The Saudi Arabian Monetary Authority's Cyber Security Framework is mandatory for every SAMA-regulated entity, with a minimum maturity level of 3 required across all five domains. This guide maps the framework's endpoint-relevant controls to specific Zecurit Endpoint Manager capabilities, so IT and compliance teams can turn SAMA's requirements into day-to-day operational practice.
The Saudi Arabian Monetary Authority, now operating as the Saudi Central Bank, issued its Cyber Security Framework in May 2017 under its mandate to enhance cybersecurity standards across Saudi Arabia's financial sector. The framework draws from internationally recognised standards including ISO/IEC 27001, NIST CSF, PCI-DSS, COBIT 5, and Basel III, adapting them specifically to the risk landscape of Saudi financial institutions operating within the Vision 2030 digital transformation context.
Unlike guidance frameworks that leave implementation to individual interpretation, SAMA's CSF is explicitly mandatory. Every SAMA-regulated entity must conduct an annual self-assessment against all five domains, submit results through SAMA's regulatory portal, and maintain evidence for independent validation during SAMA examinations. The minimum required maturity level is 3 (Defined) across every control, and SAMA conducts periodic inspection visits to verify the accuracy of self-assessments.
This guide maps the CSF's endpoint-relevant controls across all five domains to specific capabilities in Zecurit Endpoint Manager, helping IT and compliance teams build the evidence trail SAMA inspectors expect to see.
Several terms recur across SAMA's framework and its assessment process:
Any financial institution regulated and supervised by SAMA, including banks, insurance companies, finance companies, payment service providers, and credit bureaus.
A six-level scale (0 to 5) measuring how effectively each control is implemented. Level 3 (Defined) is the regulatory minimum. Levels 4 and 5 reflect best-practice maturity.
A specific, testable security measure within a sub-domain. The framework contains over 100 control considerations across its five domains, each assessed against the maturity scale.
Chief Information Security Officer: a mandatory appointment for most SAMA-regulated entities, with authority independent from IT operations and direct board reporting access.
The initial comparison of an organisation's current cybersecurity posture against all CSF requirements, used to identify weaknesses and develop the compliance roadmap.
The mandatory yearly evaluation of cybersecurity maturity across all five domains, submitted to SAMA's regulatory portal and formally approved by the board or equivalent governance body.
The framework applies to every entity regulated and supervised by SAMA, regardless of size. This includes:
Unlike many frameworks with three or four maturity tiers, SAMA's CSF uses a six-level model (0 to 5) derived from the Capability Maturity Model Integration (CMMI). Every control consideration is independently assessed against this scale. The regulatory minimum is Level 3 across all controls.
No process exists. Complete lack of any recognisable approach.
Processes exist but are informal, reactive, and undocumented.
Basic processes exist but are applied inconsistently without formal standards.
Standardised, documented, and approved. The regulatory minimum for all controls.
Required MinimumProcesses are measured and controlled with quantitative targets.
Continuous improvement through innovation and proactive adaptation.
The SAMA CSF organises all its control considerations across five core domains. All five domains are applicable to banks, while other financial institutions may have limited exclusions depending on their operational scope.
Board oversight, CISO appointment, cybersecurity strategy, risk appetite framework, policy framework, and alignment with business objectives. Requires board-level accountability for all cybersecurity decisions.
Cyber risk identification, assessment, treatment, and monitoring. Regulatory compliance tracking, third-party risk management, audit programme management, and information asset classification.
The most technically intensive domain: network security, endpoint protection, patch management, vulnerability management, access management, encryption, device control, and identity management. This is where most endpoint controls sit.
Vendor risk assessment, cloud computing security, outsourcing controls, SWIFT and payment system security, supply chain cybersecurity management, and contractual security obligations.
Business continuity planning, disaster recovery, cyber incident response, threat intelligence sharing, forensics capability, and lessons-learned programme to improve resilience after incidents.
The following sections translate the SAMA CSF's endpoint-relevant control considerations into the specific Zecurit Endpoint Manager capabilities that support Level 3 compliance and beyond.
SAMA requires organisations to maintain a comprehensive, up-to-date inventory of all information assets, with each asset assigned an owner and classified by sensitivity and criticality. This inventory must feed directly into the annual risk assessment and SAMA self-assessment process.
Hardware Inventory automatically collects CPU, RAM, storage, peripheral, and system specification data from every enrolled device. Software Inventory discovers and tracks every installed application with real-time version data, and Asset Discovery auto-onboards new devices the moment they connect to the network. Geo-location tracking maintains physical accountability for assets across branches and remote locations.
SAMA explicitly mandates a formal vulnerability management process covering regular vulnerability assessments, risk-based prioritisation of identified vulnerabilities, timely remediation, and re-testing to confirm resolution. Vulnerability scan results must feed into the risk register and SAMA self-assessment evidence.
Vulnerability Management continuously maps installed software across every managed endpoint against the current CVE database, giving security teams a real-time, severity-ranked view of the organisation's vulnerability exposure. CVSS-based prioritisation surfaces critical vulnerabilities first, directly supporting SAMA's requirement for risk-based remediation. Vulnerability data integrates with the patch deployment workflow, enabling closed-loop tracking from detection through remediation.
SAMA requires a documented patch management process with defined SLAs for different patch criticalities, covering operating systems, applications, and firmware. Patch compliance evidence must be maintained and available for SAMA inspection, with quarterly reporting to the IT risk committee as a minimum expectation.
Patch Management automates the full patch lifecycle from detection through deployment to compliance verification. Critical patches are ranked by CVSS score and active exploit intelligence, with automated deployment during configured maintenance windows eliminating the manual coordination that creates SLA breaches. Real-Time Patch Status Monitoring gives IT risk committees a live compliance view, and Patch Compliance Reports produce the dated, per-device evidence SAMA inspectors expect to see.
SAMA requires encryption of sensitive data at rest and in transit across all systems handling customer or financial data. Encryption coverage must be demonstrable, with encryption status verifiable for all assets in the information asset inventory.
BitLocker Management enforces drive encryption across every managed Windows endpoint from a central console, supporting TPM-only, TPM+PIN, and passphrase authentication modes. Recovery keys are backed up automatically, and BitLocker Compliance Reports identify any unprotected device across the fleet. This gives your CISO fleet-wide, examiner-ready evidence of encryption at rest, directly supporting SAMA's data protection control considerations.
SAMA mandates centralised identity and access management covering unique user identification, least-privilege access, privileged access management, separation of duties, regular access reviews, and comprehensive logging of all access events across critical systems.
Configuration Management's User and Group Management lets IT teams create, modify, and disable local user accounts remotely, enforce password policy, and audit all account changes from a central console. Remote Access sessions require explicit session confirmation from the end user and are governed by role-based access controls with full session logging. User Logon Reports record access patterns by account across the endpoint fleet, supporting regular access reviews and privileged access governance at SAMA's required maturity level.
SAMA requires endpoint security solutions on all devices, with controls to prevent unauthorised connection of removable storage, restrict data exfiltration channels, and ensure antivirus and antimalware protection is operational and continuously monitored. SAMA's inspectors test these controls device by device.
Security Alerts notify IT teams instantly when antivirus or antimalware protection is disabled on any endpoint. Device Control enforces allow, block, or trusted-only policies for removable storage, Bluetooth, wireless adapters, and Windows Portable Devices, with BadUSB keystroke injection prevention. Policies are enforced even when endpoints are offline, and every connection attempt and blocked event is logged with a timestamp and user account for SAMA evidence.
SAMA requires security hardening of all system components based on industry best practices, with deviations from hardening standards documented and approved. Configuration baselines must be enforced and monitored for drift, with any unauthorised configuration changes detected and remediated promptly.
Configuration Management lets IT teams define named profiles bundling firewall rules, Windows Update policy, security hardening settings, and user and group configurations, then deploy them consistently across device groups. Hardware and software change alerts detect the moment any endpoint deviates from its approved baseline, enabling rapid remediation and maintaining the documented, consistently applied configuration standard SAMA's Level 3 maturity requires.
SAMA requires real-time monitoring and logging of all security-relevant events across the organisation's technology environment, with alerts reviewed and acted upon in a timely manner. Logs must be retained, protected from tampering, and available for SAMA examination and forensic investigation.
The Monitoring and Alerts module provides real-time notifications across security, hardware, software, disk, licence, and certificate events. Security Alerts flag disabled antivirus, disabled firewall, and BitLocker protection turning off the moment they happen. Device Control logs and User Logon Reports give incident response teams the forensic detail needed to scope and investigate security events promptly, directly supporting SAMA's event management maturity requirements.
SAMA requires controls to prevent the installation and use of unauthorised software on organisation-owned devices, and to ensure software licence compliance. Unapproved or unlicensed software introduces security risk and creates regulatory exposure during SAMA examination.
Software Alerts notify IT teams instantly when prohibited or unauthorised software is installed on any managed endpoint. Software Licence Management monitors entitlements against actual installations to detect both over-installation and licence non-compliance. Software Deployment ensures approved applications are pushed through a controlled, auditable process, replacing ad-hoc installations that undermine software control posture.
SAMA requires member organisations to conduct an annual self-assessment across all five domains, submit results through the SAMA regulatory portal, and maintain evidence for independent validation during examinations. The gap between an examiner's request and producing that evidence is exactly where Level 3 maturity is most frequently undermined.
Compliance and Reporting provides 100+ built-in report templates including pre-mapped templates for ISO 27001, PCI-DSS, HIPAA, GDPR, CIS, and NIST. Security Reports surface BitLocker gaps, firewall status, and antivirus health across all endpoints, and Scheduled Report Delivery emails these reports to stakeholders automatically, building the continuous compliance record SAMA's annual self-assessment process depends on.
A consolidated reference mapping each SAMA CSF endpoint-relevant control to the relevant Zecurit features, useful for annual self-assessment preparation and SAMA examination evidence.
| SAMA CSF Control | Domain | Zecurit Endpoint Manager Capability |
|---|---|---|
| Information Asset Inventory | Domain 2 | Hardware InventorySoftware InventoryAsset Discovery |
| Vulnerability Management | Domain 3 | Vulnerability ManagementCVSS Prioritisation |
| Patch Management | Domain 3 | Patch ManagementPatch Status MonitoringPatch Compliance Reports |
| Data Protection and Encryption | Domain 3 | BitLocker ManagementTPM Policy ManagementBitLocker Compliance Reports |
| Identity and Access Management | Domain 3 | User and Group ManagementRole-Based AccessUser Logon Reports |
| Endpoint Protection and Device Control | Domain 3 | Security AlertsDevice ControlUSB/Removable Storage Policies |
| Secure Configuration and Hardening | Domain 3 | Configuration ManagementCentralised Profile ManagementChange Alerts |
| Security Event and Incident Management | Domain 3 | Real-Time Monitoring and AlertsSecurity AlertsAudit Device Logs |
| Software Control and Licence Management | Domain 3 | Software AlertsSoftware Licence ManagementSoftware Deployment |
| Audit-Ready Annual Self-Assessment | All Domains | 100+ Compliance ReportsSecurity ReportsScheduled Report Delivery |
The SAMA CSF's Level 3 maturity requirement means standardised, documented, and approved processes across all controls, not just a written policy sitting in a document management system. SAMA's examination visits verify that controls are actually operational, that logs exist and are reviewed, that patches are applied within defined SLAs, and that encryption coverage can be demonstrated device by device.
With Saudi Arabia's financial sector expanding rapidly through digital banking, fintech licensing, and Vision 2030 technology adoption, the attack surface is growing at the same pace as regulatory expectations. SAMA's inspections have become progressively more rigorous, and the enforcement actions following failed examinations are increasingly consequential.
Zecurit Endpoint Manager addresses the SAMA CSF's core endpoint-level control considerations from a single lightweight agent and unified console, giving bank and fintech IT teams the vulnerability management, patch management, encryption, device control, access governance, and compliance reporting that SAMA examiners expect to see, without assembling evidence from disconnected tools when an inspection arrives.
Zecurit develops cloud-based IT management solutions designed for modern IT teams. The Zecurit platform helps organisations manage endpoints, track assets, enforce security policies, and securely support distributed workforces through centralised, easy-to-use tools.
To learn more about Zecurit Endpoint Manager and how it supports your SAMA Cyber Security Framework compliance programme, start a free 14-day trial or contact the Zecurit team.
Contact Zecurit