Cybersecurity Regulations for Sensitive Systems

Traffic Light Protocol (TLP):

The Light Signal Protocol system was established to share the maximum amount of sensitive information and is widely used worldwide. There are four colors (light signals):

Red – Personal and confidential for the recipient only

The recipient is not entitled to share the classified information marked with the red signal with any individual, whether inside or outside the facility, beyond the specified scope of receipt.

Orange – Limited sharing

The recipient of the orange signal may share the information within the same facility only with concerned persons, and those required to take action related to the information.

Green – Sharing within the same community

You may share it with others from your facility or another facility related to you or within the same sector, and it is not permitted to exchange or publish it through public channels.

White – Unlimited

Executive Summary

Saudi Arabia’s Vision 2030 aimed at the comprehensive development of the nation, its security, economy, the welfare of its citizens, and their dignified living. It was natural that one of its targets would be the transformation towards the digital world and the development of digital infrastructure; reflecting the keeping pace with the rapid global advancement in digital services, in renewed global networks, information technology systems, and operational technology systems. This is to be followed by the growth of computational processing capabilities, massive data storage capacities, and data exchange; preparing for dealing with artificial intelligence data and the transformations of the Fourth Industrial Revolution.

This transformation requires the smooth flow of information, its security, and the integration of its systems. It necessitates maintaining and enhancing the cybersecurity of the Kingdom of Saudi Arabia; protecting the vital interests of the state, its national security, sensitive infrastructures, priority sectors, and government services and activities. Therefore, the establishment of the National Cybersecurity Authority was initiated. Its organization was approved by the Royal Order No. 6801 dated 11/2/1439 AH, designating it as the competent authority in the Kingdom for cybersecurity and the national reference in its affairs.

The tasks and competencies of this Authority were designed to meet strategic aspects, policy formulation, governance mechanisms, frameworks, standards, regulations, and guidelines related to cybersecurity, and to disseminate them to the entities.

They also address aspects of modernization and monitoring compliance by governmental and non-governmental entities; enhancing the role and importance of cybersecurity and its urgent necessity, which has increased with the rise of threats and security risks in cyberspace more than ever before.

The aforementioned organization stipulates that the regulatory role of the Authority does not exempt any public or private entity or others from their responsibility towards their cybersecurity. This was affirmed by the Royal Decree No. 57231 dated 10/11/1439 AH stating that “all governmental entities must raise their cybersecurity level to protect their networks, systems, and electronic data, and comply with the policies, frameworks, standards, regulations, and guidelines issued by the National Cybersecurity Authority in this regard,” as well as by Royal Decree No. 7732 dated 12/2/1440 AH.

On this basis, the National Cybersecurity Authority prepared the Cybersecurity Controls for Sensitive Systems (CSCC - 1: 2019) to set the minimum cybersecurity requirements for sensitive systems in public entities, in addition to the Essential Cybersecurity Controls (ECC - 1: 2018). This document details the cybersecurity controls for sensitive systems, their objectives, scope of work, and the mechanism for compliance and follow-up.

All public entities that own or operate sensitive systems must implement what achieves continuous and ongoing compliance with these controls on sensitive systems; in fulfillment of the provisions of paragraph three of Article Ten in the organization of the National Cybersecurity Authority, as well as the provisions of Royal Decree No. 57231 dated 10/11/1439 AH and Royal Decree No. 7732 dated 12/2/1440 AH.

Introduction

Objectives

Extending the basic cybersecurity regulations; the cybersecurity regulations for sensitive systems aim to enable public entities; develop protection capabilities, resilience against cyberattacks, and preserve informational and technological assets for sensitive systems, based on best practices and international standards; with the objective of meeting current security needs and enhancing the readiness of entities, within the scope of these regulations, in response to the increasing cyber risks to their sensitive systems, which may result in negative impacts and costly losses at the national level.

Definition of Sensitive Systems and Criteria for Their Identification

Definition of Sensitive Systems

They are any systems or networks, whose disruption, unauthorized alteration of their operation, or unauthorized access to them or to the data and information they store or process, leads to a negative impact on the availability of services, the operations of the public entity, or causes significant negative economic, financial, security, or social effects at the national level.

Criteria for Defining Sensitive Systems

  • A system is considered sensitive if its disruption, unlawful alteration of its operation, unauthorized access to it, or to the data and information it stores or processes, directly or indirectly leads to the likelihood of one or more of the following criteria being met (as determined by the system's owning entity):

      1. Negative impact on national security.
      1. Negative impact on the Kingdom's reputation and public image.
      1. Significant financial losses (e.g., more than 0.01% of the national gross domestic product).
      1. Negative impact on services provided to a large number of users (e.g., more than 5% of the population).
      1. Loss of lives.
      1. Unauthorized disclosure of data classified as confidential or highly confidential.
      1. Negative impact on the operations of one or more vital sectors.

Components of Sensitive Systems

  • The approved components for sensitive systems are (components 1 - 8 are technical components):

      1. Network; for example:
      • 1-1 Network-connected devices (Connecting Devices) such as:
        • Router.
        • Switches.
        • Gateways.
      • 1-2 Firewall.
      • 1-3 Intrusion Detection and Prevention Systems (IDS/IPS).
      • 1-4 Advanced Persistent Threat Protection (APT Protection).
      1. Databases.
      1. Storage Assets.
      1. Middleware.
      1. Servers and their Operating Systems.
      1. Applications.
      1. Encryption Devices.
      1. Appurtenances to sensitive systems; for example: printers and scanners.
      1. Personnel working in sensitive systems support roles (such as: users, technical staff, those with significant and sensitive privileges, operators, service providers).
      1. Documents related to the aforementioned components.

Scope of Work and Applicability

Scope of the Regulations

These regulations must be applied to sensitive systems - in accordance with the standards mentioned in this document - by the public entities owning or operating these systems, whether they are governmental entities (such as ministries, authorities, institutions, embassies, and others) inside the Kingdom of Saudi Arabia; or outside it, or entities and companies affiliated with governmental entities, or private sector entities, all of which are referred to collectively in this document as (the Entity).

Next section title

Next section content