The Kingdom of Saudi Arabia’s Vision 2030 aims for a comprehensive improvement of the nation and its security, economy, and citizens’ well-being and decent life. Naturally, one of the essential goals of Vision 2030 is the transformation towards digitalization and the improvement of digital infrastructure, in order to keep up with the accelerated global progress in digital services, renewable global networks, IT systems, and OT systems, align with growing computer processing and massive data storage and exchange capabilities, and be prepared for handling artificial intelligence and the fourth 4th industrial revolution transformations.
This transformation requires streamlining the flow of information, securing it, and preserving the integration of all systems. It also requires maintaining and supporting the cybersecurity of the Kingdom, in order to protect the State’s vital interests, national security, critical infrastructures, high priority sectors, and governmental services and activities. To this end, the National Cybersecurity Authority (NCA) was established, and the NCA’s Statute was approved by Royal Order No. 6801, dated 11/02/1439H., making the NCA the national and specialized cybersecurity reference in the Kingdom.
NCA’s powers and duties fulfill the strategic cybersecurity needs and the need to develop cybersecurity policies, governance mechanisms, frameworks, standards, controls, and guidelines, and disseminate them across entities.
NCA’s powers and duties also fulfil the needs of updating and continuously monitoring the compliance of government agencies and non-government entities, as the role and significance of cybersecurity have significantly increased more than ever with the rise of security risks in the cyberspace.
NCA’s Statute states that no public agency, private entity, or any other entity shall be relieved from their responsibility towards their own cybersecurity, as confirmed by High Order No. 57231, dated 10/11/1439H., which states that “all government agencies must raise the level of their cybersecurity to protect their electronic networks, systems and data, and to abide by the NCA’s policies, frameworks, standards, controls, and guidelines in this regard”.
From this perspective, the NCA has developed the Essential Cybersecurity Controls (ECC-1: 2018) to set the minimum cybersecurity requirements for national entities falling within the ECC scope of work. This document outlines the details, goals, scope of work, applicability, and compliance and monitoring mechanism of the ECC.
All national entities shall take the necessary measures to ensure ongoing and continuous compliance with the ECC, as per Article 10(3) of the NCA’s Statute and High Order No. 57231, dated 10/11/1439H.