Compliance with a cybersecurity framework is more than having policies and security tools in place. Financial institutions also need to know whether controls are applied consistently, monitored adequately, and effective against the risks they address.
Table of Contents
ToggleThis is where the SAMA CSF comes in. The SAMA Cybersecurity Framework provides organizations regulated by the Saudi Central Bank with a structured approach to managing cyber risk, implementing controls, measuring maturity, and enhancing their security. Rather than simply asking whether a control exists, it considers how the control works in practice. Falling short isn’t just a failed assessment; it leaves the underlying risk unmanaged and brings regulatory scrutiny and remediation timelines with it.
SAMA CSF at a Glance
| Key Area | Details |
| Framework | SAMA Cybersecurity Framework |
| Issued by | Saudi Central Bank (SAMA) |
| Applies to | SAMA-regulated Member Organizations |
| Core domains | Four |
| Maturity levels | Level 0 to Level 5 |
| Expected maturity | Level 3 or higher |
| Approach | Principle-based and risk-based |
| Focus | Governance, risk, operations, technology, and third parties |
What Is SAMA CSF?
The SAMA CSF, also known as the Saudi Central Bank Cyber Security Framework or SAMA Cyber Security Framework, is the cybersecurity framework established by the Saudi Central Bank for regulated Member Organizations.
It aims to establish a common cybersecurity approach, enhance cybersecurity maturity, and ensure proper management of cybersecurity risks. It is a principle-based approach, allowing organizations to apply its requirements in line with their context and risk profile.
Book a Free
Demo Call
with Our Expert
Discover how Threatcop protects your workforce from modern cyber threats.
To Whom Does the SAMA Framework Apply?
The framework applies to Member Organizations regulated by SAMA, including banking, insurance and reinsurance, financing, credit bureaus, financial market infrastructure, and others. Specific requirements may vary depending on the organization’s regulatory scope.
Cybersecurity is not only an IT responsibility. An organization’s security posture can be affected by leadership, employees, business functions, technology teams, and third parties.
The Four Domains of SAMA CSF
The framework consists of four domains covering leadership and governance, risk management and compliance, operations and technology, and third-party security. These four domains break down further into 32 subdomains, each with its own specific control objectives.
1. Cyber Security Leadership and Governance
This domain relates to cybersecurity strategy, policy, responsibility, oversight, and accountability. Good governance ensures that cybersecurity risks are presented to the necessary decision-makers and that security priorities have clear ownership.
2. Cyber Security Risk Management and Compliance
Organizations need to identify, assess, manage, and monitor cybersecurity risks by understanding key assets, threats, existing controls, and gaps.
Particular attention is given to connecting documentation with implementation:
- Policy: What should be done
- Procedure: How it should be done
- Monitoring: How the organization knows it is being done
- Evidence: What proves it is being done
3. Cybersecurity Operations and Technology
This area relates to the technical and operational capabilities used to protect information assets and services. Depending on the requirements, this can range from access management and vulnerability management to security monitoring, incident management, and security architecture.
4. Third-Party Cyber Security
Vendors and service providers with access to business processes, systems, and data can pose risks. Organizations should understand these risks, set appropriate security requirements, and monitor third-party security throughout the relationship.
SAMA CSF Maturity Levels Explained
The maturity model illustrates the evolution of cybersecurity practices, from informal to measurable, continuously improving controls. It comprises six levels, ranging from Level 0 to Level 5, with SAMA stating that Member Organizations should operate at Level 3 or higher. A small number of subdomains, such as security operations center capabilities and event management, are expected to reach Level 4.
| Maturity Level | What It Means |
| Level 0: Non-Existent | Appropriate cybersecurity controls are not in place. |
| Level 1: Ad-Hoc | Some security practices exist but are not consistent. |
| Level 2: Repeatable but Informal | Practices are repeatable but remain mostly informal. |
| Level 3: Defined | Controls are defined, approved, implemented, and monitored. |
| Level 4: Managed and Measurable | Control effectiveness is measured and evaluated. |
| Level 5: Adaptive | Cybersecurity is continuously improved and integrated with enterprise risk management. |
Why Level 3 Matters
Level 3 is a level that organizations should understand clearly. Controls need to be defined, approved, and implemented through appropriate processes, with compliance monitored.
For instance, an access-control policy alone is not a strong indicator of effective access management. Defined procedures, ownership, access reviews, monitoring, and supporting evidence are also required.
How to Prepare for SAMA CSF Compliance
There are five practical steps organizations can follow:
- Take stock: Identify applicable requirements and compare them with existing controls, policies, procedures, technologies, evidence, and responsibilities.
- Prioritize gaps: Consider asset criticality, business impact, threat exposure, regulatory importance, and existing safeguards when deciding which gaps to address first.
- Set ownership: Make sure major controls and remediation activities have clearly defined owners.
- Keep evidence: Integrate approvals, testing results, monitoring information, access reviews, logs, and assessments into normal security operations.
- Assess effectiveness: Evaluate whether controls are working as intended and use the results to improve the program.
The Human Layer of Cybersecurity
That same policy-procedure-monitoring-evidence chain applies to people, not just systems, and it is often hardest to hold together here. Strong technical controls still depend on people. Employees interact with email, credentials, applications, customer information, and business systems every day. These interactions can be targeted through phishing, impersonation, and social engineering attacks.
Employee security is therefore critical to overall cybersecurity maturity. Training completion alone does not indicate whether employees can detect and respond to threats. Organizations also need to understand risky behavior and determine whether their awareness efforts are effective.
Where Threatcop Fits
Threatcop’s People Security Management approach focuses on this human layer through simulated attacks, employee risk assessment, training, security awareness, and reporting.
The AAPE process, Assess, Aware, Protect, and Empower, supports an ongoing approach to security awareness. Organizations can assess employee risk, test responses to realistic scenarios, provide targeted awareness, and track progress.
What Should a Good SAMA CSF Program Achieve?
An established program should provide security leaders with a clear understanding of their cybersecurity environment. They should know the applicable requirements, their current maturity level, critical gaps, gap owners, evidence of implementation, and whether controls, including the people who operate them, are working effectively.
The best programs bring together governance, risk, technology, controls, evidence, people, and continuous improvement. This turns compliance into a long-term security practice instead of merely an annual evaluation.
Final Thoughts
The SAMA CSF provides regulated financial institutions with a framework for managing cyber risk, implementing controls, measuring maturity, and enhancing their security posture.
Passing an assessment should not be the only goal. The objective should be to develop a cybersecurity program that can demonstrate what it protects, how its controls operate, whether they are effective, and what it needs to improve next.
If your program can show policies and tools but not evidence that they are working, particularly on the human side, that is the gap to prioritize. Talk to Threatcop about running an AAPE assessment against your current SAMA CSF maturity baseline.
FAQs
What is SAMA CSF?
SAMA CSF is the SAMA Cybersecurity Framework issued by the Saudi Central Bank for Member Organizations. It provides cybersecurity principles, objectives, control considerations, and a maturity model for managing cybersecurity risk.
How many SAMA CSF domains are there?
There are four domains, broken into 32 subdomains: Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third-Party Cyber Security.
What can be done to prepare for the SAMA Framework?
Organizations should evaluate their existing posture, identify and prioritize gaps, establish control ownership, implement remediation, maintain control evidence, and evaluate control effectiveness.
Why are employees important to security?
Every day, employees interact with systems, information, credentials, and security controls. Security awareness, simulations, risk assessments, and targeted training can help organizations identify and reduce human-related cybersecurity risks.
