Saudi Arabia’s Vision 2030 aims at the comprehensive development of the nation, its security, economy, the welfare of its citizens, and their dignified living. It was natural that one of its targets would be the transformation towards the digital world and the development of digital infrastructure; reflecting the pace of rapid global progress in digital services, evolving global networks, information technology systems, and operational technology systems. This aligns with the growing capabilities of computational processing, massive data storage, and data transmission, preparing for dealing with artificial intelligence data and the transformations of the Fourth Industrial Revolution.
This transformation requires the smooth flow of information, its security, and the integration of its systems. It necessitates maintaining and enhancing the cybersecurity of the Kingdom of Saudi Arabia to protect the vital interests of the state, its national security, critical infrastructures, priority sectors, government services, and activities. Therefore, the establishment of the National Cybersecurity Authority and the approval of its statute by the gracious Royal Order No. 6801 dated 11/2/1439 AH, designated it as the competent authority in the Kingdom for cybersecurity and the national reference in its affairs.
The tasks and competencies of this Authority have been designed to meet strategic aspects, as well as aspects related to policy formulation, governance mechanisms, frameworks, standards, regulations, and guidelines related to cybersecurity and their dissemination to entities.
They also address aspects of modernization and monitoring compliance by governmental and non-governmental entities, enhancing the role and importance of cybersecurity and the urgent need that has increased with the rise of threats and security risks in cyberspace more than ever before.
The aforementioned statute stipulates that the responsibility of this Authority does not exempt any public, private, or other entity from its responsibility towards its cybersecurity. This was affirmed by the gracious Royal Decree No. 57231 dated 10/11/1439 AH, which states: “All governmental entities must raise their cybersecurity level to protect their networks, systems, and electronic data, and comply with the policies, frameworks, standards, regulations, and guidelines issued by the National Cybersecurity Authority in this regard.”
On this basis, the National Cybersecurity Authority has developed the Essential Cybersecurity Controls (ECC - 1: 2018) to set the minimum cybersecurity requirements for national entities falling under the scope of these controls. This document details these controls, their objectives, scope of work, applicability, and the mechanism for compliance and follow-up.
All national entities must implement what achieves permanent and continuous compliance with these controls, in fulfillment of what is stated in paragraph three of Article Ten of the National Cybersecurity Authority’s statute, as well as what is stated in the gracious Royal Decree No. 57231 dated 10/11/1439 AH.