Cybersecurity Regulations for Cloud Computing

Traffic Light Protocol (TLP):

  • This marking protocol is widely used around the world to share sensitive data. It has four colors (traffic lights):

    • Red – Personal, Confidential, and for the Intended Recipient only

      • The recipient has no rights to share information classified in red with any person outside the defined range of recipients, either inside or outside the entity.

    • Amber – Restricted Sharing

      • The recipient may share information classified in amber only with intended recipients inside the entity and with recipients who are required to take action related to the shared information.

    • Green – Sharing within the Same Community

      • The recipient may share information classified in green with other recipients inside the entity or outside it within the same sector or related to the entity. However, it is not allowed to exchange or publish this information on public channels.

    • White – No Restrictions

Update and Review

Executive Summary

  • NCA’s mandates and duties fulfill the regulatory cybersecurity needs related to the development of cybersecurity national policies, governance mechanisms, frameworks, standards, controls, and guidelines, to support the important role of cybersecurity which has increased with the rise of security risks in cyberspace more than any time before.

  • The cloud services subject is trending globally, while enjoying a very fast pace in the Kingdom of Saudi Arabia which results in new cybersecurity risks that require cybersecurity controls to transact with cloud services taking into consideration international common practices in this field, thus supporting the already published Essential Cybersecurity Controls (ECC-1: 2018).

  • As a result, the Cloud Cybersecurity Controls (CCC – 1: 2020) is developed to minimize the cybersecurity risks of Cloud Service Providers (CSPs), and Cloud Customers, also known as Cloud Service Tenants (CSTs). This document highlights the details of the cloud cybersecurity controls for cloud services, objectives, scope, statement of applicability, compliance approach and monitoring.

  • All CSPs and CSTs shall implement all necessary measures to ensure continuous compliance with the CCC as per Article 10(3) of NCA’s mandate and as per the Royal Decree number 57231, dated 10/11/1439 H.

Introduction

  • The National Cybersecurity Authority (referred to in this document as “NCA”) updating the Cloud Cybersecurity Controls (CCC – 2: 2024) after conducting a comprehensive study of multiple national and international cybersecurity frameworks, standards, and controls, and reviewing common industry practices and experiences in the field of cybersecurity. A mapping study is conducted with international cloud computing standards and controls such as US FedRAMP, Multi-Tier Cloud Security Standard for Singapore (MTCS SS), Germany C5, Cloud Controls Matrix (CCM), and ISO/IEC 27001.

Cloud Cybersecurity Controls Components

Objectives

  • The Cloud Cybersecurity Controls (CCC – 2: 2024) is developed as an extension to the ECC. It aims to achieve higher levels of national cybersecurity goals by focusing on cloud computing services from the perspective of Cloud Service Providers (CSPs) and Cloud Service Tenants (CSTs). Also, the CCC aims to set the minimum requirements for cybersecurity of cloud computing, for both CSPs and CSTs, to contribute to enable the CSPs and the CSTs to provide and use secure cloud computing services and mitigating cyber risks against them.

  • The cybersecurity of cloud computing services, for both CSPs and CSTs, must be able to protect the confidentiality, integrity and availability of the data and information within the cloud environment. To that aim, CCC take into consideration the following four main cybersecurity pillars:

    • Strategy

    • People

    • Procedures 

    • Technology

Scope of Work and Applicability

CCC Scope of Work

  • The cloud cybersecurity controls shall apply to the CSPs and CSTs. These controls represent the minimum cybersecurity requirements for cloud computing.

  • CSPs within the scope of CCC are any CSP which provides cloud computing services to the CSTs within the scope of work. CSTs within the scope of CCC are any government agency in the Kingdom of Saudi Arabia inside or outside the Kingdom including ministries, authorities, establishments and other entities and their companies and sub-entities, as well as all private sector entities owning, operating or hosting Critical National Infrastructures (CNIs) that currently use or are planning to use any cloud service.

  • The cybersecurity controls shall apply to the CSPs and CSTs. These controls represent the minimum cybersecurity requirements for cloud computing.

  • NCA strongly encourages all other entities in the Kingdom to leverage these controls to implement best practices to improve and enhance their cloud cybersecurity.

Examples of CSPs outside Scope of Work

  •  CSPs who provide cloud computing services for non-Saudi entities outside the Kingdom and do not provide services to CSTs within scope of work. 

  • CSPs who provide cloud computing services for individuals, and private sector entities not owning, operating, or hosting Critical National Infrastructures (CNIs), and do not provide services to CSTs within scope of work.

CCC Statement of Applicability

  • The ECC and the CCC have been developed after taking into consideration the cybersecurity needs of CSPs and CSTs, and every CSP and CST must comply with all applicable controls.

Next section title

Next section content