Saif Ali AlghamdiTransformation & Growth Advisor
تواصل
LibraryمكتبتيDigital & Technologyرقمي وتقنية
CYBERSECURITY · OPERATIONAL FRAMEWORKالأمن السيبراني · إطار تشغيلي

Regulatory Cybersecurity Framework (SAMA)الإطار السيبراني التنظيمي (SAMA)

SectionالقسمDigital & Technologyرقمي وتقنية
Reading timeزمن القراءة7 min٧ دقيقة
ByإعدادSaif Alghamdiسيف الغامدي
One

Overview

Field: Regulatory cybersecurity (financial sector)
Scope: Operating a cyber program to a financial regulator's framework
Owner role: Chief information security officer
Review cadence: Continuous, with maturity assessment on the regulator's cycle
By: Saif Alghamdi

Financial regulators require the institutions they oversee to run cybersecurity to a defined standard, because a bank's cyber failure is not a private matter, it can shake confidence in the whole financial system. A regulatory cyber framework translates that public interest into specific, assessable obligations.

The framework of the Saudi central bank, SAMA, is a leading example in the region. It exists so that regulated financial institutions identify and address cyber risk in a common, comparable way, and it is built on recognized international standards while adding the supervisory expectation that maturity is measured and reported, not merely claimed.

This page describes how to operate to such a framework as a reusable model, organized around its four domains, and aligned to the publicly issued SAMA framework and the international standards it draws on, without reproducing their text.

Note: A regulatory framework is a floor, not a ceiling. Meeting it is the minimum a supervised institution owes, and strong programs treat it as the baseline they build above.
الأول

نظرة عامة

المجال: الأمن السيبراني التنظيمي (القطاع المالي)
النطاق: تشغيل برنامج سيبراني وفق إطار جهةٍ مالية منظِّمة
دور المالك: رئيس أمن المعلومات
دورية المراجعة: مستمرة، مع تقييم نضجٍ على دورة الجهة المنظِّمة
إعداد: سيف الغامدي

تُلزِم الجهات المالية المنظِّمة المؤسسات التي تشرف عليها بتشغيل الأمن السيبراني وفق معيارٍ محدَّد، لأن فشل بنكٍ سيبرانيًا ليس شأنًا خاصًا، بل قد يزعزع الثقة في النظام المالي كله. وإطارٌ سيبراني تنظيمي يترجم تلك المصلحة العامة إلى التزاماتٍ محدَّدة قابلة للتقييم.

إطار البنك المركزي السعودي (SAMA) مثالٌ رائد في المنطقة. وُجِد ليُحدّد ويعالج المؤسسات المالية المنظَّمة الخطرَ السيبراني بطريقةٍ موحَّدة قابلة للمقارنة، وهو مبنيٌ على معايير دولية معترف بها مع إضافة التوقّع الرقابي بأن يُقاس النضج ويُبلَّغ عنه، لا أن يُدَّعى فحسب.

تصف هذه الصفحة كيفية التشغيل وفق مثل هذا الإطار كنموذجٍ قابل لإعادة الاستخدام، منظَّمًا حول محاوره الأربعة، ومتوائمًا مع إطار SAMA المنشور والمعايير الدولية التي يستند إليها، دون نسخ نصّها.

ملاحظة: الإطار التنظيمي أرضيةٌ لا سقف. فالوفاء به أدنى ما تدين به مؤسسةٌ مُشرَف عليها، والبرامج القوية تعامله كخطّ أساسٍ تبني فوقه.
Two

The Four Domains

The framework organizes cybersecurity into four domains that together cover direction, decision, execution, and dependency. Splitting the work this way makes coverage easy to reason about and gaps easy to see.

The four domains are leadership and governance, risk management and compliance, operations and technology, and third-party considerations. Read together, they describe a complete program: leadership sets direction, risk and compliance decide and prove, operations and technology carry it out, and third-party management extends it to the parties the institution depends on.

DomainWhat it covers
Leadership & governanceDirection, structures, policy, and accountable ownership
Risk management & complianceIdentifying, treating, and evidencing cyber risk and obligations
Operations & technologyThe controls and processes that protect systems day to day
Third-party considerationsManaging the cyber risk introduced by suppliers and partners

The design mirrors the recognized governance-management split and the risk cycle used across international standards, which is why an institution already aligned to ISO or NIST finds most of the work already done and mainly needs to map it to the regulator's structure and evidence expectations.

A subtle but important feature of a regulatory framework is that it is prescriptive where an international standard is permissive. ISO tells you to manage risk and lets you decide how, while a regulator often specifies the how, mandating particular controls, notification timelines, and maturity targets. This trades flexibility for comparability: the supervisor can hold every institution to the same measurable bar and compare them, which is the whole point of regulating a sector where one firm's failure can spread. Operating well under such a framework therefore means meeting specific requirements to the letter while still running the underlying risk management with genuine judgment, not just to the checklist.

Note: The domains are not silos. A single control, such as access management, produces evidence relevant to governance, risk, and operations at once.
الثاني

المحاور الأربعة

ينظّم الإطار الأمن السيبراني في أربعة محاور تغطّي معًا التوجيه والقرار والتنفيذ والاعتماد. وتقسيم العمل هكذا يُسهّل التفكير في التغطية ورؤية الفجوات.

المحاور الأربعة هي القيادة والحوكمة، وإدارة المخاطر والامتثال، والعمليات والتقنية، واعتبارات الأطراف الثالثة. ومقروءةً معًا تصف برنامجًا كاملًا: القيادة تضع التوجيه، والمخاطر والامتثال يقرّران ويُثبتان، والعمليات والتقنية تُنفّذ، وإدارة الأطراف الثالثة تمدّه إلى الجهات التي تعتمد عليها المؤسسة.

المحورما يغطّيه
القيادة والحوكمةالتوجيه والهياكل والسياسة والملكية المساءَلة
إدارة المخاطر والامتثالتحديد الخطر السيبراني والالتزامات ومعالجتها وإثباتها
العمليات والتقنيةالضوابط والعمليات التي تحمي الأنظمة يوميًا
اعتبارات الأطراف الثالثةإدارة الخطر السيبراني الذي يُدخِله المورّدون والشركاء

يعكس التصميم فصلَ الحوكمة عن الإدارة المعترف به ودورةَ المخاطر المستخدَمة عبر المعايير الدولية، ولذا تجد مؤسسةٌ متوائمة أصلًا مع ISO أو NIST أغلب العمل منجَزًا وتحتاج أساسًا ربطه بهيكل الجهة المنظِّمة وتوقّعات الإثبات.

ومن سماته الدقيقة المهمّة أن الإطار التنظيمي آمرٌ حيث يكون المعيار الدولي مُبيحًا. فـ ISO يطلب إدارة الخطر ويترك لك كيف، بينما تحدّد الجهة المنظِّمة غالبًا الكيفية، فتفرض ضوابط بعينها وأزمنة إبلاغٍ وأهداف نضج. وهذا يقايض المرونة بالقابلية للمقارنة: فتستطيع الجهة المشرفة إلزام كل مؤسسة بالحدّ القابل للقياس نفسه ومقارنتها، وهو مقصد تنظيم قطاعٍ قد ينتشر فيه فشل شركةٍ واحدة. ولذا فالتشغيل الجيد تحت مثل هذا الإطار يعني الوفاء بمتطلباتٍ محدَّدة بحذافيرها مع إدارة المخاطر الكامنة بحكمٍ حقيقي، لا امتثالًا لقائمة الفحص فحسب.

ملاحظة: المحاور ليست صوامع. فضابطٌ واحد، كإدارة الوصول، يُنتج دليلًا يخصّ الحوكمة والمخاطر والعمليات دفعةً واحدة.
Three

Leadership & Governance

The first domain makes cybersecurity a board-level responsibility, not a technical afterthought. In a regulated institution the expectation is explicit: senior leadership owns the cyber program and is answerable for it.

In practice this means a designated senior officer accountable for cybersecurity, a governance structure with a clear mandate, an endorsed cyber strategy and policy, and the resources to deliver them. The regulatory weight matters here, because it turns leadership involvement from good practice into a supervised obligation the institution must be able to demonstrate.

  • Accountable officer: a named senior owner of the cyber program.
  • Governance structure: a committee with mandate, decision rights, and cadence.
  • Strategy and policy: endorsed direction that the rest of the program implements.
  • Resourcing: the budget and people to meet the obligations, not just the intent.
Note: Under a regulator, leadership involvement must be evidenced. Minutes, endorsed policies, and decision records are the proof that governance is real rather than nominal.
الثالث

القيادة والحوكمة

المحور الأول يجعل الأمن السيبراني مسؤوليةً على مستوى المجلس لا فكرةً تقنية لاحقة. وفي مؤسسةٍ منظَّمة يكون التوقّع صريحًا: القيادة العليا تملك البرنامج السيبراني وتُساءَل عنه.

عمليًا يعني هذا مسؤولًا تنفيذيًا مُعيَّنًا مساءَلًا عن الأمن السيبراني، وهيكل حوكمةٍ بولايةٍ واضحة، واستراتيجيةً وسياسةً سيبرانية معتمَدة، والموارد لتحقيقها. والثقل التنظيمي يهمّ هنا، لأنه يحوّل مشاركة القيادة من ممارسةٍ جيدة إلى التزامٍ مُشرَف عليه يجب أن تستطيع المؤسسة إثباته.

  • المسؤول المساءَل: مالكٌ تنفيذي مُسمّى للبرنامج السيبراني.
  • هيكل الحوكمة: لجنة بولايةٍ وحقوق قرارٍ ودورية.
  • الاستراتيجية والسياسة: توجيهٌ معتمَد يُنفّذه بقية البرنامج.
  • الموارد: الميزانية والناس للوفاء بالالتزامات لا النيّة فقط.
ملاحظة: تحت جهةٍ منظِّمة، يجب إثبات مشاركة القيادة. فالمحاضر والسياسات المعتمَدة وسجلات القرار هي الدليل على أن الحوكمة حقيقية لا اسمية.
Four

Risk Management & Compliance

The second domain applies the standard risk cycle inside a compliance envelope. The institution must not only manage cyber risk well, it must prove to a supervisor that it does, which raises the bar on evidence and consistency.

This means a documented risk methodology, a maintained risk register, defined risk appetite, and treatment tracked to closure, all in a form a regulator can examine. Compliance adds the obligation to map controls to the framework's requirements and to demonstrate coverage, so the risk work and the regulatory reporting draw on the same underlying evidence rather than running as separate exercises.

The evidence bar is the practical difference from an unregulated program. It is not enough that a control works, the institution must be able to show, on demand and for a past date, that it was working then, which means logs, records, and sign-offs retained over time rather than reconstructed for an inspection. A useful discipline is to ask of every control, if the supervisor asked us to prove this was operating three months ago, could we, and to fix the answer before the question is ever asked. Building that evidence trail into daily operation is what separates a program that passes examinations calmly from one that lurches from one pre-audit crisis to the next.

  • Methodology: a documented, repeatable way of assessing cyber risk.
  • Register and appetite: a living record and a stated line for treatment.
  • Control mapping: each requirement linked to the control that meets it and its evidence.
  • Reporting: risk and compliance status presented to leadership and, as required, the regulator.
Note: Under supervision, the difference between doing and proving becomes central. Build evidence into the process so demonstration is a byproduct, not a scramble before an inspection.
الرابع

إدارة المخاطر والامتثال

المحور الثاني يطبّق دورة المخاطر المعيارية داخل غلافٍ امتثالي. فعلى المؤسسة ألّا تدير الخطر السيبراني جيدًا فحسب، بل أن تُثبت لجهةٍ مشرفة أنها تفعل، وهذا يرفع سقف الدليل والاتساق.

يعني هذا منهجية مخاطر موثَّقة، وسجل مخاطر مُصانًا، وشهية مخاطر محدَّدة، ومعالجةً تُتابَع للإغلاق، كلّها بصورةٍ تستطيع جهةٌ منظِّمة فحصها. والامتثال يضيف التزام ربط الضوابط بمتطلبات الإطار وإثبات التغطية، فيستمدّ عمل المخاطر والتقرير التنظيمي الدليل الأساسي نفسه بدل تشغيلهما كتمرينين منفصلين.

وسقف الدليل هو الفرق العملي عن برنامجٍ غير منظَّم. فلا يكفي أن يعمل الضابط، بل على المؤسسة أن تستطيع أن تُظهر، عند الطلب ولتاريخٍ ماضٍ، أنه كان يعمل حينها، وهذا يعني سجلات ومحاضر واعتماداتٍ محفوظة عبر الزمن لا مُعادة البناء لأجل تفتيش. وانضباطٌ مفيد أن تسأل عن كل ضابط: لو طلبت الجهة إثبات أنه كان يعمل قبل ثلاثة أشهر، أنقدر؟ وأن تُصلِح الجواب قبل أن يُطرَح السؤال أصلًا. وبناء ذلك الأثر في التشغيل اليومي هو ما يفصل برنامجًا يجتاز الفحوص بهدوء عن آخر يترنّح من أزمة ما قبل تدقيقٍ إلى التي تليها.

  • المنهجية: طريقةٌ موثَّقة قابلة للتكرار لتقييم الخطر السيبراني.
  • السجل والشهية: سجلٌ حيّ وخطٌ مُعلَن للمعالجة.
  • ربط الضوابط: كل متطلبٍ مرتبط بالضابط الذي يُلبّيه ودليله.
  • التقارير: وضع المخاطر والامتثال معروضًا للقيادة، وللجهة المنظِّمة عند الطلب.
ملاحظة: تحت الإشراف يصير الفرق بين الفعل والإثبات محوريًا. ادمج الدليل في العملية ليكون الإثبات ناتجًا ثانويًا لا تدافعًا قبل التفتيش.
Five

Operations & Technology

The third domain is where protection actually happens. It covers the operational controls that defend systems every day, from access and network security to monitoring, incident response, and resilience.

This domain is broad because it holds the working machinery of security. It expects the institution to run the practical controls covered elsewhere in this portfolio, security operations and incident management, identity and access, and secure configuration, and to keep them effective rather than merely present. A regulated institution also weighs resilience heavily, because a financial service that cannot recover quickly harms customers and confidence at once.

  • Protective controls: access, network, endpoint, and cryptographic safeguards.
  • Detection and response: monitoring and incident management that limit harm quickly.
  • Resilience: the ability to keep critical services running and recover them fast.
  • Secure operations: patching, configuration, and change control done consistently.
Note: Operations is judged on effectiveness, not existence. A control that is documented but not operating reliably is a finding waiting to be written.
الخامس

العمليات والتقنية

المحور الثالث حيث تقع الحماية فعلًا. يغطّي الضوابط التشغيلية التي تدافع عن الأنظمة كل يوم، من الوصول وأمن الشبكة إلى المراقبة والاستجابة للحوادث والمرونة.

هذا المحور واسع لأنه يحوي آلة الأمن العاملة. يتوقّع من المؤسسة تشغيل الضوابط العملية المغطّاة في مواضع أخرى من هذا البورتفوليو، عمليات الأمن والاستجابة للحوادث، والهوية والصلاحيات، والإعداد الآمن، وإبقاءها فعّالة لا موجودةً فحسب. والمؤسسة المنظَّمة تزن المرونة بثقلٍ أيضًا، لأن خدمةً مالية لا تتعافى سريعًا تؤذي العملاء والثقة معًا.

  • ضوابط وقائية: وقايات الوصول والشبكة والأجهزة الطرفية والتعمية.
  • الكشف والاستجابة: مراقبةٌ وإدارة حوادث تحدّان الضرر سريعًا.
  • المرونة: القدرة على إبقاء الخدمات الحرجة عاملةً وتعافيها سريعًا.
  • التشغيل الآمن: ترقيعٌ وإعدادٌ وضبط تغييرٍ يُؤدّى باتساق.
ملاحظة: تُقيَّم العمليات على الفعالية لا الوجود. فضابطٌ موثَّق لا يعمل بموثوقية ملاحظةٌ تنتظر أن تُكتَب.
Six

Third-Party Considerations

The fourth domain recognizes that a modern financial institution runs on outsourced services, and that a supplier's weakness can become the institution's incident. It extends the cyber obligations outward to the parties the institution depends on.

Practically, this means assessing a third party's security before relying on it, writing security requirements and audit rights into the contract, and maintaining assurance for as long as the dependency lasts. Where a service is outsourced, the regulator's expectation is that accountability is not: the institution remains answerable for risk it has handed to a supplier.

  • Due diligence: assess a provider's security before onboarding, sized to the risk.
  • Contractual controls: security terms, breach notification, and the right to audit.
  • Ongoing assurance: periodic evidence the provider still meets the bar.
  • Retained accountability: outsourcing the service does not outsource the responsibility.
Note: Concentration risk is a supervisory concern. When many institutions depend on the same critical provider, that provider becomes systemically important, and its assurance deserves proportionate attention.
السادس

اعتبارات الأطراف الثالثة

المحور الرابع يُقرّ بأن مؤسسةً مالية حديثة تعمل على خدماتٍ مُسنَدة للخارج، وأن ضعف مورّدٍ قد يصير حادثة المؤسسة. وهو يمدّ الالتزامات السيبرانية للخارج إلى الجهات التي تعتمد عليها المؤسسة.

عمليًا يعني هذا تقييم أمن الطرف الثالث قبل الاعتماد عليه، وكتابة متطلبات الأمن وحقوق التدقيق في العقد، وصون الضمان ما دام الاعتماد قائمًا. وحيث تُسنَد خدمةٌ للخارج، يكون توقّع الجهة المنظِّمة أن المساءلة لا تُسنَد: فتبقى المؤسسة مُساءَلة عن خطرٍ سلّمته لمورّد.

  • العناية اللازمة: قيّم أمن المزوّد قبل التعاقد، بحجم الخطر.
  • ضوابط تعاقدية: شروط أمنٍ وإبلاغ اختراقٍ وحقّ تدقيق.
  • الضمان المستمر: دليلٌ دوري بأن المزوّد ما زال يفي بالحدّ.
  • مساءلةٌ محفوظة: إسناد الخدمة للخارج لا يُسنِد المسؤولية.
ملاحظة: خطر التركّز شأنٌ رقابي. فحين تعتمد مؤسساتٌ كثيرة على المزوّد الحرج نفسه، يصير ذا أهميةٍ نظامية، ويستحق ضمانه اهتمامًا متناسبًا.
Seven

Maturity Assessment

A defining feature of a regulatory framework is that compliance is measured on a maturity scale, not as a simple pass or fail. The institution assesses how well each control is embedded, and the regulator expects that assessment to be honest and improving.

A maturity scale describes control effectiveness in levels, from controls that exist only by individual effort, through defined and managed, to controls that are continuously improved. Placing each area on the scale turns compliance into a roadmap: the institution can see where it stands, agree a target, and plan the gap, and the supervisor can track progress over successive cycles.

Target
Maturity level set per domain
Gap
Distance from current to target
Trend
Improvement across assessment cycles

The value is in honest placement and steady movement. A flattering self-assessment produces a plan that closes nothing, while an honest one, even where uncomfortable, gives leadership and the regulator a real picture and a credible path forward.

Bottom line: operating to a regulatory framework is running a full, evidenced cyber program whose maturity you can measure, defend, and steadily raise.
السابع

تقييم النضج

من سمات الإطار التنظيمي المميِّزة أن الامتثال يُقاس على مقياس نضجٍ لا كنجاحٍ أو رسوبٍ بسيط. فالمؤسسة تقيّم مدى ترسّخ كل ضابط، وتتوقّع الجهة المنظِّمة أن يكون ذلك التقييم صادقًا ومتحسّنًا.

مقياس النضج يصف فعالية الضابط بمستويات، من ضوابط توجد بجهدٍ فردي فقط، عبر المعرَّف والمُدار، إلى ضوابط تُحسَّن باستمرار. وتموضع كل مجالٍ على المقياس يحوّل الامتثال إلى خارطة طريق: ترى المؤسسة أين تقف، وتتّفق على هدف، وتخطّط الفجوة، وتتابع الجهة المشرفة التقدّم عبر دوراتٍ متتالية.

هدف
مستوى نضجٍ مُحدَّد لكل محور
فجوة
المسافة من الحالي إلى الهدف
اتجاه
التحسّن عبر دورات التقييم

القيمة في التموضع الصادق والحركة الثابتة. فتقييمٌ ذاتي مُطرٍ يُنتج خطةً لا تُغلق شيئًا، وصادقٌ ولو كان مزعجًا يمنح القيادة والجهة المنظِّمة صورةً حقيقية ومسارًا موثوقًا للأمام.

الخلاصة: التشغيل وفق إطارٍ تنظيمي هو إدارة برنامجٍ سيبراني كامل مُثبَت يمكنك قياس نضجه والدفاع عنه ورفعه باطّراد.
Eight

Key Takeaways & References

A regulatory cyber framework turns cybersecurity into a supervised, evidenced obligation, organized here around four domains and a maturity scale.

  • Treat the framework as a floor built on international standards, and build above it.
  • Make leadership accountable and evidence its involvement with records.
  • Run the risk cycle inside a compliance envelope, mapping controls to requirements.
  • Keep operational controls effective, and weigh resilience heavily.
  • Extend obligations to third parties, and measure maturity honestly each cycle.

References

الثامن

الخلاصات والمراجع

إطارٌ سيبراني تنظيمي يحوّل الأمن السيبراني إلى التزامٍ مُشرَف عليه مُثبَت، منظَّمٍ هنا حول أربعة محاور ومقياس نضج.

  • عامِل الإطار كأرضيةٍ مبنية على معايير دولية، وابنِ فوقه.
  • اجعل القيادة مساءَلة وأثبِت مشاركتها بالسجلات.
  • أدِر دورة المخاطر داخل غلافٍ امتثالي، بربط الضوابط بالمتطلبات.
  • أبقِ الضوابط التشغيلية فعّالة، وزِن المرونة بثقل.
  • مُدّ الالتزامات إلى الأطراف الثالثة، وقِس النضج بصدق كل دورة.

المراجع