SAMA Cyber Security Framework
The Saudi Central Bank’s Cyber Security Framework, version 1.0 of May 2017, binds every Member Organization SAMA regulates: banks, insurers, financing companies, credit bureaus and the financial market infrastructure. Its subdomain 3.4.3, Cloud Computing, says a hybrid or public cloud service is used only after SAMA’s approval, and in principle only one located in Saudi Arabia, with explicit approval from SAMA for one outside. A hosted model is a cloud service, so this pack puts those two facts on the provider and holds every request to them at the call. Four further control considerations a gateway can show are mapped to the mechanism and the evidence.
It is a starting point and certifies nothing. The framework is principle-based: a consideration a Member Organization cannot implement is met by a compensating control, a risk acceptance and a waiver from SAMA, as section 2.2 says.
What it does
Section titled “What it does”The provider says what it is and where it is, in its metadata:
cloud: privatemarks an internal cloud, which subdomain 3.4.3 does not apply to. A model the Member Organization hosts itself is one.residency: sasays the service is located in Saudi Arabia.sama_approval: …records SAMA’s approval to use the service.sama_approval_abroad: …records SAMA’s explicit approval to use a service located outside Saudi Arabia.
| Rule | Refuses | Consideration |
|---|---|---|
sa-sama-csf-cloud-approved-by-sama |
a hybrid or public cloud provider that declares no SAMA approval | 3.4.3.4.a.2 |
sa-sama-csf-cloud-located-in-the-kingdom |
a provider not declared located in Saudi Arabia and without explicit approval for being outside | 3.4.3.4.b.1 |
The gateway reads that each approval is declared, not what it says. Put the reference of SAMA’s letter in the value, so the audit record and the provider block agree on which approval a request went out under. A provider that declares no residency is outside Saudi Arabia, and one that declares neither a private cloud nor an approval is refused. That is the direction that makes adding a provider safe.
Four considerations no rule can enforce are mapped: the review, audit
and monitoring rights over the provider, which the rules over provider
metadata and the access records are; classification, labelling and
handling of information assets, which the key’s classification
metadata carries for the caller; the circumstances when approved
cryptography applies, which the https scheme and the reversible
fpe redaction operator are; and protected, centrally analysed
security logs, which the signed audit trail shipped to the SIEM is.
The mapping says where to look. Whether the consideration is met is
yours to show.
Alongside the other Saudi packs
Section titled “Alongside the other Saudi packs”A Member Organization also falls under the Personal Data Protection Law, and the PDPL pack is the one that replaces personal data before a request leaves. This pack does not depend on it, because subdomain 3.4.3 is about the provider and not the request, but a bank adds both. The classification vocabulary this pack’s mapping refers to is the NDMO pack’s, whose levels the national classification sets; SAMA’s framework names classification and leaves the scheme to the Member Organization.
What it does not cover
Section titled “What it does not cover”- The other 31 subdomains. Governance, risk, human resources, architecture, identity, change, payments, electronic banking, incidents, threats and vulnerabilities are the Member Organization’s programme. The pack takes the two considerations in 3.4.3 a gateway between the organization and the provider can hold, and maps four more.
- Cardholder data. Section 1.4 says an organization that stores, processes or transmits cardholder data implements the PCI standard. A redaction of card numbers is the PDPL pack’s rule today; a PCI DSS pack would cite requirement 3 for it.
- The approval itself. The gateway reads that a provider declares one, not whether it exists, is current or covers this service.
- Data use limitations, segregation, continuity and exit in 3.4.3.4.c to 4.h. Those are contract terms, and the Member Organization’s due diligence.
- Maturity levels. The framework’s maturity model rates the process around a control. A rule at the call is evidence for level 3 and above; the process is yours.
Before you rely on it
Section titled “Before you rely on it”- The text is version 1.0 of May 2017, which the SAMA Rulebook lists as in force under circular 381000091275. Section 1.8 says a new version retires the preceding one; check the Rulebook for the edition your organization is held to.
- Adding this pack refuses every hybrid or public cloud provider
without
sama_approval, and every one abroad withoutsama_approval_abroad. Declare them, orcloud: private, on every provider first. - The control identifiers are the framework’s own numbering, subdomain then consideration. Each title is a paraphrase; check it against the text before a reviewer reads the audit trail through it.
Controls this pack cites
Section titled “Controls this pack cites”Every identifier below is declared in pack.yaml and named by a rule, an attachment or a mapping. A rule that cites one carries it onto every audit record it decides.
| Control | What it requires | Text |
|---|---|---|
sa-sama-csf:3.4.3.4.a.2 |
The Member Organization obtains SAMA approval prior to using cloud services or signing the contract with the cloud provider (3.4.3, control consideration 4.a.2). | citation |
sa-sama-csf:3.4.3.4.b.1 |
In principle only cloud services located in Saudi Arabia are used; for cloud services outside Saudi Arabia the Member Organization obtains explicit approval from SAMA (3.4.3, control consideration 4.b.1). | citation |
sa-sama-csf:3.4.3.4.g |
The Member Organization has the right to review, audit and examine the cloud service provider, and monitors compliance with the cloud computing policy (3.4.3, control considerations 2 and 4.g). | citation |
sa-sama-csf:3.3.3.3.d |
The asset management process includes information asset classification, labeling and handling (3.3.3, control consideration 3.d). | citation |
sa-sama-csf:3.3.9.4.b |
The cryptographic security standard states the circumstances when the approved cryptographic solutions are applied, so that access to sensitive information is protected (3.3.9, objective and control consideration 4.b). | citation |
sa-sama-csf:3.3.14.4 |
Security loggings are adequately protected and analysed centrally and automatically, with events monitored according to the classification of the asset (3.3.14, control considerations 3.a, 4.h and 4.j). | citation |
Rules it adds
Section titled “Rules it adds”| Rule | Kind | Action | At | Controls |
|---|---|---|---|---|
sa-sama-csf-cloud-approved-by-sama |
access | deny |
llm | sa-sama-csf:3.4.3.4.a.2 |
sa-sama-csf-cloud-located-in-the-kingdom |
access | deny |
llm | sa-sama-csf:3.4.3.4.b.1 |
Controls no rule can enforce
Section titled “Controls no rule can enforce”A pointer and never an attestation: the mechanism that addresses the control, the evidence it leaves, and the page that describes it.
| Control | Addressed by | Evidence | See |
|---|---|---|---|
sa-sama-csf:3.4.3.4.g |
access rules evaluated on every request, reading the facts each provider declares in its metadata rather than a list of provider names, so the cloud computing policy’s conditions are held at the call; the two rules this pack adds are the approval and location conditions |
request.auth records naming the provider and the rule that decided; the providers: block of the deployment document, where the declarations live |
policy |
sa-sama-csf:3.3.3.3.d |
the key’s classification metadata, minted with the key and read by every rule as key.metadata.classification; it labels the level the caller handles, and the register of information assets stays with the Member Organization |
pistra query over the keys lists each key’s metadata; every request.auth record names the key |
mint-rotate-and-revoke-a-key |
sa-sama-csf:3.3.9.4.b |
TLS on every provider’s base_url, declared with the https scheme, and the fpe redaction operator, which replaces an identifier with a format-preserving ciphertext under a key the Member Organization holds before the request leaves. The gateway does not refuse a plain http address, so the scheme is a declaration. |
the providers: block of the deployment document; guardrail.decision records naming a redact rule whose operator is fpe |
guardrail-pipeline |
sa-sama-csf:3.3.14.4 |
the signed, hash-chained audit trail, which records every authentication, access decision and guardrail decision with the key, the provider and the controls named, and is exported to the Member Organization’s SIEM | request.auth and guardrail.decision records in the SIEM export; pistra audit verify over the export |
ship-the-audit-trail-to-your-siem |
Related: Control packs for what shipped and what a pack is not.