Skip to content

SAMA Cyber Security Framework

The Saudi Central Bank’s Cyber Security Framework, version 1.0 of May 2017, binds every Member Organization SAMA regulates: banks, insurers, financing companies, credit bureaus and the financial market infrastructure. Its subdomain 3.4.3, Cloud Computing, says a hybrid or public cloud service is used only after SAMA’s approval, and in principle only one located in Saudi Arabia, with explicit approval from SAMA for one outside. A hosted model is a cloud service, so this pack puts those two facts on the provider and holds every request to them at the call. Four further control considerations a gateway can show are mapped to the mechanism and the evidence.

It is a starting point and certifies nothing. The framework is principle-based: a consideration a Member Organization cannot implement is met by a compensating control, a risk acceptance and a waiver from SAMA, as section 2.2 says.

The provider says what it is and where it is, in its metadata:

  • cloud: private marks an internal cloud, which subdomain 3.4.3 does not apply to. A model the Member Organization hosts itself is one.
  • residency: sa says the service is located in Saudi Arabia.
  • sama_approval: … records SAMA’s approval to use the service.
  • sama_approval_abroad: … records SAMA’s explicit approval to use a service located outside Saudi Arabia.
Rule Refuses Consideration
sa-sama-csf-cloud-approved-by-sama a hybrid or public cloud provider that declares no SAMA approval 3.4.3.4.a.2
sa-sama-csf-cloud-located-in-the-kingdom a provider not declared located in Saudi Arabia and without explicit approval for being outside 3.4.3.4.b.1

The gateway reads that each approval is declared, not what it says. Put the reference of SAMA’s letter in the value, so the audit record and the provider block agree on which approval a request went out under. A provider that declares no residency is outside Saudi Arabia, and one that declares neither a private cloud nor an approval is refused. That is the direction that makes adding a provider safe.

Four considerations no rule can enforce are mapped: the review, audit and monitoring rights over the provider, which the rules over provider metadata and the access records are; classification, labelling and handling of information assets, which the key’s classification metadata carries for the caller; the circumstances when approved cryptography applies, which the https scheme and the reversible fpe redaction operator are; and protected, centrally analysed security logs, which the signed audit trail shipped to the SIEM is. The mapping says where to look. Whether the consideration is met is yours to show.

A Member Organization also falls under the Personal Data Protection Law, and the PDPL pack is the one that replaces personal data before a request leaves. This pack does not depend on it, because subdomain 3.4.3 is about the provider and not the request, but a bank adds both. The classification vocabulary this pack’s mapping refers to is the NDMO pack’s, whose levels the national classification sets; SAMA’s framework names classification and leaves the scheme to the Member Organization.

  • The other 31 subdomains. Governance, risk, human resources, architecture, identity, change, payments, electronic banking, incidents, threats and vulnerabilities are the Member Organization’s programme. The pack takes the two considerations in 3.4.3 a gateway between the organization and the provider can hold, and maps four more.
  • Cardholder data. Section 1.4 says an organization that stores, processes or transmits cardholder data implements the PCI standard. A redaction of card numbers is the PDPL pack’s rule today; a PCI DSS pack would cite requirement 3 for it.
  • The approval itself. The gateway reads that a provider declares one, not whether it exists, is current or covers this service.
  • Data use limitations, segregation, continuity and exit in 3.4.3.4.c to 4.h. Those are contract terms, and the Member Organization’s due diligence.
  • Maturity levels. The framework’s maturity model rates the process around a control. A rule at the call is evidence for level 3 and above; the process is yours.
  • The text is version 1.0 of May 2017, which the SAMA Rulebook lists as in force under circular 381000091275. Section 1.8 says a new version retires the preceding one; check the Rulebook for the edition your organization is held to.
  • Adding this pack refuses every hybrid or public cloud provider without sama_approval, and every one abroad without sama_approval_abroad. Declare them, or cloud: private, on every provider first.
  • The control identifiers are the framework’s own numbering, subdomain then consideration. Each title is a paraphrase; check it against the text before a reviewer reads the audit trail through it.

Every identifier below is declared in pack.yaml and named by a rule, an attachment or a mapping. A rule that cites one carries it onto every audit record it decides.

Control What it requires Text
sa-sama-csf:3.4.3.4.a.2 The Member Organization obtains SAMA approval prior to using cloud services or signing the contract with the cloud provider (3.4.3, control consideration 4.a.2). citation
sa-sama-csf:3.4.3.4.b.1 In principle only cloud services located in Saudi Arabia are used; for cloud services outside Saudi Arabia the Member Organization obtains explicit approval from SAMA (3.4.3, control consideration 4.b.1). citation
sa-sama-csf:3.4.3.4.g The Member Organization has the right to review, audit and examine the cloud service provider, and monitors compliance with the cloud computing policy (3.4.3, control considerations 2 and 4.g). citation
sa-sama-csf:3.3.3.3.d The asset management process includes information asset classification, labeling and handling (3.3.3, control consideration 3.d). citation
sa-sama-csf:3.3.9.4.b The cryptographic security standard states the circumstances when the approved cryptographic solutions are applied, so that access to sensitive information is protected (3.3.9, objective and control consideration 4.b). citation
sa-sama-csf:3.3.14.4 Security loggings are adequately protected and analysed centrally and automatically, with events monitored according to the classification of the asset (3.3.14, control considerations 3.a, 4.h and 4.j). citation
Rule Kind Action At Controls
sa-sama-csf-cloud-approved-by-sama access deny llm sa-sama-csf:3.4.3.4.a.2
sa-sama-csf-cloud-located-in-the-kingdom access deny llm sa-sama-csf:3.4.3.4.b.1

A pointer and never an attestation: the mechanism that addresses the control, the evidence it leaves, and the page that describes it.

Control Addressed by Evidence See
sa-sama-csf:3.4.3.4.g access rules evaluated on every request, reading the facts each provider declares in its metadata rather than a list of provider names, so the cloud computing policy’s conditions are held at the call; the two rules this pack adds are the approval and location conditions request.auth records naming the provider and the rule that decided; the providers: block of the deployment document, where the declarations live policy
sa-sama-csf:3.3.3.3.d the key’s classification metadata, minted with the key and read by every rule as key.metadata.classification; it labels the level the caller handles, and the register of information assets stays with the Member Organization pistra query over the keys lists each key’s metadata; every request.auth record names the key mint-rotate-and-revoke-a-key
sa-sama-csf:3.3.9.4.b TLS on every provider’s base_url, declared with the https scheme, and the fpe redaction operator, which replaces an identifier with a format-preserving ciphertext under a key the Member Organization holds before the request leaves. The gateway does not refuse a plain http address, so the scheme is a declaration. the providers: block of the deployment document; guardrail.decision records naming a redact rule whose operator is fpe guardrail-pipeline
sa-sama-csf:3.3.14.4 the signed, hash-chained audit trail, which records every authentication, access decision and guardrail decision with the key, the provider and the controls named, and is exported to the Member Organization’s SIEM request.auth and guardrail.decision records in the SIEM export; pistra audit verify over the export ship-the-audit-trail-to-your-siem

Related: Control packs for what shipped and what a pack is not.