanisms, frameworks, standards, regulations, and guidelines related to cybersecurity, disseminating them to relevant entities, monitoring compliance, and updating them. Additionally, it involves establishing cybersecurity risk management frameworks, monitoring compliance, and updating them.

Accordingly, the Authority has prepared this framework, which serves as a reference and methodology for managing cybersecurity risks in the Kingdom under the supervision of the Authority. This framework provides a clear vision for managing cybersecurity risks at the entity level and at the national level. It primarily outlines the methodology for managing cybersecurity risks, in addition to the related roles, responsibilities, and procedures that enhance the capabilities of cybersecurity risk management in the Kingdom.

2. Definitions

3. Objectives of the Framework

  • This framework aims to effectively manage cybersecurity risks, thereby forming the cornerstone of a unified, integrated, comprehensive, and aligned system capable of identifying, analyzing, addressing, and monitoring cybersecurity risks.

  • The following factors contribute to achieving this goal:

    • • Identifying cybersecurity risks that are prioritized for handling.
    • • Enhancing the resilience of national cybersecurity; through the application of necessary controls to reduce cybersecurity risks.
    • • Defining the roles and responsibilities of cybersecurity risk management.
    • • Promoting a culture of cybersecurity risk management within entities.
    • • Effectively managing cybersecurity risks; enabling entities to perform their functions and fulfill their roles and responsibilities across various fields and sectors.

4. Scope of Application of the Framework

  • This framework applies to government entities in the Kingdom of Saudi Arabia (including ministries, authorities, institutions, and others) and their affiliated entities and companies (inside and outside the Kingdom), as well as private sector entities that own, operate, or host Critical National Infrastructure (CNI) (all of which are collectively referred to in this document as the "Entity"). The Authority also strongly encourages other entities in the Kingdom to benefit from this framework to implement best practices regarding cybersecurity risk management and to enhance and elevate cybersecurity at the national level.

5. Responsibilities in Managing Cybersecurity Risks at the National Level

  • Each entity within the scope of this framework must comply with the following:

    • 5.1 Designate a liaison officer with the Authority, responsible for managing cybersecurity risks; to activate this framework, its requirements, and its current and future obligations.
    • 5.2 Inventory the entity's assets such as (sensitive systems, facilities and operational systems, social media accounts, and others) and classify them, in accordance with what is issued by the Authority, and then periodically review the classification.
    • 5.3 Inventory the entity's internet-facing assets.
    • 5.4 Submit to the Authority the assets identified in paragraphs 5.2 and 5.3 periodically according to the specified period, and update them upon any change, through Hesin or any other channel determined by the Authority.
    • 5.5 Report to the Authority cybersecurity risks of catastrophic level (5) and high level (4) within the entity, immediately upon identification; according to the cybersecurity risk assessment matrix in Figure (2), and share cybersecurity risk mitigation plans periodically, upon updating them, or upon any change, through Hesin or any other channel determined by the Authority.
    • 5.6 Address the cybersecurity risks, vulnerabilities, and observations received from the Authority, provide feedback on the actions taken, and report on what has been addressed periodically according to the specified period, and update upon any change, through Hesin or any other channel, in accordance with what is issued by the Authority.

6. Responsibilities in Cybersecurity Risk Management at the Entity Level

Each entity within the scope of this framework must adhere to the cybersecurity risk management methodology and the cybersecurity risk assessment matrix, as stipulated in this section of the framework.

Cybersecurity Risk Management Methodology

  • The cybersecurity risk management methodology works on identifying inherent cybersecurity risks, assessing impact and likelihood, and determining plans to address these risks, so that decisions on how to handle them are made accordingly. Assets, cybersecurity vulnerabilities, cybersecurity threats, and controls are used as potential inputs to understand cybersecurity risks within this methodology.

  • The stages illustrated in Figure (1) below constitute the main stages in the cybersecurity risk management methodology. Each stage also includes several tasks to enhance vision, understanding, and action within the cybersecurity risk management methodology.

  • Figure 1: Main Stages of the Cybersecurity Risk Management Methodology

  • To apply this methodology sustainably, the following must be done:

    • 6.1 Develop and continuously activate a program for the cybersecurity risk management methodology and operate it; with allocation of the necessary resources.
    • 6.2 Engage stakeholders at various stages; such as the Cybersecurity Supervisory Committee and the Information Technology Department.

Evaluation Stage

  • At this stage, cybersecurity risk assessment is conducted according to the expected cybersecurity risk scenarios; through studying the likelihood and impact. This stage consists of the following steps:

    • 6.9 Conducting an analysis of inherent risks in cybersecurity, for all expected cybersecurity risk scenarios, the currently applied controls, and assessing the likelihood and impact; according to the cybersecurity risk assessment matrix in Figure (2).
    • 6.10 Documenting the analysis and assessment results in the cybersecurity risk register.

Next section title

Next section content