Saudi Arabia’s Vision 2030 aimed at the comprehensive development of the nation, its security, economy, the welfare of its citizens, and their dignified living. It was natural that one of its targets would be the transformation towards the digital world and the development of digital infrastructure; reflecting the keeping pace with the rapid global advancement in digital services, in renewed global networks, information technology systems, and operational technology systems. This is to be followed by the growth of computational processing capabilities, massive data storage capacities, and data exchange; preparing for dealing with artificial intelligence data and the transformations of the Fourth Industrial Revolution.
This transformation requires the smooth flow of information, its security, and the integration of its systems. It necessitates maintaining and enhancing the cybersecurity of the Kingdom of Saudi Arabia; protecting the vital interests of the state, its national security, sensitive infrastructures, priority sectors, and government services and activities. Therefore, the establishment of the National Cybersecurity Authority was initiated. Its organization was approved by the Royal Order No. 6801 dated 11/2/1439 AH, designating it as the competent authority in the Kingdom for cybersecurity and the national reference in its affairs.
The tasks and competencies of this Authority were designed to meet strategic aspects, policy formulation, governance mechanisms, frameworks, standards, regulations, and guidelines related to cybersecurity, and to disseminate them to the entities.
They also address aspects of modernization and monitoring compliance by governmental and non-governmental entities; enhancing the role and importance of cybersecurity and its urgent necessity, which has increased with the rise of threats and security risks in cyberspace more than ever before.
The aforementioned organization stipulates that the regulatory role of the Authority does not exempt any public or private entity or others from their responsibility towards their cybersecurity. This was affirmed by the Royal Decree No. 57231 dated 10/11/1439 AH stating that “all governmental entities must raise their cybersecurity level to protect their networks, systems, and electronic data, and comply with the policies, frameworks, standards, regulations, and guidelines issued by the National Cybersecurity Authority in this regard,” as well as by Royal Decree No. 7732 dated 12/2/1440 AH.
On this basis, the National Cybersecurity Authority prepared the Cybersecurity Controls for Sensitive Systems (CSCC - 1: 2019) to set the minimum cybersecurity requirements for sensitive systems in public entities, in addition to the Essential Cybersecurity Controls (ECC - 1: 2018). This document details the cybersecurity controls for sensitive systems, their objectives, scope of work, and the mechanism for compliance and follow-up.
All public entities that own or operate sensitive systems must implement what achieves continuous and ongoing compliance with these controls on sensitive systems; in fulfillment of the provisions of paragraph three of Article Ten in the organization of the National Cybersecurity Authority, as well as the provisions of Royal Decree No. 57231 dated 10/11/1439 AH and Royal Decree No. 7732 dated 12/2/1440 AH.