Organizations Social Media Accounts

Traffic Light Protocol (TLP)

  • This marking protocol is widely used around the world. It has four colors (traffic lights):

  • Red – Personal and Confidential to the Recipient only

    • The recipient is not allowed to share red-classified materials with any person, from within or outside the organization, beyond the scope specified for receipt.

  • Amber – Limited Sharing

    • The recipient of amber-classified materials may share the information contained therein with concerned personnel only in the same organization, and with those competent to take procedures with regard to the information.

  • Green – Sharing within the Same Community

    • Green-classified materials may be shared with others within the same organization or in other organization that have relations with your organization or are operating in the same sector. However, such materials may not be shared or exchanged through public channels.

  • White – No Restrictions

Executive Summary

  • Social networks are one of the enablers for rapid and effective communication with the beneficiaries, which contributes to a speedy response and improving and facilitating the experience of the beneficiaries. With the increase in the use of social networks officially by organizations inside the Kingdom to communicate with the beneficiaries, the risk of theft crimes of official social media accounts, misuse of them or impersonation has increased, which necessitates setting cybersecurity requirements to reduce these risks.

  • To contribute to reducing these risks and enhancing the protection of organizations’ social media accounts, with the aim of reaching a safe and reliable Saudi cyber space that enables growth and prosperity; The National Cybersecurity Authority has developed the Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC - 1: 2021) to set the minimum cybersecurity requirements to enable organizations to use social networks in a safe manner. This document explains the details of the Organizations’ Social Media Accounts Cybersecurity Controls, their goals, scope of work, and compliance approach and monitoring.

  • Organizations must implement all necessary measures to ensure continuous compliance with these controls, in order to comply with item 3 of article 10, in the mandate of the National Cybersecurity Authority.

Introduction

  • The National Cybersecurity Authority (referred to in this document as “The Authority”) has developed the Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC - 1: 2021) after conducting a study of cybersecurity best practices and analyzing previous cyber incidents and attacks. This comes within the mandate and tasks of The Authority according to its mandate as per the Royal Decree No. (6801) dated 11/2/1439 AH, “Establishing policies, governance mechanisms, frameworks, standards, controls and guidelines related to cybersecurity, circulating them to the relevant organization, following up on compliance with them, and updating them.”

  • Social networks are one of the enablers for rapid and effective communication with the beneficiaries, which contributes to a speedy response and improving and facilitating the experience of the beneficiaries. With the increase in the use of social networks officially by organizations inside the Kingdom to communicate with the beneficiaries, the risk of theft crimes of official social media accounts or misuse of them has increased. In addition, the risk of impersonation of official organizations in social networks.

  • To contribute to reducing these risks and enhancing the protection of organizations’ social media accounts, with the aim of reaching a safe and reliable Saudi cyber space that enables growth and prosperity; The National Cybersecurity Authority has developed the Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC - 1: 2021) to set the minimum cybersecurity requirements to enable Organizations’ to use social networks in a safe manner.

  • In preparing the Organizations’ Social Media Accounts Cybersecurity Controls, The Authority has been keen to align its components with the components of the Essential Cybersecurity Controls that are a basic requirement for the OSMACC. Adherence to OSMACC can only be achieved by achieving continuous compliance with the Essential Cybersecurity Controls in the first place, as they are linked to relevant national and international legislative and regulatory requirements

  • The Organizations’ Social Media Accounts Cybersecurity Controls consist of the following:

    • • 3 Main Domains

    • • 12 Subdomains

    • • 15 Main Controls

    • • 38 Subcontrols

Objectives

  • The Organizations’ Social Media Accounts Cybersecurity Controls aim to:

    • • Contribute to raising the level of cybersecurity at the national level.

    • • Enabling organizations to use social networks in a safe manner.

    • • Readiness to respond effectively to cyber incidents that may have negative impacts.

Scope of Work and Applicability

Scope of Work

  • These controls apply to government organizations in the Kingdom of Saudi Arabia, including ministries, authorities, establishments and others, and organizations and companies related to them. It also applies to private sector organizations that own, operate or host sensitive national infrastructure. All of them are referred to in this document as (The Organization).

  • The NCA strongly encourages all other organizations in the Kingdom to leverage these controls to implement best practices to improve and enhance their cybersecurity.

Statement of Applicability

  • These controls have been prepared so that they are compatible with the cybersecurity requirements for all organizations and sectors in the Kingdom of Saudi Arabia taking into account the diversity and nature of work, and The Organization that uses social networks must adhere to all the controls applicable to it.

Implementation and Compliance

  • In order to comply with item 3 of article 10, in the mandate of the National Cybersecurity Authority, organizations must implement all necessary measures to ensure continuous compliance with these controls, which cannot be achieved without achieving continuous compliance with the Essential Cybersecurity Controls (ECC – 1: 2018) where applicable.

  • The Authority evaluates organizations’ compliance with the OSMACC through multiple means such as self-assessments by the organizations, and/or on-site audits, in accordance with the mechanisms deemed appropriate by the Authority.

Update and Review

  • The Authority will periodically review and update the OSMACC as per the cybersecurity requirements and the related industry updates. The Authority will communicate and publish the updated version of OSMACC for implementation and compliance.

OSMACC Domains and Structure

Next section title

Next section content