The National Cybersecurity Authority has prepared the Cybersecurity Guidelines for the Internet of Things (CGIoT-1:2024), which are recommended for implementation in all entities using Internet of Things technology in the Kingdom; this is to reduce the cybersecurity risks associated with the widespread adoption of the Internet of Things.
These guidelines cover four main components: Cybersecurity Governance, Cybersecurity Enhancement, Cybersecurity Resilience, and Cybersecurity related to Third Parties and Cloud Computing.
The (Cybersecurity Governance) component is concerned with ensuring that the entity’s strategy, vision, roadmap, and objectives take into account the cybersecurity of the Internet of Things. This includes compliance with relevant regulations and legislations. This component also involves documenting and publishing cybersecurity policies and procedures related to the Internet of Things, in addition to ensuring the identification of cybersecurity roles and responsibilities for the Internet of Things for all relevant parties within the entity, within the governance structure. This component also clarifies the recommended guidelines to be applied regarding the management of cybersecurity risks for the Internet of Things, and ensures the inclusion of cybersecurity requirements for the Internet of Things in the lifecycle of information and technology project management. Furthermore, it focuses on the cybersecurity aspect of the Internet of Things concerning human resources, and the development of awareness and training programs for employees in the field of cybersecurity related to the Internet of Things.
Regarding the (Cybersecurity Enhancement) component, it is concerned with ensuring the application of appropriate cybersecurity mechanisms for the Internet of Things technology system in order to protect information and its assets against cyberattacks. Meanwhile, the (Cybersecurity Resilience) component is concerned with enhancing the entity’s ability to withstand the impacts that may arise due to incidents related to the cybersecurity of the Internet of Things.
The (Cybersecurity related to Third Parties and Cloud Computing) component addresses the need for effective management of cybersecurity risks related to third parties that support Internet of Things operations; including risks associated with cloud computing services.
This document also contains the cybersecurity principles for the Internet of Things for manufacturers, as detailed in Annex (A), which are recommended to be applied by companies manufacturing Internet of Things technology, in order to reduce cybersecurity risks in Internet of Things products and services.