This is an earlier version ofBasic Cybersecurity Regulations - 1440Switch to the new version

Basic Cybersecurity Regulations - 1440

Traffic Light Protocol (TLP):

The Light Signal Protocol system was established to share the maximum amount of sensitive information and is widely used worldwide. There are four colors (light signals):

Red - Personal and Confidential for the Recipient Only

The recipient is not entitled to share the classified information marked with the red signal with any individual, whether inside or outside the facility, beyond the specified scope of receipt.

Orange - Limited Sharing

The recipient of the orange signal may share the information within the same facility only with concerned persons and those required to take action related to the information.

Green - Sharing Within the Same Community

You may share it with others from your facility or another facility related to you or within the same sector, but it is not permitted to exchange or publish it through public channels.

White - Unlimited

Executive Summary

Saudi Arabia’s Vision 2030 aims at the comprehensive development of the nation, its security, economy, the welfare of its citizens, and their dignified living. It was natural that one of its targets would be the transformation towards the digital world and the development of digital infrastructure; reflecting the pace of rapid global progress in digital services, evolving global networks, information technology systems, and operational technology systems. This aligns with the growing capabilities of computational processing, massive data storage, and data transmission, preparing for dealing with artificial intelligence data and the transformations of the Fourth Industrial Revolution.

This transformation requires the smooth flow of information, its security, and the integration of its systems. It necessitates maintaining and enhancing the cybersecurity of the Kingdom of Saudi Arabia to protect the vital interests of the state, its national security, critical infrastructures, priority sectors, government services, and activities. Therefore, the establishment of the National Cybersecurity Authority and the approval of its statute by the gracious Royal Order No. 6801 dated 11/2/1439 AH, designated it as the competent authority in the Kingdom for cybersecurity and the national reference in its affairs.

The tasks and competencies of this Authority have been designed to meet strategic aspects, as well as aspects related to policy formulation, governance mechanisms, frameworks, standards, regulations, and guidelines related to cybersecurity and their dissemination to entities.

They also address aspects of modernization and monitoring compliance by governmental and non-governmental entities, enhancing the role and importance of cybersecurity and the urgent need that has increased with the rise of threats and security risks in cyberspace more than ever before.

The aforementioned statute stipulates that the responsibility of this Authority does not exempt any public, private, or other entity from its responsibility towards its cybersecurity. This was affirmed by the gracious Royal Decree No. 57231 dated 10/11/1439 AH, which states: “All governmental entities must raise their cybersecurity level to protect their networks, systems, and electronic data, and comply with the policies, frameworks, standards, regulations, and guidelines issued by the National Cybersecurity Authority in this regard.”

On this basis, the National Cybersecurity Authority has developed the Essential Cybersecurity Controls (ECC - 1: 2018) to set the minimum cybersecurity requirements for national entities falling under the scope of these controls. This document details these controls, their objectives, scope of work, applicability, and the mechanism for compliance and follow-up.

All national entities must implement what achieves permanent and continuous compliance with these controls, in fulfillment of what is stated in paragraph three of Article Ten of the National Cybersecurity Authority’s statute, as well as what is stated in the gracious Royal Decree No. 57231 dated 10/11/1439 AH.

Introduction

The National Cybersecurity Authority (referred to in this document as the "Authority") has developed the Essential Cybersecurity Controls (ECC - 1: 2018) after studying several cybersecurity standards, frameworks, and controls previously prepared by various local and international entities and organizations. This was done following an examination of the requirements of relevant national legislations, regulations, and decisions, reviewing best practices and experiences in the field of cybersecurity and benefiting from them, analyzing observed cyber incidents and attacks at the level of government entities and other sensitive entities, and after consulting the opinions of many national entities and considering their views.

These controls consist of:

⏺ 5 Main Domains of cybersecurity controls

⏺ 29 Subdomains of cybersecurity controls

⏺ 114 Essential cybersecurity controls

These controls are also linked to relevant national and international legislative and regulatory requirements.

Objectives

These regulations aim to provide the minimum basic requirements for cybersecurity based on best practices and standards to reduce cyber risks to the informational and technical assets of entities from internal and external threats. Protecting the informational and technical assets of the entity requires focusing on the core protection objectives, which are:

⏺ Confidentiality

⏺ Integrity

⏺ Availability

These regulations take into account the four fundamental pillars on which cybersecurity is based, which are:

⏺ Strategy

⏺ People

⏺ Process

⏺ Technology

Scope of Work and Applicability

Scope of the Regulations

These regulations apply to government entities in the Kingdom of Saudi Arabia (including ministries, authorities, institutions, and others), their affiliated entities and companies, and private sector entities that own, operate, or host Critical National Infrastructures ("CNIs") (all collectively referred to in this document as the "Entity"). The Authority also strongly encourages other entities in the Kingdom to benefit from these regulations to implement best practices regarding the enhancement and development of cybersecurity within the entity.

Execution and Obligation

In fulfillment of what is stated in the third paragraph of Article Ten of the Statute of the National Cybersecurity Authority, as well as what is stated in the Royal Order No. 57231 dated 10/11/1439 AH, all entities within the scope of these regulations must implement measures that ensure continuous and permanent compliance with these regulations.

The Authority shall assess the entities' compliance with the provisions of these regulations through various methods, including: self-assessment by the entities, periodic reports of the compliance tool, and/or field audit visits, according to the mechanism the Authority deems appropriate for that purpose.

Compliance Assessment and Measurement Tool

The Authority shall issue the tool (ECC - 1: 2018 Assessment and Compliance Tool) to regulate the process of evaluating and measuring the extent of entities' compliance with the implementation of the fundamental cybersecurity regulations.

Update and Review

The Authority undertakes the periodic updating and review of the fundamental cybersecurity regulations according to cybersecurity requirements and related developments. The Authority also undertakes the announcement of the updated version of the regulations for implementation and compliance.

Next section title

Next section content