The 38-control curated ECC-2:2024 pass, mapped to SAMA Cyber Security Framework v1.0 and the SAMA IT Governance Framework, with the evidence a supervisory examination typically requests per control area. Scope: a curated subset of ECC-2:2024's 108 main controls — not full-framework coverage.
| NCA ECC-2:2024 | SAMA CSF v1.0 | SAMA ITGF | Evidence a SAMA examination typically requests |
|---|---|---|---|
| Governance | |||
1-1-1 Cybersecurity strategy defined, documented, approved | Direct 3.1.2 Cyber Security Strategy | Partial 3.1.2 Information Technology Strategy | Strategy approved by the authority the applicable framework mandates: strategy document showing the approval date, the linked implementation roadmap with the current-to-target gap analysis, and minutes recording progress reported against it. For the ITGF line specifically, examiners expect ITSC approval and board endorsement of the IT strategy (3.1.5) and evidence of the periodic review or the material-change trigger that prompted the last update. |
1-2-1 Independent cybersecurity department established | Partial 3.1.1 Cyber Security Governance | Partial 3.1.1 Information Technology Governance | Approved organisation chart showing reporting lines, the head-of-function appointment letter and job description, and charter or committee documents evidencing a reporting line outside IT operations. On the ITGF side examiners also request the CIO appointment file: evidence the CIO is a full-time senior manager and a Saudi national, the qualification evidence, and SAMA's written no-objection letter obtained prior to the assignment (3.1.1 control requirement 6). |
1-2-3 Cybersecurity supervisory committee | Direct 3.1.1 Cyber Security Governance | Partial 3.1.1 Information Technology Governance | Committee charter or terms of reference with membership and quorum, dated minutes covering the last twelve months, and evidence that decisions and risks were escalated to the board. For the ITGF line the charter is tested against the five elements 3.1.1 enumerates, the minimum quarterly meeting cadence, board approval of the charter (3.1.5), and attendance evidence for the CRO, CISO, compliance officer, business heads and CIO. |
1-3-1 Policies and procedures documented and approved | Direct 3.1.3 Cyber Security Policy | Partial 3.1.4 Information Technology Policy and Procedures | Policy register showing version, approving authority, approval date and next review date; the approval minutes; and staff acknowledgement or controlled-distribution records. On the ITGF line examiners test the policy against the four contents 3.1.4 requires, evidence that the cyber security, finance and HR policies were taken as input, and the documentation pyramid of policy, standards and procedures that section 2.4.1 expects at maturity level 3. |
1-5-1 Risk-management methodology approved | Direct 3.2.1 Cyber Security Risk Management | Direct 3.2.1 Managing IT Risks | Approved risk-management methodology with impact and likelihood scales and risk-appetite thresholds, a risk-register extract showing owners, treatment plans and due dates, and minutes of the committee that reviews the register. On the ITGF line examiners also test the register against the analysis fields 3.2.2 enumerates (asset classification, threats, impact and likelihood, existing controls, risk owner, implementation owner, inherent and residual risk), the annual assessment of all mission-critical assets, and defined IT key risk indicators. |
1-7-1 Compliance with nationally approved international commitments | Partial 3.2.2 Regulatory Compliance | Partial 3.1.6 Regulatory Compliance | Regulatory-obligations register mapped to internal controls and owners, the most recent compliance assessment against that register, and a remediation tracker for identified gaps. The ITGF names the register explicitly - an up-to-date log of legal, regulatory and contractual requirements with impact and required actions - plus evidence that representatives from key areas of the organisation participated and that IT policies, standards and procedures were updated as a result. |
1-8-1 Periodic internal cybersecurity review | Direct 3.2.4 Cyber Security Review | None No equivalent | Approved annual review plan, completed control self-assessment workpapers with the evidence supporting each maturity rating, and a findings log showing remediation status and re-test results. On the ITGF line examiners also request the KPI catalogue with target values and thresholds, the deviation analysis and remedial actions, the reporting pack to senior management and the ITSC, and the completed SAMA self-assessment questionnaire referenced in section 2.3. |
1-8-2 Independent cybersecurity audit | Direct 3.2.5 Cyber Security Audits | Direct 3.1.7 Internal IT Audit | Cybersecurity-scoped audit plan and report by a function independent of the cybersecurity department, evidence of the auditor's independence and conflict-of-interest handling, and the findings tracker with closure evidence. On the ITGF line examiners test the documented audit cycle, audit-committee approval of the plan, the auditors' competency and certification records, the report format against the minimum contents 3.1.7 lists, and the observation follow-up log. |
1-9-1 Personnel cybersecurity requirements defined | Direct 3.3.1 Human Resources | Partial 3.1.8 Staff Competence and Training | HR procedure showing the security steps at joiner, mover and leaver stages, sample onboarding and termination checklists, and access-revocation records timed against leaving dates. On the ITGF line examiners request the critical-IT-role register, evidence that no critical role rests on a single individual, the required-certification list with held certifications, the periodic staffing evaluation, and the IT succession plan agreed with HR. |
1-9-3 Pre-employment requirements (NDA clauses, screening/vetting) | Direct 3.3.1 Human Resources | None No equivalent | Signed confidentiality and non-disclosure undertakings on file, background-screening records for staff and contractors in technology and security roles, and employment contracts evidencing the security clauses. |
1-10-1 Awareness program developed and approved | Direct 3.1.6 Cyber Security Awareness | Partial 3.1.8 Staff Competence and Training | Approved awareness plan or calendar, completion statistics by population including senior management and third parties, phishing-simulation results with the follow-up training given, and dated copies of the materials used. On the ITGF line examiners request the approved annual IT training plan, its periodic review, delivery records for existing and new IT staff and for contractors, and the specialist-training records for critical-role, development and risk-assessment staff. |
| Defense | |||
2-1-1 Asset-management requirements defined | Direct 3.3.3 Asset Management | Direct 3.3.1 Manage Assets | Asset inventory or CMDB extract showing owner, classification, location and criticality; reconciliation between the inventory and network-discovery output; and the asset-lifecycle procedure covering acquisition through disposal. The ITGF is unusually prescriptive on register contents, so examiners test the register against the seventeen fields 3.3.1 control requirement 4 enumerates - including PCI in-scope flags, backup information, licence and service-contract data, technical contacts, acceptable downtime aligned to the BCM business impact analysis, financial impact per hour of downtime, and vendor SLA and classification details - plus the yearly update evidence and the critical-asset list. |
2-1-3 Acceptable-use policy defined and communicated | None No equivalent | Partial 3.3.6 Network Architecture and Monitoring | Approved acceptable-use policy showing its review date, signed user acknowledgements for a sample of staff and contractors, and evidence of communication to all users. On the ITGF line examiners look for the approved network architecture policy containing the acceptable-use stance, the secure-use rules for specific network resources and services, and the stated consequences of non-compliance. |
2-1-5 Assets classified, labeled, and handled per regulation | Direct 3.3.3 Asset Management | Direct 3.3.1 Manage Assets | Approved classification scheme with the handling matrix per level, evidence of labelling on a sample of documents, systems and removable media, and data-owner sign-off on the classification of critical repositories. On the ITGF line examiners test asset-owner sign-off on classification and labelling for a sample of assets, alignment of that classification with cyber security controls, and controlled secure-disposal records at end of useful life. |
2-2-1 IAM requirements defined | Direct 3.3.5 Identity and Access Management | Partial 3.3.1 Manage Assets | Access-control policy and the role-to-entitlement matrix, joiner/mover/leaver request and approval tickets, and periodic user-access review records signed off by system or data owners. On the ITGF line examiners look for asset-owner evidence of defining and reviewing access rights per asset, and the documented authorization profile matrix supporting segregation of duties within infrastructure components (3.3.6). |
2-2-3 Minimum IAM requirements (authentication, MFA, least privilege, PAM, periodic review) | Partial 3.3.5 Identity and Access Management | Partial 3.3.6 Network Architecture and Monitoring | Privileged-account inventory with vaulting and session-recording evidence, multi-factor authentication configuration for remote and privileged access, and dated periodic access-review records showing that removals were actioned. On the ITGF line examiners test the centralised authentication server for network devices, the source-IP restriction and encrypted channel for remote administration, the time-bound approved vendor access records, and least-privilege configuration on hypervisors, host and guest operating systems. |
2-3-1 System-protection requirements defined | Partial 3.3.8 Infrastructure Security | Partial 3.3.11 Virtualization | Approved hardening baselines per platform, anti-malware coverage report reconciled to the asset inventory, and configuration-compliance scan results with approved exceptions. On the ITGF line examiners request the CMDB with configuration-item criticality and interrelationships, the periodic configuration-item verification records, and the approved minimum baseline security standards for virtual and container components with evidence of their application. |
2-3-3 Minimum system protection (anti-malware, external media, patching, clock sync) | Partial 3.3.8 Infrastructure Security | Partial 3.4.9 Patch Management | Patch-compliance report by severity with aging against the remediation SLA, anti-malware console coverage and signature-currency report, removable-media restriction evidence at both policy and technical level, and the time-synchronisation standard with a sample of configured hosts. On the ITGF line examiners additionally test the cyber security sign-off on patch impact assessments, test-environment evidence prior to production deployment, the patch window communicated to business in advance and outside freezing periods, and the vendor-feed monitoring records. |
2-4-1 Email-protection requirements defined | Partial 3.3.8 Infrastructure Security | None No equivalent | Email gateway configuration for anti-spam, anti-malware and attachment sandboxing; the sender-authentication records (SPF, DKIM, DMARC) published for the institution's domains; and phishing-report and blocking statistics for the period. |
2-5-1 Network-security requirements defined | Partial 3.3.8 Infrastructure Security | Direct 3.3.6 Network Architecture and Monitoring | Approved network architecture and topology diagrams showing security zones, the firewall rulebase with business justification per rule and the date of its last review, and the network-segmentation standard. On the ITGF line examiners test the approved network architecture policy itself, the current complete network diagram, and the per-gateway service access rules ensuring 'only the authorized traffic is allowed to pass'. |
2-5-3 Minimum network security (segmentation, secure browsing, wireless, IPS, DNS, DDoS) | Partial 3.3.8 Infrastructure Security | Partial 3.3.6 Network Architecture and Monitoring | Segmentation and DMZ design evidence with zone-to-zone rule matrices, firewall rule-review reports, IPS and anti-DDoS service configuration with tuning records, wireless authentication configuration, and DNS filtering or proxy policy with block-category evidence. On the ITGF line examiners specifically test the two-firewall path to the DMZ, proxy-enforced authenticated outbound browsing, visitor network isolation, active-scanning alert and block at the DMZ perimeter, and the WAF in front of customer-facing applications. |
2-6-1 Mobile/BYOD security requirements defined | Partial 3.3.10 Bring Your Own Device (BYOD) | None No equivalent | Mobile-device-management enrolment report reconciled to the device inventory, the BYOD policy with signed user consent, and configuration evidence for containerisation, encryption and remote wipe including a sample wipe record. |
2-7-1 Data-protection requirements defined per legal requirements | Partial 3.3.3 Asset Management | Partial 3.3.1 Manage Assets | Data-protection standard tied to each classification level, DLP rule-set with blocked-event and incident reports, retention and secure-disposal records, and the data inventory or record of processing for personal data. On the ITGF line examiners also test the data-privacy regulations entry in the compliance log (3.1.6), retention periods set against legal and regulatory requirements in the backup strategy (3.3.10), and evidence that only sanitized data is used in test environments (3.4.5). |
2-8-1 Cryptography requirements defined | Direct 3.3.9 Cryptography | None No equivalent | Approved cryptographic standard listing permitted algorithms, key lengths and prohibited primitives; key-management procedures with custodian assignment and dual-control records; the HSM inventory; and the certificate register with expiry monitoring. |
2-9-1 Backup-and-recovery requirements defined | Partial 3.3.8 Infrastructure Security | Direct 3.3.10 Data Backup and Recoverability | Backup policy stating RPO and RTO by system tier, backup success and failure reports for the period, restore-test reports with dates and outcomes, and evidence of offsite or immutable copies. On the ITGF line examiners also test alignment of the strategy with the SAMA BCM Framework, the defined minimum backup scope, replication-sync issue resolution against RPO and RTO, the alternate redundancy mechanism such as transaction dumps in addition to full database backups, media labelling, and encryption of USB and other media before offsite transport. |
2-10-1 Vulnerability-management requirements defined | Direct 3.3.17 Vulnerability Management | Partial 3.4.9 Patch Management | Vulnerability-management procedure with severity-based remediation SLAs, scan reports evidencing coverage of the full asset estate including externally facing systems, and the remediation-aging and exception register with approved compensating controls. On the ITGF line examiners test the periodic scan or inspection records for outdated patches and vulnerabilities, the vendor and third-party vulnerability feed monitoring, and the change records through which remediation was deployed. |
2-11-1 Penetration-testing requirements defined | Partial 3.3.17 Vulnerability Management | Partial 3.4.5 Testing | Annual penetration-test plan and scope covering internet-facing and critical internal systems, the independent tester's report, retest evidence closing high and critical findings, and the tester's independence and qualification records. On the ITGF line examiners test security-testing evidence within the change record for a sample of changes, the approved test cases including negative scenarios, and the cyber security function's review and approval prior to CAB submission. |
2-12-1 Logging-and-monitoring requirements defined | Direct 3.3.14 Cyber Security Event Management | Partial 3.3.6 Network Architecture and Monitoring | Logging standard listing mandatory event sources, event types and retention periods; the SIEM use-case and alert inventory; log-source coverage reconciled to the critical-asset list; and log-integrity protection configuration. On the ITGF line examiners test the centralised log server collecting from all network devices, the administrative and login trail configuration, resource-utilisation monitoring, and virtual-machine audit logging covering creation, deployment and removal, root and administrative activity, and system-level object changes. |
2-12-3 Minimum logging (critical assets, privileged/remote access, SIEM, continuous monitoring, 12-month retention) | Direct 3.3.14 Cyber Security Event Management | Partial 3.3.6 Network Architecture and Monitoring | SIEM onboarding list with a log-source health report, retention configuration evidencing at least twelve months of searchable logs, monitoring-coverage and shift-handover records, and a sample of alert-triage tickets showing time to acknowledge and to close. The twelve-month retention figure is stated by the ITGF itself for network device logs, so examiners test the syslog server retention configuration directly against it. |
2-13-1 Incident-and-threat-management requirements defined | Partial 3.3.15 Cyber Security Incident Management | Partial 3.3.8 IT Incident Management | Incident-response plan with a severity matrix and the regulatory notification timelines, an incident-register extract showing detection, containment and closure timestamps, post-incident review reports with lessons-learned actions, and records of the most recent tabletop exercise. The ITGF names the regulatory artifacts precisely: evidence of immediate notification to the General Department of Cyber Risk Control for incidents classified Medium or above that impact customers and for disruption or slowness in critical customer-facing applications, notification before any media disclosure, and the detailed incident report submitted within five days containing the nine minimum contents 3.3.8 lists. |
2-14-1 Physical-security requirements defined | Direct 3.3.2 Physical Security | Partial 3.3.5 Manage Data Center | Data-centre access list with periodic recertification, badge-access logs and visitor register for a sample period, CCTV retention configuration, environmental-control maintenance and test records for power, cooling and fire suppression, and secure media-destruction certificates. The ITGF enumerates its expected controls, so examiners test each of the eight named items directly, plus the escorted-visitor logs and, where the data centre is outsourced, the documented business case and the defined nature and type of provider access. |
2-15-1 Web-application-security requirements defined | Direct 3.3.6 Application Security | Partial 3.4.4 System Development | SDLC procedure showing the security gates and who signs them, the secure-coding standard, pre-go-live application security test results (static, dynamic and where applicable penetration test), WAF configuration and rule-tuning evidence, and the release approval records. The ITGF names two artifacts precisely: the secure code review report, or an independent assurance statement where the source code is not held by the institution, and the WAF in front of customer-facing applications. |
| Resilience | |||
3-1-1 Resilience requirements within BCM defined | Partial 3.1.3 Cyber Security Policy | Partial 3.3.2 Interdependencies | Business impact analysis covering critical systems with RTO and RPO, approved business-continuity and disaster-recovery plans with approval dates, and evidence that cyber scenarios such as ransomware are inside the BCM scope. On the ITGF line examiners request the critical-asset interdependency register, the governance model covering interdependencies with service providers and government institutions, BCP test evidence exercising interdependency scenarios, and the resilience measures recorded for critical assets. |
3-1-3 Minimum resilience requirements (continuity of security systems, incident response plans, DRP) | Partial 3.3.15 Cyber Security Incident Management | Partial 3.3.10 Data Backup and Recoverability | Approved continuity, incident-response and disaster-recovery requirements and plans covering cybersecurity systems, with owners and review dates. On the ITGF line examiners also test defined RTOs for payment and customer-facing services, replication-sync issue resolution against agreed RPO and RTO, backup-media recovery test records, and evidence that changes released to production were also released to the corresponding disaster recovery system (3.4.7). |
| Third-Party & Cloud | |||
4-1-1 Third-party contract cybersecurity requirements defined | Direct 3.4.1 Contract and Vendor Management | Direct 3.3.3 Manage Service Level Agreements | Third-party register with criticality tiering, pre-onboarding due-diligence and security-assessment records, the contract template containing the security clause set, and ongoing monitoring or SLA review reports. On the ITGF line examiners test the signed SLA itself, the procurement-stage risk assessment, the CIA safeguard clauses, and the periodic reporting, review and evaluation of contractually agreed SLA requirements including the escalation process on breach. |
4-1-2 Minimum third-party contract clauses (NDA/secure removal, incident communication, policy compliance) | Direct 3.4.1 Contract and Vendor Management | Partial 3.3.3 Manage Service Level Agreements | A sample of executed contracts evidencing confidentiality, right-to-audit, incident-notification and secure data-return or destruction clauses, plus destruction certificates obtained at contract exit. On the ITGF line examiners also test the exit, termination and renewal clauses including escrow where applicable, the framework-compliance clause naming the SAMA CSF, BCM and ITGF, and the onsite-support undertaking with its defined response timeline. |
4-1-3 Outsourcing/managed-services requirements (pre-contract risk assessment, KSA-located managed SOCs) | Direct 3.4.2 Outsourcing | Partial 3.3.3 Manage Service Level Agreements | Pre-contract outsourcing risk assessment and business case, the regulatory notification or no-objection correspondence where the arrangement is material, agreement clauses on subcontracting and data location, evidence of in-Kingdom hosting or SOC location, and the provider's third-party assurance report (for example ISAE 3402 or SOC 2) with the institution's review notes. On the ITGF line examiners test the procurement-stage risk assessment, the IT risk assessment initiated at the point of outsourcing, and evidence that the provider's availability and data-protection processes were assessed. |
4-2-1 Cloud/hosting cybersecurity requirements defined | Direct 3.4.3 Cloud Computing | Partial 3.3.5 Manage Data Center | Cloud-service register recording the data classification hosted in each service, cloud risk assessments and provider due-diligence (certifications and assurance reports), data-residency evidence for in-Kingdom workloads, the signed shared-responsibility matrix, configuration-baseline or CSPM reports, and the documented exit and portability plan. On the ITGF line examiners test the documented business case for any outsourced data centre, the defined nature and type of provider access, and evidence of compliance with the SAMA Outsourcing Rules and Cybersecurity Framework the subdomain points to. |