Basic Regulations for Cybersecurity

Traffic Light Protocol (TLP):

  • This marking protocol is widely used around the world to share sensitive data. It has four colors (traffic lights):

    • Red – Personal and Confidential to the Recipient Only

      • The recipient has no rights to share information classified in red with any person outside the defined range of recipients, either inside or outside the entity.

    • Amber – Restricted Sharing

      • The recipient may share information marked in amber with the concerned personnel only within the same entity, and with those required to take action with regard to the information.

    • Green – Sharing within the Same Community

      • The recipient may share information marked in green with other recipients inside the same entity or with others in a related entity or in an entity within the same sector. However, sharing or publishing this information on public platforms is not permitted.

    • White – No Restrictions

Update and Review

Executive Summary

  • The Kingdom of Saudi Arabia’s Vision 2030 aims for a comprehensive improvement of the nation and its security, economy, and citizens’ well-being and decent life. Naturally, one of the essential goals of Vision 2030 is the transformation towards digitalization and the improvement of digital infrastructure, in order to keep up with the accelerated global progress in digital services, renewable global networks, IT systems, and OT systems, align with growing computer processing and massive data storage and exchange capabilities, and be prepared for handling artificial intelligence and the fourth 4th industrial revolution transformations.

  • This transformation requires streamlining the flow of information, securing it, and preserving the integration of all systems. It also requires maintaining and supporting the cybersecurity of the Kingdom, in order to protect the State’s vital interests, national security, critical infrastructures, high priority sectors, and governmental services and activities. To this end, the National Cybersecurity Authority (NCA) was established, and the NCA’s Statute was approved by Royal Order No. 6801, dated 11/02/1439H., making the NCA the national and specialized cybersecurity reference in the Kingdom.

  • NCA’s powers and duties fulfill the strategic cybersecurity needs and the need to develop cybersecurity policies, governance mechanisms, frameworks, standards, controls, and guidelines, and disseminate them across entities.

  • NCA’s powers and duties also fulfil the needs of updating and continuously monitoring the compliance of government agencies and non-government entities, as the role and significance of cybersecurity have significantly increased more than ever with the rise of security risks in the cyberspace.

  • NCA’s Statute states that no public agency, private entity, or any other entity shall be relieved from their responsibility towards their own cybersecurity, as confirmed by High Order No. 57231, dated 10/11/1439H., which states that “all government agencies must raise the level of their cybersecurity to protect their electronic networks, systems and data, and to abide by the NCA’s policies, frameworks, standards, controls, and guidelines in this regard”.

  • From this perspective, the NCA has developed the Essential Cybersecurity Controls (ECC-1: 2018) to set the minimum cybersecurity requirements for national entities falling within the ECC scope of work. This document outlines the details, goals, scope of work, applicability, and compliance and monitoring mechanism of the ECC.

  • All national entities shall take the necessary measures to ensure ongoing and continuous compliance with the ECC, as per Article 10(3) of the NCA’s Statute and High Order No. 57231, dated 10/11/1439H.

Introduction

  • The National Cybersecurity Authority (Hereinafter referred to as the “NCA”) developed the Essential Cybersecurity Controls (ECC–1:2018) after conducting a study on multiple cybersecurity standards, frameworks, and controls that have previously been developed by (national and international) entities and organizations, considering the requirements of relevant national legislations, regulations, and decisions, as well as reviewing and leveraging cybersecurity best practices, analyzing previous cybersecurity incidents and attacks against government agencies and other critical entities, and surveying and considering opinions of multiple national entities.

  • The Essential Cybersecurity Controls consist of the following: 

    • 4 Cybersecurity Main Domains. 

    • 28 Cybersecurity Subdomains. 

    • 108 Cybersecurity Main Controls. 

    • 92 Cybersecurity Subcontrols.

  • Moreover, these Controls are linked to relevant national and international legislative and regulatory requirements.

Objectives

  • These Controls aim to provide the minimum cybersecurity requirements based on the best practices and standards to minimize the internal and external cybersecurity threats against the entities’ information and technology assets. The protection of the entity’s information and technology assets requires focusing on the key protection goals, which are as follows: 

    • Confidentiality

    • Integrity

    • Availability

  • These Controls take into account the following four main cybersecurity pillars: 

    • Strategy 

    • People 

    • Process 

    • Technology

Scope of Work and Applicability

ECC Scope of Work

  • These Controls are applicable to government agencies in the Kingdom of Saudi Arabia (including ministries, authorities, establishments and others) and their affiliated companies and entities (inside and outside the kingdom), as well as all private sector entities owning, operating, or hosting Critical National Infrastructures (CNIs) (Hereinafter referred to collectively as the "entity"). The NCA strongly encourages all other entities in the Kingdom to leverage these Controls to implement best practices to improve and enhance their cybersecurity.

ECC Statement of Applicability

  • These Controls have been developed to fulfill the cybersecurity needs of all entities and sectors in the Kingdom, taking into account the diverse nature of their businesses. Each entity shall comply with all controls applicable thereto.

  • Here are some examples of controls the applicability of which varies from one entity to another based on the entity’s business and use of certain technologies: 

    • Controls under the Subdomain (4-2) relating to Cloud Computing and Hosting Cybersecurity are applicable and binding on entities currently using or planning to use cloud computing and hosting services.

Implementation and Compliance

  • As per Article 10(3) of the NCA's Statute and High Order No. 57231, dated 10/11/1439H., all entities within the scope of these Controls shall take all necessary measures to ensure ongoing and continuous compliance with these Controls.

  • The NCA shall evaluate the entities’ compliance with the ECC through multiple means, such as self-assessment by the entities, periodic reports of the compliance tool, and/or field auditing visits, in accordance with the mechanism deemed appropriate by the NCA.

Assessment and Compliance Tool

  • The NCA will issue a tool (ECC-2:2024 Assessment and Compliance Tool) to organize the process of assessment and measurement of compliance by entities in applying the ECC.

Next section title

Next section content