News & Updates

SAMA CSF: Cybersecurity Compliance, Domains, Maturity Levels, Audit Readiness

SAMA Compliance in 2024

Table of Contents

Financial institutions in Saudi Arabia must recognize that cybersecurity is not an exclusive information technology (IT) domain. Banks, insurers, financing companies, credit bureaus, and payment processors store financial and customer data that can be subject to incidental or premeditated breaches, exposing customers to harm, business processes to disruption, reputation to damage, and regulatory compliance to risk.

What Is the SAMA Cyber Security Framework (CSF)? A Complete Overview

Four domains of SAMA CSF illustrated: governance, risk, operations, third-party security

The SAMA Cyber Security Framework is a control framework developed by the Saudi Arabian Monetary Authority, otherwise known as the Saudi Central Bank, to standardize the approach to managing cybersecurity risk. Designed to achieve common goals and principles, the framework enables organizations to establish a suitable level of cybersecurity maturity while addressing critical areas of governance and risk management, operations and technology, and third-party security. The SAMA CSF covers cybersecurity areas beyond technology, including governance, risk management, operations, information assets, people, and processes, making it relevant to organizations that seek to achieve higher cybersecurity maturity beyond the basics. It also incorporates existing cybersecurity and risk management frameworks, standards, and principles, including NIST, ISF, ISO, Basel, and PCI.

Does Your Organization Need to Comply with SAMA CSF?

SAMA CSF requirements apply to entities that operate under the supervision of the Saudi Arabian Monetary Authority. According to the official guidelines, the framework applies to banks, insurance and reinsurance companies, financing companies, credit bureaus, and financial market infrastructure. The list of organizations supervised by SAMA also includes insurance brokerage companies authorized to engage in electronic insurance sales, insurance aggregators, and medical claims settlement companies under a SAMA circular issued in 2022.

Therefore, organizations cannot decide for themselves whether they need to apply the framework. Instead, they must rely on the latest regulatory guidance to define whether their type of business activity falls under the supervision of SAMA. The entities supervised by the Saudi Arabian Monetary Authority are also referred to as member organizations within the framework.

The 4 Domains of SAMA CSF Explained (With Examples)

four-domains-sama-csf-governance-risk-operations-third-party

The SAMA CSF is organized into the following domains:

Cyber Security Leadership and Governance Cyber Security Risk Management and Compliance Cyber Security Operations and Technology Third Party Cyber Security

The SAMA CSF is organized into the following domains:

  • Cyber Security Leadership and Governance
  • Cyber Security Risk Management and Compliance
  • Cyber Security Operations and Technology
  • Third Party Cyber Security

 Cyber Security Leadership and Governance

Governance is the responsibility of an organization’s leadership, including the board of directors and senior management, who are accountable for strategy development and decision-making relating to cybersecurity.The SAMA CSF highlights that effective governance contributes to embedding cybersecurity discipline across the organization, securing executive support and resources for cybersecurity initiatives, and ensuring that appropriate policies, procedures, and controls are established, implemented, and maintained.

Organizations are encouraged to address governance-related questions, including:

  • Who owns cybersecurity?
  • Who approves cybersecurity policies?
  • How are cyber risks reported to the executive leadership?
  • Who makes decisions regarding cybersecurity?
  • Is there a cybersecurity strategy?
  • Are security responsibilities delegated?
  • Are policies reviewed and updated periodically?

Cyber Security Risk Management and Compliance

SAMA CSF’s second domain, Cyber Security Risk Management and Compliance, supports organizations in delivering effective governance by aligning cybersecurity objectives with enterprise risk management principles.It emphasizes the need for organizations to develop and maintain an information security program that addresses critical information assets, including information security requirements, threats, vulnerabilities, associated risks, risk treatment, and continuous monitoring.An effective cybersecurity program will enable organizations to identify, assess, understand, and treat cyber risk in a structured manner. This means that organizations must perform the following activities:

  • Identify information assets
  • Assess threats and vulnerabilities
  • Analyze risk
  • Define risk treatment
  • Agree on risk acceptance criteria
  • Monitor and report continuously

The SAMA CSF is principle-based, which means that organizations are expected to work toward meeting the objectives while considering their unique circumstances and approaches to risk management. 

3. Cyber Security Operations and Technology

The third domain highlights the importance of supporting cybersecurity strategy through operations and technology. This area covers the capabilities needed to operate and protect information assets and services, including security architecture, security event management, incident management, threat management, vulnerability management, access controls, and monitoring among other areas. Technology is generally not sufficient on its own as evidence of effective control unless supported by supporting procedures, policies, and continuous monitoring. For example, simply possessing a security information and event management system is not sufficient evidence that an organization has effective security event management. The auditor will seek to understand how the organization investigates events and incidents, escalates, documents, and reports them.

Third Party Cyber Security

Modern organizations rely extensively on third-party service providers to deliver IT services, financial services, data storage solutions, and other critical business functions. The same is true for financial institutions that depend on cloud platform providers, payment processors, software vendors, and managed security service providers among other third-party organizations that offer critical services and possess sensitive information. An effective cybersecurity program must recognize that the risks arising from third parties can impact an organization and require due diligence when engaging service providers, establishing contracts, and conducting continuous monitoring of third-party security performance.

  • The domain encourages organizations to perform the following activities:
  • Planning for vendor exits and continuity managementt
  • Conducting risk assessments of vendors
  • Defining security requirements in contracts
  • Performing access reviews
  • Implementing appropriate security monitoring measures
  • Reviewing and evaluating vendor performance
  • Providing third-party risk management support and guidance
  • Performing regular vendor assessments and reviews

SAMA CSF Maturity Levels 0–5: Where Does Your Organization Stand?

Maturity levelDescriptionWhat it generally means
Level 0Non-existentControls are not in place and there may be little awareness of the risk
Level 1Ad-hocControls may be partially defined and performed inconsistently
Level 2Repeatable but informalPractices are repeatable but may not be formally documented or approved
Level 3Structured and formalizedControls, policies, standards, and procedures are formally defined, approved, implemented, and demonstrated
Level 4Managed and measurableControl effectiveness is periodically measured, evaluated, and improved
Level 5AdaptiveSecurity is continuously improved and integrated with enterprise risk management and broader performance information

SAMA CSF Requirements Checklist: Governance, Risk, Operations & Third-Party

sama-csf-maturity-levels-0-to-5-cybersecurity-assessment.

The framework’s requirements are organized into the four previously mentioned domains.Within each domain, organizations must address subdomains, principles, objectives, and control considerations.A high-level overview of requirements that must be addressed by organizations includes:

Governance-related requirements:

  • Cyber security strategy
  • Policies, standards, procedures
  • Roles and responsibilities
  • Committee structure
  • Reporting lines and responsibilities
  • Risk-related requirements:
  • Information asset inventory
  • Risk identification and assessment
  • Risk treatment and acceptance
  • Risk monitoring and reporting

Operations-related requirements:

  • Vulnerability assessment
  • Monitoring and incident management
  • Threat management
  • Access controls and reviews
  • Security testing and remediation
  • Management of security events

Third-party requirements:

  • Third-party risk assessments
  • Contract requirements
  • Monitoring and reviews
  • Information security aspects
  • Due diligence and control testing

Performance-related requirements:

  • Reviews and continuous improvement
  • Management reporting
  • Security metrics and indicators

Creating the SAMA CSF Audit Checklist?

In general, the activities can be grouped into the following:

  • Preparing the initial assessment and addressing any gaps
  • Ensuring that the framework requirements are reflected in policies, procedures, and operations
  • Collecting evidence that demonstrates that controls are followed
  • Reviewing and analyzing results to support continuous improvement

SAMA CSF Compliance for Banks vs. Fintechs vs. Insurers: Key Differences

The SAMA CSF principles apply to all financial institutions, including banks, fintechs, and insurers, but the implementation can be different based on the nature of their operations. In general, banks tend to operate large-scale systems that include core banking systems, infrastructure, payments and clearing systems, and extensive third-party networks, including local and international branches. Fintechs are more technology-driven and rely on APIs, cloud infrastructure, mobile apps, and other technologies but still operate under the regulatory framework and may utilize a number of third-party providers. Insurance companies have their own set of considerations, including the need to secure customer data, third-party applications, and claims processing solutions.

The #1 Reason Organizations Fail Their SAMA CSF Audit (And How to Avoid It)

Many organizations try to address regulatory requirements by developing policies, procedures, and even operational approaches that exist only on paper. In reality, they are never followed or supported by evidence. This is especially evident when organizations use generic policy language to address specific requirements without providing additional context or controls.

An organization may have a vulnerability management policy, for instance, but have no procedures that actually address the scanning, prioritization, remediation, and verification of identified vulnerabilities. Similarly, many organizations have incident response procedures but do not actually test them. As the SAMA CSF requirements emphasize the need for implementation and evidence, such organizations will find themselves in significant difficulties during an audit.

A better approach is to link policies to actual implementation practices and ensure that evidence is available. Such evidence is crucial for demonstrating that an organization has effective controls in place.

7 Steps to Prepare for Your SAMA CSF Assessment

Organizations can address the requirements using the following steps:

  1. Determine Applicability: Organizations must identify the requirements that apply to them.
  2. Conduct a Gap Assessment: Organizations must review the requirements to identify what they have done, what they have partially implemented, and what they have not addressed.
  3. Determine Maturity: Organizations must conduct a maturity assessment to determine their level for each area.
  4. Prioritize: Organizations must prioritize the areas based on risk and complexity.
  5. Create Roadmap: Organizations must create a detailed action plan that includes owners, timelines, and deliverables.
  6. Collect Evidence: Organizations must collect the evidence that demonstrates that they follow the required policies and procedures.
  7. Test and Improve Organizations must test controls, track findings, and remediate issues, using the results to inform continuous improvement.

Key Takeaways on SAMA CSF Compliance

The SAMA CSF enables Saudi Arabia’s financial institutions to operate in a secure environment that promotes cybersecurity maturity. The framework consists of four domains and six levels of maturity that allow organizations to address the key areas of cybersecurity, including governance, operations, technology, and third-party management. The maturity model encourages organizations to move from ad-hoc approaches to cybersecurity to a formalized system that is supported by evidence and continually improved. For banks, fintechs, and other financial institutions, preparing for the assessment entails understanding the requirements, addressing the gaps, and collecting the required evidence. In general, organizations must ensure that their policies and procedures are meaningful and supported by implementation activities and evidence.

SAMA CSF FAQs: Your Top Questions Answered

What is SAMA CSF, exactly?

SAMA CSF is a cybersecurity framework that helps regulated financial organizations manage cyber risks and improve security maturity.

Who is required to comply with SAMA CSF?

It applies to SAMA-regulated organizations, including banks, insurance companies, financing companies, and other applicable financial institutions.

What are the main SAMA CSF domains?

The four main domains cover governance, risk management and compliance, operations and technology, and third-party cybersecurity.

How many SAMA CSF maturity levels are there?

The framework has six maturity levels, from Level 0 to Level 5, with Level 3 or higher identified as the appropriate target.

How should organizations prepare for SAMA CSF compliance?

Organizations should assess their gaps, implement required controls, measure maturity, fix weaknesses, and maintain evidence for assessments and audits.


Discover more from Diginatives

Subscribe to get the latest posts sent to your email.

Share to:

Relevant Articles

Discover more from Diginatives

Subscribe now to keep reading and get access to the full archive.

Continue reading