The baseline national cyber security controls for organisations operating in the Kingdom of Saudi Arabia.
Government entities and organisations designated as critical national infrastructure, together with their suppliers where the controls are applied contractually.
The essential controls are a baseline rather than a ceiling, and they are written to be assessable. Organisations already operating an ISO 27001 management system generally find substantial overlap, though the national obligations must still be addressed directly.
Assessed compliance against the national baseline, evidenced to the authority.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings exist between this framework and others in the library, so evidence gathered here may support work elsewhere. Mappings are published as draft, and a mapping shows a relationship rather than satisfied coverage. An auditor decides whether the evidence answers the requirement.