Financial regulators require the institutions they oversee to run cybersecurity to a defined standard, because a bank's cyber failure is not a private matter, it can shake confidence in the whole financial system. A regulatory cyber framework translates that public interest into specific, assessable obligations.
The framework of the Saudi central bank, SAMA, is a leading example in the region. It exists so that regulated financial institutions identify and address cyber risk in a common, comparable way, and it is built on recognized international standards while adding the supervisory expectation that maturity is measured and reported, not merely claimed.
This page describes how to operate to such a framework as a reusable model, organized around its four domains, and aligned to the publicly issued SAMA framework and the international standards it draws on, without reproducing their text.
تُلزِم الجهات المالية المنظِّمة المؤسسات التي تشرف عليها بتشغيل الأمن السيبراني وفق معيارٍ محدَّد، لأن فشل بنكٍ سيبرانيًا ليس شأنًا خاصًا، بل قد يزعزع الثقة في النظام المالي كله. وإطارٌ سيبراني تنظيمي يترجم تلك المصلحة العامة إلى التزاماتٍ محدَّدة قابلة للتقييم.
إطار البنك المركزي السعودي (SAMA) مثالٌ رائد في المنطقة. وُجِد ليُحدّد ويعالج المؤسسات المالية المنظَّمة الخطرَ السيبراني بطريقةٍ موحَّدة قابلة للمقارنة، وهو مبنيٌ على معايير دولية معترف بها مع إضافة التوقّع الرقابي بأن يُقاس النضج ويُبلَّغ عنه، لا أن يُدَّعى فحسب.
تصف هذه الصفحة كيفية التشغيل وفق مثل هذا الإطار كنموذجٍ قابل لإعادة الاستخدام، منظَّمًا حول محاوره الأربعة، ومتوائمًا مع إطار SAMA المنشور والمعايير الدولية التي يستند إليها، دون نسخ نصّها.
The framework organizes cybersecurity into four domains that together cover direction, decision, execution, and dependency. Splitting the work this way makes coverage easy to reason about and gaps easy to see.
The four domains are leadership and governance, risk management and compliance, operations and technology, and third-party considerations. Read together, they describe a complete program: leadership sets direction, risk and compliance decide and prove, operations and technology carry it out, and third-party management extends it to the parties the institution depends on.
| Domain | What it covers |
|---|---|
| Leadership & governance | Direction, structures, policy, and accountable ownership |
| Risk management & compliance | Identifying, treating, and evidencing cyber risk and obligations |
| Operations & technology | The controls and processes that protect systems day to day |
| Third-party considerations | Managing the cyber risk introduced by suppliers and partners |
The design mirrors the recognized governance-management split and the risk cycle used across international standards, which is why an institution already aligned to ISO or NIST finds most of the work already done and mainly needs to map it to the regulator's structure and evidence expectations.
A subtle but important feature of a regulatory framework is that it is prescriptive where an international standard is permissive. ISO tells you to manage risk and lets you decide how, while a regulator often specifies the how, mandating particular controls, notification timelines, and maturity targets. This trades flexibility for comparability: the supervisor can hold every institution to the same measurable bar and compare them, which is the whole point of regulating a sector where one firm's failure can spread. Operating well under such a framework therefore means meeting specific requirements to the letter while still running the underlying risk management with genuine judgment, not just to the checklist.
ينظّم الإطار الأمن السيبراني في أربعة محاور تغطّي معًا التوجيه والقرار والتنفيذ والاعتماد. وتقسيم العمل هكذا يُسهّل التفكير في التغطية ورؤية الفجوات.
المحاور الأربعة هي القيادة والحوكمة، وإدارة المخاطر والامتثال، والعمليات والتقنية، واعتبارات الأطراف الثالثة. ومقروءةً معًا تصف برنامجًا كاملًا: القيادة تضع التوجيه، والمخاطر والامتثال يقرّران ويُثبتان، والعمليات والتقنية تُنفّذ، وإدارة الأطراف الثالثة تمدّه إلى الجهات التي تعتمد عليها المؤسسة.
| المحور | ما يغطّيه |
|---|---|
| القيادة والحوكمة | التوجيه والهياكل والسياسة والملكية المساءَلة |
| إدارة المخاطر والامتثال | تحديد الخطر السيبراني والالتزامات ومعالجتها وإثباتها |
| العمليات والتقنية | الضوابط والعمليات التي تحمي الأنظمة يوميًا |
| اعتبارات الأطراف الثالثة | إدارة الخطر السيبراني الذي يُدخِله المورّدون والشركاء |
يعكس التصميم فصلَ الحوكمة عن الإدارة المعترف به ودورةَ المخاطر المستخدَمة عبر المعايير الدولية، ولذا تجد مؤسسةٌ متوائمة أصلًا مع ISO أو NIST أغلب العمل منجَزًا وتحتاج أساسًا ربطه بهيكل الجهة المنظِّمة وتوقّعات الإثبات.
ومن سماته الدقيقة المهمّة أن الإطار التنظيمي آمرٌ حيث يكون المعيار الدولي مُبيحًا. فـ ISO يطلب إدارة الخطر ويترك لك كيف، بينما تحدّد الجهة المنظِّمة غالبًا الكيفية، فتفرض ضوابط بعينها وأزمنة إبلاغٍ وأهداف نضج. وهذا يقايض المرونة بالقابلية للمقارنة: فتستطيع الجهة المشرفة إلزام كل مؤسسة بالحدّ القابل للقياس نفسه ومقارنتها، وهو مقصد تنظيم قطاعٍ قد ينتشر فيه فشل شركةٍ واحدة. ولذا فالتشغيل الجيد تحت مثل هذا الإطار يعني الوفاء بمتطلباتٍ محدَّدة بحذافيرها مع إدارة المخاطر الكامنة بحكمٍ حقيقي، لا امتثالًا لقائمة الفحص فحسب.
The first domain makes cybersecurity a board-level responsibility, not a technical afterthought. In a regulated institution the expectation is explicit: senior leadership owns the cyber program and is answerable for it.
In practice this means a designated senior officer accountable for cybersecurity, a governance structure with a clear mandate, an endorsed cyber strategy and policy, and the resources to deliver them. The regulatory weight matters here, because it turns leadership involvement from good practice into a supervised obligation the institution must be able to demonstrate.
المحور الأول يجعل الأمن السيبراني مسؤوليةً على مستوى المجلس لا فكرةً تقنية لاحقة. وفي مؤسسةٍ منظَّمة يكون التوقّع صريحًا: القيادة العليا تملك البرنامج السيبراني وتُساءَل عنه.
عمليًا يعني هذا مسؤولًا تنفيذيًا مُعيَّنًا مساءَلًا عن الأمن السيبراني، وهيكل حوكمةٍ بولايةٍ واضحة، واستراتيجيةً وسياسةً سيبرانية معتمَدة، والموارد لتحقيقها. والثقل التنظيمي يهمّ هنا، لأنه يحوّل مشاركة القيادة من ممارسةٍ جيدة إلى التزامٍ مُشرَف عليه يجب أن تستطيع المؤسسة إثباته.
The second domain applies the standard risk cycle inside a compliance envelope. The institution must not only manage cyber risk well, it must prove to a supervisor that it does, which raises the bar on evidence and consistency.
This means a documented risk methodology, a maintained risk register, defined risk appetite, and treatment tracked to closure, all in a form a regulator can examine. Compliance adds the obligation to map controls to the framework's requirements and to demonstrate coverage, so the risk work and the regulatory reporting draw on the same underlying evidence rather than running as separate exercises.
The evidence bar is the practical difference from an unregulated program. It is not enough that a control works, the institution must be able to show, on demand and for a past date, that it was working then, which means logs, records, and sign-offs retained over time rather than reconstructed for an inspection. A useful discipline is to ask of every control, if the supervisor asked us to prove this was operating three months ago, could we, and to fix the answer before the question is ever asked. Building that evidence trail into daily operation is what separates a program that passes examinations calmly from one that lurches from one pre-audit crisis to the next.
المحور الثاني يطبّق دورة المخاطر المعيارية داخل غلافٍ امتثالي. فعلى المؤسسة ألّا تدير الخطر السيبراني جيدًا فحسب، بل أن تُثبت لجهةٍ مشرفة أنها تفعل، وهذا يرفع سقف الدليل والاتساق.
يعني هذا منهجية مخاطر موثَّقة، وسجل مخاطر مُصانًا، وشهية مخاطر محدَّدة، ومعالجةً تُتابَع للإغلاق، كلّها بصورةٍ تستطيع جهةٌ منظِّمة فحصها. والامتثال يضيف التزام ربط الضوابط بمتطلبات الإطار وإثبات التغطية، فيستمدّ عمل المخاطر والتقرير التنظيمي الدليل الأساسي نفسه بدل تشغيلهما كتمرينين منفصلين.
وسقف الدليل هو الفرق العملي عن برنامجٍ غير منظَّم. فلا يكفي أن يعمل الضابط، بل على المؤسسة أن تستطيع أن تُظهر، عند الطلب ولتاريخٍ ماضٍ، أنه كان يعمل حينها، وهذا يعني سجلات ومحاضر واعتماداتٍ محفوظة عبر الزمن لا مُعادة البناء لأجل تفتيش. وانضباطٌ مفيد أن تسأل عن كل ضابط: لو طلبت الجهة إثبات أنه كان يعمل قبل ثلاثة أشهر، أنقدر؟ وأن تُصلِح الجواب قبل أن يُطرَح السؤال أصلًا. وبناء ذلك الأثر في التشغيل اليومي هو ما يفصل برنامجًا يجتاز الفحوص بهدوء عن آخر يترنّح من أزمة ما قبل تدقيقٍ إلى التي تليها.
The third domain is where protection actually happens. It covers the operational controls that defend systems every day, from access and network security to monitoring, incident response, and resilience.
This domain is broad because it holds the working machinery of security. It expects the institution to run the practical controls covered elsewhere in this portfolio, security operations and incident management, identity and access, and secure configuration, and to keep them effective rather than merely present. A regulated institution also weighs resilience heavily, because a financial service that cannot recover quickly harms customers and confidence at once.
المحور الثالث حيث تقع الحماية فعلًا. يغطّي الضوابط التشغيلية التي تدافع عن الأنظمة كل يوم، من الوصول وأمن الشبكة إلى المراقبة والاستجابة للحوادث والمرونة.
هذا المحور واسع لأنه يحوي آلة الأمن العاملة. يتوقّع من المؤسسة تشغيل الضوابط العملية المغطّاة في مواضع أخرى من هذا البورتفوليو، عمليات الأمن والاستجابة للحوادث، والهوية والصلاحيات، والإعداد الآمن، وإبقاءها فعّالة لا موجودةً فحسب. والمؤسسة المنظَّمة تزن المرونة بثقلٍ أيضًا، لأن خدمةً مالية لا تتعافى سريعًا تؤذي العملاء والثقة معًا.
The fourth domain recognizes that a modern financial institution runs on outsourced services, and that a supplier's weakness can become the institution's incident. It extends the cyber obligations outward to the parties the institution depends on.
Practically, this means assessing a third party's security before relying on it, writing security requirements and audit rights into the contract, and maintaining assurance for as long as the dependency lasts. Where a service is outsourced, the regulator's expectation is that accountability is not: the institution remains answerable for risk it has handed to a supplier.
المحور الرابع يُقرّ بأن مؤسسةً مالية حديثة تعمل على خدماتٍ مُسنَدة للخارج، وأن ضعف مورّدٍ قد يصير حادثة المؤسسة. وهو يمدّ الالتزامات السيبرانية للخارج إلى الجهات التي تعتمد عليها المؤسسة.
عمليًا يعني هذا تقييم أمن الطرف الثالث قبل الاعتماد عليه، وكتابة متطلبات الأمن وحقوق التدقيق في العقد، وصون الضمان ما دام الاعتماد قائمًا. وحيث تُسنَد خدمةٌ للخارج، يكون توقّع الجهة المنظِّمة أن المساءلة لا تُسنَد: فتبقى المؤسسة مُساءَلة عن خطرٍ سلّمته لمورّد.
A defining feature of a regulatory framework is that compliance is measured on a maturity scale, not as a simple pass or fail. The institution assesses how well each control is embedded, and the regulator expects that assessment to be honest and improving.
A maturity scale describes control effectiveness in levels, from controls that exist only by individual effort, through defined and managed, to controls that are continuously improved. Placing each area on the scale turns compliance into a roadmap: the institution can see where it stands, agree a target, and plan the gap, and the supervisor can track progress over successive cycles.
The value is in honest placement and steady movement. A flattering self-assessment produces a plan that closes nothing, while an honest one, even where uncomfortable, gives leadership and the regulator a real picture and a credible path forward.
من سمات الإطار التنظيمي المميِّزة أن الامتثال يُقاس على مقياس نضجٍ لا كنجاحٍ أو رسوبٍ بسيط. فالمؤسسة تقيّم مدى ترسّخ كل ضابط، وتتوقّع الجهة المنظِّمة أن يكون ذلك التقييم صادقًا ومتحسّنًا.
مقياس النضج يصف فعالية الضابط بمستويات، من ضوابط توجد بجهدٍ فردي فقط، عبر المعرَّف والمُدار، إلى ضوابط تُحسَّن باستمرار. وتموضع كل مجالٍ على المقياس يحوّل الامتثال إلى خارطة طريق: ترى المؤسسة أين تقف، وتتّفق على هدف، وتخطّط الفجوة، وتتابع الجهة المشرفة التقدّم عبر دوراتٍ متتالية.
القيمة في التموضع الصادق والحركة الثابتة. فتقييمٌ ذاتي مُطرٍ يُنتج خطةً لا تُغلق شيئًا، وصادقٌ ولو كان مزعجًا يمنح القيادة والجهة المنظِّمة صورةً حقيقية ومسارًا موثوقًا للأمام.
A regulatory cyber framework turns cybersecurity into a supervised, evidenced obligation, organized here around four domains and a maturity scale.
إطارٌ سيبراني تنظيمي يحوّل الأمن السيبراني إلى التزامٍ مُشرَف عليه مُثبَت، منظَّمٍ هنا حول أربعة محاور ومقياس نضج.