Saudi Central Bank (SAMA)
SAMA Cyber Security Framework
Cyber security controls and maturity expectations for SAMA-regulated financial institutions.
Who it applies to
Banks, insurers, financing companies and other entities supervised by the Saudi Central Bank, together with their material third parties.
What internal audit has to show
Internal audit is expected to give independent assurance over the control environment and the maturity self-assessment, with evidence that each domain has been tested rather than attested.
What Oversight does with SAMA CSF
- Maps the framework domains and sub-domains into your audit universe against the departments and systems that own them.
- Drafts engagement programs per domain with the test steps, sampling approach and the evidence each step needs.
- Requests the evidence from control owners, tracks it to receipt and records what was examined against each control.
- Drafts findings from tested gaps with the source document attached and carries the maturity rationale into the committee pack.
Typical engagements
- Annual cyber security maturity review
- Third-party cyber risk assurance
- Identity and access management review
- Security operations and incident response review
See a SAMA CSF engagement drafted from your scope
Bring the regulation and your org structure. The walkthrough builds the universe, drafts a program and traces a finding to its source on your documents.
Request a demo