The Saudi Arabian Monetary Authority was created in 2017 to provide sufficient guidance to all SAMA members to identify cyber threats and control their spread accurately. The SAMA framework is based on various compliance standards such as ISO, PCI, BASEL, ISF and NIST. It is a risk-based methodology with an expanded list of crucial security mandates and controls businesses should follow. It is mandatory to provide SAMA acceptance of legal risk when the company fails to comply. It helps SAMA determine the level of security maturity related to business enterprises.
SAMA Goals
SAMA has carefully covered every aspect of the cyber risk management process that all its member organizations must consider when protecting critical data/information.
Its implementation is mandatory for SAMA members to:
- They can adopt a viable approach to cyber security risk management
- They may have a well-defined level of maturity
- Digital risks are managed at an early stage to keep the damage under control
SAMA's objectives are defined to protect a wide range of assets, such as electronic/digital data, any kind of physical details, every single application, electronic device, database, and software used by a financial institution, electronic/computing machines, data storage devices, and everything that is part of the technical infrastructure.
SAMA Cyber Security Maturity Levels
SAMA directs organizations to adopt a certain degree of security controls according to their current level of security maturity. To measure level, SAMA CSF refers to a predefined model with 6 levels of maturity. With this level of security maturity, SAMA seeks to address critical risks for financial institutions in their early stages and control the damage. Successful completion of all previous levels is mandatory for those willing to reach level >3.
The first three maturity levels indicate the absence of robust controls in a given ecosystem. An organization must operate at a natural level of 3 or higher to be called reliable.
At Maturity Level 3, which is the minimum acceptable level of maturity, it is mandatory for members and the board to have a fully approved and binding cyber security policy whose purpose is clearly stated to all.
Employees, customers and third-party suppliers should be fully aware of acceptable policies.
At Maturity Level 4, the focus remains on testing the usefulness of working security controls and policies to ensure current controls are in place. As cyber threats evolve rapidly, implementing outdated security controls will not provide the required cyber security. Thus, this level of security maturity assesses an organisation's effort to evaluate security controls.
Finally, we have maturity level 5, which is more about continuously improving implemented and evaluated controls. At this level, members need to be sure that risk management and security controls are not polar opposites and are not two different aspects. Rather, they should be integrated and monitored regularly.
Control Domains
The basis of SAMA is four domains, which are further divided into several subdomains. The focus of a subdomain remains on a specific topic or issue. There are mainly three subdomains:
- The main reason for the existence of this security control
- Objective, which explains the objectives of the principle and what the particular security control is trying to achieve
- Review consideration refers to the mandatory security review that needs to be considered for each domain. There are generally four levels of control considerations.
Next, we have explained in detail the control domains of the SAMA Framework.
1. Leadership and management of cyber security
Member governing bodies are primarily responsible for maintaining a strong cybersecurity infrastructure. The board of directors of these bodies can delegate this responsibility to a well-formed security committee.
This security committee's role is to outline which governance standards are acceptable for cybersecurity review and to provide members with well-defined cybersecurity standards.
In addition, the committee is responsible for setting cybersecurity policy and identifying viable operational practices that will improve CSC's effectiveness.
It is mandatory to have an independent cybersecurity function to design, maintain and manage the applied cybersecurity policies.
In terms of governance, SAMA ensures that the cyber security governance structure should be under the authority of the board of directors. During the process, important checks include representing all leading cybersecurity committees, conducting regular internal audits, creating a cybersecurity charter, and clearly defining committee objectives.
2. Cyber security and compliance risk management
Members must understand that cyber risk management must be a continuous process and should revolve around the timely identification, monitoring and analysis of relevant risks. SAMA directs authorities to focus on the following:
- Timely identification of the threat/risk or its prediction
- Determining the likelihood of a cyber security risk
- Conducting regular risk analysis
- Creating a viable and results-driven response
- Periodic monitoring of treatment risks and analysis of the effectiveness of CSCs
- Adherence to defined CSCs (Cyber Security Controls)
SAMA states that a risk management procedure needs to be precisely defined, designed, approved, and implemented. Its motive is to protect the integrity and confidentiality of the critical details of the respective member businesses.
To ensure compliance, SAMA member companies must design risk management processes and communicate their implications to others. The risk compliance process must be conducted regularly and should be key to updating the cybersecurity policy.
Adherence to globally recognized standards is mandatory.
This is where PCI-DSS compliance, the SWIFT Customer Security Control framework and the EMV technical standard come into play.
3. Cyber Security Operations and Technology
SAMA instructs its member businesses to protect their critical operations and technologies and those of their employees, third-party suppliers, and members.
It is important to have a well-defined and improved CSC to ensure that the technologies at work do not introduce any threats to the system. The penetration of cybersecurity requirements should start with HR processes.
Employees of member businesses should be vetted from an early stage of processing, and the proper measures should be taken throughout the employee lifecycle.
According to SAMA, robust physical security measures should be taken to keep physical assets out of the reach of all security threats.
Sufficient security controls should be in place to ensure that unauthorized access to members' physical property does not occur. The most viable security controls that SAMA suggests in this regard are the use of advanced monitoring and surveillance tools, the protection of data centre tools, the use of resourceful environmental protection measures, the supervision of data access, and the analysis of all access control measures in place to prevent unauthorized access.
Application security is also included in SAMA. All applications/software used by financial institutions must adopt a viable SDLC approach and use secure code standards. Sufficient attention is also paid to identity and access management. Access control, user access management and user request management must be regularly monitored and regulated.
This domain includes much more. It is extensive, and the image below can provide more clarity.
4. Cyber Security of Third Parties
This SAMA review domain fully focuses on third-party services and their security review. Member Firms should make increased efforts to ensure that all third-party resources are secure and free of cybersecurity threats. Some of the recommended security checks are here:
- Incorporating risk assessment into the procurement process
- Have clear security requirements
- Testing security controls used by third-party vendors
- Termination of the contract if the seller does not comply with the best security controls
- Compliance with SAMA outsourcing controls when outsourcing technology or talent
- Request SAMA approval before using any cloud service or device
- Make sure that the chosen cloud service provider does not use the data for personal use
- Granting membership termination rights to member companies
- Conducting cyber security audits of the cloud provider at regular intervals
SAMA has covered extensive security checks related to vendors, suppliers, and other external third-party sources.
Conclusion
Maintaining a healthy cybersecurity infrastructure is essential for any financial institution. Ignoring the first signs of vulnerability can prove very fatal in the future. The SAMA Cybersecurity Framework operates as a fully standardized CSC and processes for each SAMA member.
SAMA enables financial institutions to better respond to hidden threats by explaining security maturity levels, cybersecurity risks, and remedial responses in detail. As the framework encourages the adoption of the latest cybersecurity technology, its implementation will surely improve the security posture of Saudi financial institutions.SAMA instructs its member businesses to protect key operations and technologies of their own, as well as employees, third-party suppliers, and members.

