Skip to main content

1.3 Scope

No: 381000091275 Date(g): 24/5/2017 | Date(h): 28/8/1438

Effective from May 24 2017 - May 23 2017
To view other versions open the versions tab on the right

The Framework defines principles and objectives for initiating, implementing, maintaining, monitoring and improving cyber security controls in Member Organizations. 
 
The Framework provides cyber security controls which are applicable to the information assets of the Member Organization, including: 
 
Electronic information.
 
Physical information (hardcopy).
 
Applications, software, electronic services and databases.
 
Computers and electronic machines (e.g., ATM).
 
Information storage devices (e.g., hard disk, USB stick).
 
Premises, equipment and communication networks (technical infrastructure).
 
The Framework provides direction for cyber security requirements for Member Organizations and its subsidiaries, staff, third parties and customers. 
 
For business continuity related requirements please refer to the SAMA Business Continuity Minimum Requirements. 
 
The Framework has an interrelationship with other corporate policies for related areas, such as physical security and fraud management. This framework does not address the non-cyber security requirements for those areas.