SAMA CSF ↔ SAMA ITGF ↔ NCA ECC-2 Crosswalk

The 38-control curated ECC-2:2024 pass, mapped to SAMA Cyber Security Framework v1.0 and the SAMA IT Governance Framework, with the evidence a supervisory examination typically requests per control area. Scope: a curated subset of ECC-2:2024's 108 main controls — not full-framework coverage.

Provenance: ECC-2 and CSF mappings carried from the Security Lab crosswalk (author-reviewed, checked against the SAMA Rulebook). ITGF references checked against the official framework text on the SAMA Rulebook in an AI-assisted review pass (all 38 rows, last pass 2026-08-09), with Mohammed AlYahya as the domain expert of record; independently verify before use. Evidence column reflects generic examination practice, not any institution's examination. Mapping strength: Direct = substantially the same requirement; Partial = meaningful but incomplete overlap. The published ITGF text does not reference COBIT (zero occurrences); any COBIT context shown is an analytical annotation, not a statement of the framework. Where no subdomain covers an obligation, the row says so rather than forcing a fit.
NCA ECC-2:2024SAMA CSF v1.0SAMA ITGFEvidence a SAMA examination typically requests
Governance
1-1-1
Cybersecurity strategy defined, documented, approved
Direct
3.1.2
Cyber Security Strategy
Partial
3.1.2
Information Technology Strategy
Strategy approved by the authority the applicable framework mandates: strategy document showing the approval date, the linked implementation roadmap with the current-to-target gap analysis, and minutes recording progress reported against it. For the ITGF line specifically, examiners expect ITSC approval and board endorsement of the IT strategy (3.1.5) and evidence of the periodic review or the material-change trigger that prompted the last update.
1-2-1
Independent cybersecurity department established
Partial
3.1.1
Cyber Security Governance
Partial
3.1.1
Information Technology Governance
Approved organisation chart showing reporting lines, the head-of-function appointment letter and job description, and charter or committee documents evidencing a reporting line outside IT operations. On the ITGF side examiners also request the CIO appointment file: evidence the CIO is a full-time senior manager and a Saudi national, the qualification evidence, and SAMA's written no-objection letter obtained prior to the assignment (3.1.1 control requirement 6).
1-2-3
Cybersecurity supervisory committee
Direct
3.1.1
Cyber Security Governance
Partial
3.1.1
Information Technology Governance
Committee charter or terms of reference with membership and quorum, dated minutes covering the last twelve months, and evidence that decisions and risks were escalated to the board. For the ITGF line the charter is tested against the five elements 3.1.1 enumerates, the minimum quarterly meeting cadence, board approval of the charter (3.1.5), and attendance evidence for the CRO, CISO, compliance officer, business heads and CIO.
1-3-1
Policies and procedures documented and approved
Direct
3.1.3
Cyber Security Policy
Partial
3.1.4
Information Technology Policy and Procedures
Policy register showing version, approving authority, approval date and next review date; the approval minutes; and staff acknowledgement or controlled-distribution records. On the ITGF line examiners test the policy against the four contents 3.1.4 requires, evidence that the cyber security, finance and HR policies were taken as input, and the documentation pyramid of policy, standards and procedures that section 2.4.1 expects at maturity level 3.
1-5-1
Risk-management methodology approved
Direct
3.2.1
Cyber Security Risk Management
Direct
3.2.1
Managing IT Risks
Approved risk-management methodology with impact and likelihood scales and risk-appetite thresholds, a risk-register extract showing owners, treatment plans and due dates, and minutes of the committee that reviews the register. On the ITGF line examiners also test the register against the analysis fields 3.2.2 enumerates (asset classification, threats, impact and likelihood, existing controls, risk owner, implementation owner, inherent and residual risk), the annual assessment of all mission-critical assets, and defined IT key risk indicators.
1-7-1
Compliance with nationally approved international commitments
Partial
3.2.2
Regulatory Compliance
Partial
3.1.6
Regulatory Compliance
Regulatory-obligations register mapped to internal controls and owners, the most recent compliance assessment against that register, and a remediation tracker for identified gaps. The ITGF names the register explicitly - an up-to-date log of legal, regulatory and contractual requirements with impact and required actions - plus evidence that representatives from key areas of the organisation participated and that IT policies, standards and procedures were updated as a result.
1-8-1
Periodic internal cybersecurity review
Direct
3.2.4
Cyber Security Review
None
No equivalent
Approved annual review plan, completed control self-assessment workpapers with the evidence supporting each maturity rating, and a findings log showing remediation status and re-test results. On the ITGF line examiners also request the KPI catalogue with target values and thresholds, the deviation analysis and remedial actions, the reporting pack to senior management and the ITSC, and the completed SAMA self-assessment questionnaire referenced in section 2.3.
1-8-2
Independent cybersecurity audit
Direct
3.2.5
Cyber Security Audits
Direct
3.1.7
Internal IT Audit
Cybersecurity-scoped audit plan and report by a function independent of the cybersecurity department, evidence of the auditor's independence and conflict-of-interest handling, and the findings tracker with closure evidence. On the ITGF line examiners test the documented audit cycle, audit-committee approval of the plan, the auditors' competency and certification records, the report format against the minimum contents 3.1.7 lists, and the observation follow-up log.
1-9-1
Personnel cybersecurity requirements defined
Direct
3.3.1
Human Resources
Partial
3.1.8
Staff Competence and Training
HR procedure showing the security steps at joiner, mover and leaver stages, sample onboarding and termination checklists, and access-revocation records timed against leaving dates. On the ITGF line examiners request the critical-IT-role register, evidence that no critical role rests on a single individual, the required-certification list with held certifications, the periodic staffing evaluation, and the IT succession plan agreed with HR.
1-9-3
Pre-employment requirements (NDA clauses, screening/vetting)
Direct
3.3.1
Human Resources
None
No equivalent
Signed confidentiality and non-disclosure undertakings on file, background-screening records for staff and contractors in technology and security roles, and employment contracts evidencing the security clauses.
1-10-1
Awareness program developed and approved
Direct
3.1.6
Cyber Security Awareness
Partial
3.1.8
Staff Competence and Training
Approved awareness plan or calendar, completion statistics by population including senior management and third parties, phishing-simulation results with the follow-up training given, and dated copies of the materials used. On the ITGF line examiners request the approved annual IT training plan, its periodic review, delivery records for existing and new IT staff and for contractors, and the specialist-training records for critical-role, development and risk-assessment staff.
Defense
2-1-1
Asset-management requirements defined
Direct
3.3.3
Asset Management
Direct
3.3.1
Manage Assets
Asset inventory or CMDB extract showing owner, classification, location and criticality; reconciliation between the inventory and network-discovery output; and the asset-lifecycle procedure covering acquisition through disposal. The ITGF is unusually prescriptive on register contents, so examiners test the register against the seventeen fields 3.3.1 control requirement 4 enumerates - including PCI in-scope flags, backup information, licence and service-contract data, technical contacts, acceptable downtime aligned to the BCM business impact analysis, financial impact per hour of downtime, and vendor SLA and classification details - plus the yearly update evidence and the critical-asset list.
2-1-3
Acceptable-use policy defined and communicated
None
No equivalent
Partial
3.3.6
Network Architecture and Monitoring
Approved acceptable-use policy showing its review date, signed user acknowledgements for a sample of staff and contractors, and evidence of communication to all users. On the ITGF line examiners look for the approved network architecture policy containing the acceptable-use stance, the secure-use rules for specific network resources and services, and the stated consequences of non-compliance.
2-1-5
Assets classified, labeled, and handled per regulation
Direct
3.3.3
Asset Management
Direct
3.3.1
Manage Assets
Approved classification scheme with the handling matrix per level, evidence of labelling on a sample of documents, systems and removable media, and data-owner sign-off on the classification of critical repositories. On the ITGF line examiners test asset-owner sign-off on classification and labelling for a sample of assets, alignment of that classification with cyber security controls, and controlled secure-disposal records at end of useful life.
2-2-1
IAM requirements defined
Direct
3.3.5
Identity and Access Management
Partial
3.3.1
Manage Assets
Access-control policy and the role-to-entitlement matrix, joiner/mover/leaver request and approval tickets, and periodic user-access review records signed off by system or data owners. On the ITGF line examiners look for asset-owner evidence of defining and reviewing access rights per asset, and the documented authorization profile matrix supporting segregation of duties within infrastructure components (3.3.6).
2-2-3
Minimum IAM requirements (authentication, MFA, least privilege, PAM, periodic review)
Partial
3.3.5
Identity and Access Management
Partial
3.3.6
Network Architecture and Monitoring
Privileged-account inventory with vaulting and session-recording evidence, multi-factor authentication configuration for remote and privileged access, and dated periodic access-review records showing that removals were actioned. On the ITGF line examiners test the centralised authentication server for network devices, the source-IP restriction and encrypted channel for remote administration, the time-bound approved vendor access records, and least-privilege configuration on hypervisors, host and guest operating systems.
2-3-1
System-protection requirements defined
Partial
3.3.8
Infrastructure Security
Partial
3.3.11
Virtualization
Approved hardening baselines per platform, anti-malware coverage report reconciled to the asset inventory, and configuration-compliance scan results with approved exceptions. On the ITGF line examiners request the CMDB with configuration-item criticality and interrelationships, the periodic configuration-item verification records, and the approved minimum baseline security standards for virtual and container components with evidence of their application.
2-3-3
Minimum system protection (anti-malware, external media, patching, clock sync)
Partial
3.3.8
Infrastructure Security
Partial
3.4.9
Patch Management
Patch-compliance report by severity with aging against the remediation SLA, anti-malware console coverage and signature-currency report, removable-media restriction evidence at both policy and technical level, and the time-synchronisation standard with a sample of configured hosts. On the ITGF line examiners additionally test the cyber security sign-off on patch impact assessments, test-environment evidence prior to production deployment, the patch window communicated to business in advance and outside freezing periods, and the vendor-feed monitoring records.
2-4-1
Email-protection requirements defined
Partial
3.3.8
Infrastructure Security
None
No equivalent
Email gateway configuration for anti-spam, anti-malware and attachment sandboxing; the sender-authentication records (SPF, DKIM, DMARC) published for the institution's domains; and phishing-report and blocking statistics for the period.
2-5-1
Network-security requirements defined
Partial
3.3.8
Infrastructure Security
Direct
3.3.6
Network Architecture and Monitoring
Approved network architecture and topology diagrams showing security zones, the firewall rulebase with business justification per rule and the date of its last review, and the network-segmentation standard. On the ITGF line examiners test the approved network architecture policy itself, the current complete network diagram, and the per-gateway service access rules ensuring 'only the authorized traffic is allowed to pass'.
2-5-3
Minimum network security (segmentation, secure browsing, wireless, IPS, DNS, DDoS)
Partial
3.3.8
Infrastructure Security
Partial
3.3.6
Network Architecture and Monitoring
Segmentation and DMZ design evidence with zone-to-zone rule matrices, firewall rule-review reports, IPS and anti-DDoS service configuration with tuning records, wireless authentication configuration, and DNS filtering or proxy policy with block-category evidence. On the ITGF line examiners specifically test the two-firewall path to the DMZ, proxy-enforced authenticated outbound browsing, visitor network isolation, active-scanning alert and block at the DMZ perimeter, and the WAF in front of customer-facing applications.
2-6-1
Mobile/BYOD security requirements defined
Partial
3.3.10
Bring Your Own Device (BYOD)
None
No equivalent
Mobile-device-management enrolment report reconciled to the device inventory, the BYOD policy with signed user consent, and configuration evidence for containerisation, encryption and remote wipe including a sample wipe record.
2-7-1
Data-protection requirements defined per legal requirements
Partial
3.3.3
Asset Management
Partial
3.3.1
Manage Assets
Data-protection standard tied to each classification level, DLP rule-set with blocked-event and incident reports, retention and secure-disposal records, and the data inventory or record of processing for personal data. On the ITGF line examiners also test the data-privacy regulations entry in the compliance log (3.1.6), retention periods set against legal and regulatory requirements in the backup strategy (3.3.10), and evidence that only sanitized data is used in test environments (3.4.5).
2-8-1
Cryptography requirements defined
Direct
3.3.9
Cryptography
None
No equivalent
Approved cryptographic standard listing permitted algorithms, key lengths and prohibited primitives; key-management procedures with custodian assignment and dual-control records; the HSM inventory; and the certificate register with expiry monitoring.
2-9-1
Backup-and-recovery requirements defined
Partial
3.3.8
Infrastructure Security
Direct
3.3.10
Data Backup and Recoverability
Backup policy stating RPO and RTO by system tier, backup success and failure reports for the period, restore-test reports with dates and outcomes, and evidence of offsite or immutable copies. On the ITGF line examiners also test alignment of the strategy with the SAMA BCM Framework, the defined minimum backup scope, replication-sync issue resolution against RPO and RTO, the alternate redundancy mechanism such as transaction dumps in addition to full database backups, media labelling, and encryption of USB and other media before offsite transport.
2-10-1
Vulnerability-management requirements defined
Direct
3.3.17
Vulnerability Management
Partial
3.4.9
Patch Management
Vulnerability-management procedure with severity-based remediation SLAs, scan reports evidencing coverage of the full asset estate including externally facing systems, and the remediation-aging and exception register with approved compensating controls. On the ITGF line examiners test the periodic scan or inspection records for outdated patches and vulnerabilities, the vendor and third-party vulnerability feed monitoring, and the change records through which remediation was deployed.
2-11-1
Penetration-testing requirements defined
Partial
3.3.17
Vulnerability Management
Partial
3.4.5
Testing
Annual penetration-test plan and scope covering internet-facing and critical internal systems, the independent tester's report, retest evidence closing high and critical findings, and the tester's independence and qualification records. On the ITGF line examiners test security-testing evidence within the change record for a sample of changes, the approved test cases including negative scenarios, and the cyber security function's review and approval prior to CAB submission.
2-12-1
Logging-and-monitoring requirements defined
Direct
3.3.14
Cyber Security Event Management
Partial
3.3.6
Network Architecture and Monitoring
Logging standard listing mandatory event sources, event types and retention periods; the SIEM use-case and alert inventory; log-source coverage reconciled to the critical-asset list; and log-integrity protection configuration. On the ITGF line examiners test the centralised log server collecting from all network devices, the administrative and login trail configuration, resource-utilisation monitoring, and virtual-machine audit logging covering creation, deployment and removal, root and administrative activity, and system-level object changes.
2-12-3
Minimum logging (critical assets, privileged/remote access, SIEM, continuous monitoring, 12-month retention)
Direct
3.3.14
Cyber Security Event Management
Partial
3.3.6
Network Architecture and Monitoring
SIEM onboarding list with a log-source health report, retention configuration evidencing at least twelve months of searchable logs, monitoring-coverage and shift-handover records, and a sample of alert-triage tickets showing time to acknowledge and to close. The twelve-month retention figure is stated by the ITGF itself for network device logs, so examiners test the syslog server retention configuration directly against it.
2-13-1
Incident-and-threat-management requirements defined
Partial
3.3.15
Cyber Security Incident Management
Partial
3.3.8
IT Incident Management
Incident-response plan with a severity matrix and the regulatory notification timelines, an incident-register extract showing detection, containment and closure timestamps, post-incident review reports with lessons-learned actions, and records of the most recent tabletop exercise. The ITGF names the regulatory artifacts precisely: evidence of immediate notification to the General Department of Cyber Risk Control for incidents classified Medium or above that impact customers and for disruption or slowness in critical customer-facing applications, notification before any media disclosure, and the detailed incident report submitted within five days containing the nine minimum contents 3.3.8 lists.
2-14-1
Physical-security requirements defined
Direct
3.3.2
Physical Security
Partial
3.3.5
Manage Data Center
Data-centre access list with periodic recertification, badge-access logs and visitor register for a sample period, CCTV retention configuration, environmental-control maintenance and test records for power, cooling and fire suppression, and secure media-destruction certificates. The ITGF enumerates its expected controls, so examiners test each of the eight named items directly, plus the escorted-visitor logs and, where the data centre is outsourced, the documented business case and the defined nature and type of provider access.
2-15-1
Web-application-security requirements defined
Direct
3.3.6
Application Security
Partial
3.4.4
System Development
SDLC procedure showing the security gates and who signs them, the secure-coding standard, pre-go-live application security test results (static, dynamic and where applicable penetration test), WAF configuration and rule-tuning evidence, and the release approval records. The ITGF names two artifacts precisely: the secure code review report, or an independent assurance statement where the source code is not held by the institution, and the WAF in front of customer-facing applications.
Resilience
3-1-1
Resilience requirements within BCM defined
Partial
3.1.3
Cyber Security Policy
Partial
3.3.2
Interdependencies
Business impact analysis covering critical systems with RTO and RPO, approved business-continuity and disaster-recovery plans with approval dates, and evidence that cyber scenarios such as ransomware are inside the BCM scope. On the ITGF line examiners request the critical-asset interdependency register, the governance model covering interdependencies with service providers and government institutions, BCP test evidence exercising interdependency scenarios, and the resilience measures recorded for critical assets.
3-1-3
Minimum resilience requirements (continuity of security systems, incident response plans, DRP)
Partial
3.3.15
Cyber Security Incident Management
Partial
3.3.10
Data Backup and Recoverability
Approved continuity, incident-response and disaster-recovery requirements and plans covering cybersecurity systems, with owners and review dates. On the ITGF line examiners also test defined RTOs for payment and customer-facing services, replication-sync issue resolution against agreed RPO and RTO, backup-media recovery test records, and evidence that changes released to production were also released to the corresponding disaster recovery system (3.4.7).
Third-Party & Cloud
4-1-1
Third-party contract cybersecurity requirements defined
Direct
3.4.1
Contract and Vendor Management
Direct
3.3.3
Manage Service Level Agreements
Third-party register with criticality tiering, pre-onboarding due-diligence and security-assessment records, the contract template containing the security clause set, and ongoing monitoring or SLA review reports. On the ITGF line examiners test the signed SLA itself, the procurement-stage risk assessment, the CIA safeguard clauses, and the periodic reporting, review and evaluation of contractually agreed SLA requirements including the escalation process on breach.
4-1-2
Minimum third-party contract clauses (NDA/secure removal, incident communication, policy compliance)
Direct
3.4.1
Contract and Vendor Management
Partial
3.3.3
Manage Service Level Agreements
A sample of executed contracts evidencing confidentiality, right-to-audit, incident-notification and secure data-return or destruction clauses, plus destruction certificates obtained at contract exit. On the ITGF line examiners also test the exit, termination and renewal clauses including escrow where applicable, the framework-compliance clause naming the SAMA CSF, BCM and ITGF, and the onsite-support undertaking with its defined response timeline.
4-1-3
Outsourcing/managed-services requirements (pre-contract risk assessment, KSA-located managed SOCs)
Direct
3.4.2
Outsourcing
Partial
3.3.3
Manage Service Level Agreements
Pre-contract outsourcing risk assessment and business case, the regulatory notification or no-objection correspondence where the arrangement is material, agreement clauses on subcontracting and data location, evidence of in-Kingdom hosting or SOC location, and the provider's third-party assurance report (for example ISAE 3402 or SOC 2) with the institution's review notes. On the ITGF line examiners test the procurement-stage risk assessment, the IT risk assessment initiated at the point of outsourcing, and evidence that the provider's availability and data-protection processes were assessed.
4-2-1
Cloud/hosting cybersecurity requirements defined
Direct
3.4.3
Cloud Computing
Partial
3.3.5
Manage Data Center
Cloud-service register recording the data classification hosted in each service, cloud risk assessments and provider due-diligence (certifications and assurance reports), data-residency evidence for in-Kingdom workloads, the signed shared-responsibility matrix, configuration-baseline or CSPM reports, and the documented exit and portability plan. On the ITGF line examiners test the documented business case for any outsourced data centre, the defined nature and type of provider access, and evidence of compliance with the SAMA Outsourcing Rules and Cybersecurity Framework the subdomain points to.