GCC
NCA CCC
NCA Cloud Cybersecurity Controls (CCC-1:2020)
CCC-1:2020
55 controls · 24 domains · 122 sub-controls
Mandatory for: Mandatory for cloud computing in KSA
About this framework
The Cloud Cybersecurity Controls extend Saudi Arabia's NCA framework to cloud computing. They set security requirements for both cloud providers and the organisations that use them, covering data residency, access, and shared responsibility.
Who needs this
For Saudi cloud providers and the regulated organisations that rely on cloud services.
Cross-framework coverage
Controls in NCA CCC also cover:
ISO 27001 17 shared
NCA ECC-2 17 shared
Qatar NIA 17 shared
UAE IA 17 shared
ADHICS 16 shared
See how NCA CCC connects to the rest → the Security Universe
Control domains
1-1 · Cybersecurity Roles and Responsibilities 2
1-1-P-1
In addition to the ECC control 1-4-1, the Authorizing Official shall also identify, document and approve:
In addition to the ECC control 1-4-1, the Authorizing Official shall also identify, document and approve:
1 sub-control
- 1-1-P-1-1 Cybersecurity roles and RACI assignment for all stakeholders of the cloud services including Authorizing Official’s roles and responsibilities. Cybersecurity roles and RACI assignment for all stakeholders of the cloud services including Authorizing Official’s roles and responsibilities.
1-1-T-1
In addition to the ECC control 1-4-1, the Authorizing Official shall also identify, docu ment and approve:
In addition to the ECC control 1-4-1, the Authorizing Official shall also identify, docu ment and approve:
1 sub-control
- 1-1-T-1-1 Cybersecurity roles and RACI assignment for all stakeholders of the cloud services including Authorizing Official’s roles and responsibilities. Cybersecurity roles and RACI assignment for all stakeholders of the cloud services including Authorizing Official’s roles and responsibilities.
1-2 · Cybersecurity Risk Management 2
1-2-P-1
Cybersecurity risk management methodology mentioned in the ECC Subdomain 1-5, shall also include for the CSP, as a minimum:
Cybersecurity risk management methodology mentioned in the ECC Subdomain 1-5, shall also include for the CSP, as a minimum:
3 sub-controls
- 1-2-P-1-1 Defining acceptable risk levels for the cloud services, and clarifying them to the CST if they are related to the CST. Defining acceptable risk levels for the cloud services, and clarifying them to the CST if they are related to the CST.
- 1-2-P-1-2 Considering data and information classification in cybersecurity risk management methodology. Considering data and information classification in cybersecurity risk management methodology.
- 1-2-P-1-3 Developing cybersecurity risk register for cloud services, and monitoring it periodically according to the risks Developing cybersecurity risk register for cloud services, and monitoring it periodically according to the risks. Cybersecurity Governance 1 17 Cloud Cybersecurity Controls
1-2-T-1
Cybersecurity risk management methodology mentioned in the ECC Subdomain 1-5 shall also include for the CST, as a minimum:
Cybersecurity risk management methodology mentioned in the ECC Subdomain 1-5 shall also include for the CST, as a minimum:
3 sub-controls
- 1-2-T-1-1 Defining acceptable risk levels for the cloud services. Defining acceptable risk levels for the cloud services.
- 1-2-T-1-2 Considering data and information classification accredited by CST in cybersecurity risk management methodology. Considering data and information classification accredited by CST in cybersecurity risk management methodology.
- 1-2-T-1-3 Developing cybersecurity risk register for cloud services, and monitoring it periodically according to the risks Developing cybersecurity risk register for cloud services, and monitoring it periodically according to the risks. 18 Cloud Cybersecurity Controls
1-3 · Compliance with Cybersecurity Standards, Laws and Regulations 2
1-3-P-1
In addition to the ECC control 1-7-1, the CSP legislative and regulatory compliance should include as a minimum with the following requirements:
In addition to the ECC control 1-7-1, the CSP legislative and regulatory compliance should include as a minimum with the following requirements:
1 sub-control
- 1-3-P-1-1 Continuous compliance with all laws, regulations, instructions, decisions, regulatory frameworks and controls, and mandates regarding cybersecurity in KSA. Continuous compliance with all laws, regulations, instructions, decisions, regulatory frameworks and controls, and mandates regarding cybersecurity in KSA.
1-3-T-1
In addition to the ECC control 1-7-1, the CST legislative and regulatory compliance should include as a minimum with the following requirements:
In addition to the ECC control 1-7-1, the CST legislative and regulatory compliance should include as a minimum with the following requirements:
1 sub-control
- 1-3-T-1-1 Continuous or real-time compliance monitoring of the CSP with relevant cybersecurity legislation and contract clauses. Continuous or real-time compliance monitoring of the CSP with relevant cybersecurity legislation and contract clauses.
1-4 · Cybersecurity in Human Resources 3
1-4-P-1
In addition to subcontrols in the ECC controls 1-9-3 and 1-9-4, the following requirements should be covered prior and during the professional relationship of personnel with the CSP as a minimum:
In addition to subcontrols in the ECC controls 1-9-3 and 1-9-4, the following requirements should be covered prior and during the professional relationship of personnel with the CSP as a minimum:
3 sub-controls
- 1-4-P-1-1 Positions of cybersecurity functions in CSP’s data centers within the KSA must be filled with qualified and suitable Saudi nationals. Positions of cybersecurity functions in CSP’s data centers within the KSA must be filled with qualified and suitable Saudi nationals.
- 1-4-P-1-2 Screening or vetting candidates of personnel working inside KSA who have access to Cloud Technology Stack, periodically. Screening or vetting candidates of personnel working inside KSA who have access to Cloud Technology Stack, periodically.
- 1-4-P-1-3 Cybersecurity policies as a prerequisite to access to Cloud Technology Stack, signed and appropriately approved. Cybersecurity policies as a prerequisite to access to Cloud Technology Stack, signed and appropriately approved.
1-4-P-2
In addition to subcontrols in the ECC control 1-9-5, the following requirements should be in place, as a minimum, for the termination/completion of a human resource’s professional
In addition to subcontrols in the ECC control 1-9-5, the following requirements should be in place, as a minimum, for the termination/completion of a human resource’s professional relationship with the CSP:
1 sub-control
- 1-4-P-2-1 Assurance that assets owned by the organization (especially those with security exposure) are accounted for and returned upon termination. Assurance that assets owned by the organization (especially those with security exposure) are accounted for and returned upon termination.
1-4-T-1
In addition to subcontrols in the ECC control 1-9-3, the following requirements should be covered prior the professional relationship of staff with the CST shall cover, at a minimum:
In addition to subcontrols in the ECC control 1-9-3, the following requirements should be covered prior the professional relationship of staff with the CST shall cover, at a minimum:
1 sub-control
- 1-4-T-1-1 Screening or vetting candidates of personnel with access to Cloud Service sensitive functions (Key Management, Service Administration, Access Control). Screening or vetting candidates of personnel with access to Cloud Service sensitive functions (Key Management, Service Administration, Access Control).
1-5 · Cybersecurity in Change Management 4
1-5-P-1
Cybersecurity requirements for change management within the CSP shall be identified, documented and approved.
Cybersecurity requirements for change management within the CSP shall be identified, documented and approved.
1-5-P-2
Cybersecurity requirements for change management within the CSP shall be applied.
Cybersecurity requirements for change management within the CSP shall be applied.
1-5-P-3
Cybersecurity for change management in the CSP shall cover, as a minimum:
Cybersecurity for change management in the CSP shall cover, as a minimum:
2 sub-controls
- 1-5-P-3-1 Processes and procedures to securely implement changes (planned works) in production systems, with priority given to cybersecurity observations. Processes and procedures to securely implement changes (planned works) in production systems, with priority given to cybersecurity observations.
- 1-5-P-3-2 Process for the implementation of cybersecurity exceptional changes (e.g.: changes during incident restoration). Process for the implementation of cybersecurity exceptional changes (e.g.: changes during incident restoration).
1-5-P-4
Cybersecurity requirements for change management within the CSP shall be applied and reviewed periodically
Cybersecurity requirements for change management within the CSP shall be applied and reviewed periodically. 19 Cloud Cybersecurity Controls
2-1 · Asset Management 2
2-1-P-1
In addition to controls in the ECC control 2-1, the CSP shall cover the following additional controls for cybersecurity requirements for cybersecurity event logs and monitoring man
In addition to controls in the ECC control 2-1, the CSP shall cover the following additional controls for cybersecurity requirements for cybersecurity event logs and monitoring man agement, as a minimum:
2 sub-controls
- 2-1-P-1-1 Inventory of all information and technology assets using suitable techniques such as Configuration Management Database (CMDB) or similar capability containing an inventory of all technical assets. Inventory of all information and technology assets using suitable techniques such as Configuration Management Database (CMDB) or similar capability containing an inventory of all technical assets.
- 2-1-P-1-2 Identifying assets owners and involving them in the asset management li fecycle. Identifying assets owners and involving them in the asset management li fecycle.
2-1-T-1
In addition to controls in the ECC control 2-1, the CST shall cover the following additional controls for cybersecurity requirements for cybersecurity event logs and monitoring man
In addition to controls in the ECC control 2-1, the CST shall cover the following additional controls for cybersecurity requirements for cybersecurity event logs and monitoring man agement, as a minimum:
1 sub-control
- 2-1-T-1-1 Inventory of all cloud services and information and technology assets relat ed to the cloud services. Inventory of all cloud services and information and technology assets relat ed to the cloud services.
2-10 · Penetration Testing 1
2-10-P-1
In addition to subcontrols in the ECC control 2-11-3, the CSP shall cover the following ad ditional subcontrols for cybersecurity requirements for penetration testing, as a minimum:
In addition to subcontrols in the ECC control 2-11-3, the CSP shall cover the following ad ditional subcontrols for cybersecurity requirements for penetration testing, as a minimum:
1 sub-control
- 2-10-P-1-1 Scope of penetration tests must cover Cloud Technology Stack and must be conducted at least once every six months. Scope of penetration tests must cover Cloud Technology Stack and must be conducted at least once every six months.
2-11 · Cybersecurity Event Logs and Monitoring Management 2
2-11-P-1
In addition to subcontrols in the ECC control 2-12-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for cybersecurity event logs and monit
In addition to subcontrols in the ECC control 2-12-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for cybersecurity event logs and monitoring management, as a minimum:
8 sub-controls
- 2-11-P-1-1 Activating and protecting event logs and audit trails of Cloud Technology Stack. Activating and protecting event logs and audit trails of Cloud Technology Stack.
- 2-11-P-1-2 Activating and collecting of login attempts history. Activating and collecting of login attempts history.
- 2-11-P-1-3 Activating and protecting all event logs of activities and operations per formed by the CSP at the tenant level in order to support forensic analysis. Activating and protecting all event logs of activities and operations per formed by the CSP at the tenant level in order to support forensic analysis.
- 2-11-P-1-4 Protecting cybersecurity event logs from alteration, disclosure, destruction and unauthorized access and unauthorized release, in accordance with reg ulatory, or law requirements. Protecting cybersecurity event logs from alteration, disclosure, destruction and unauthorized access and unauthorized release, in accordance with reg ulatory, or law requirements.
- 2-11-P-1-5 Continuous cybersecurity events monitoring using SIEM technique cover ing the full Cloud Technology Stack. Continuous cybersecurity events monitoring using SIEM technique cover ing the full Cloud Technology Stack.
- 2-11-P-1-6 Reviewing cybersecurity event logs and audit trails periodically, covering CSP events in the Cloud Technology Stack. Reviewing cybersecurity event logs and audit trails periodically, covering CSP events in the Cloud Technology Stack.
- 2-11-P-1-7 Automated monitoring and logging of remote access sessions event logs. Automated monitoring and logging of remote access sessions event logs.
- 2-11-P-1-8 Secure handling of user-related data found in the audit trails and the cyber security event logs. Secure handling of user-related data found in the audit trails and the cyber security event logs.
2-11-T-1
In addition to subcontrols in the ECC control 2-12-3, the CST shall cover the following ad ditional subcontrols for cybersecurity requirements for cybersecurity event logs and mon
In addition to subcontrols in the ECC control 2-12-3, the CST shall cover the following ad ditional subcontrols for cybersecurity requirements for cybersecurity event logs and moni toring management, as a minimum:
2 sub-controls
- 2-11-T-1-1 Activating and collecting of login event logs, and cybersecurity event logs on assets related to cloud services. Activating and collecting of login event logs, and cybersecurity event logs on assets related to cloud services.
- 2-11-T-1-2 Monitoring shall include all activated cybersecurity logs on the cloud ser vices of the CST. Monitoring shall include all activated cybersecurity logs on the cloud ser vices of the CST.
2-12 · Cybersecurity Incident and Threat Management 1
2-12-P-1
Cybersecurity Incident and Threat Management
CSP commitments for cybersecurity incident and threat management (see subcontrols).
8 sub-controls
- 2-12-P-1-1 Subscribing in authorized and specialized organizations and groups to stay up-to-date on cybersecurity threats, common practices and key know-how. Subscribing in authorized and specialized organizations and groups to stay up-to-date on cybersecurity threats, common practices and key know-how.
- 2-12-P-1-2 Training for employees and third-party personnel to respond to cybersecu rity incidents, in line with their roles and responsibilities. Training for employees and third-party personnel to respond to cybersecu rity incidents, in line with their roles and responsibilities.
- 2-12-P-1-3 Periodically testing the incident response capability. Periodically testing the incident response capability.
- 2-12-P-1-4 Root Cause Analysis of cybersecurity incidents and developing plans to address them. Root Cause Analysis of cybersecurity incidents and developing plans to address them.
- 2-12-P-1-5 Support the CST in cases legal proceedings and forensics, protecting the chain of custody that falls under the management and responsibility of the CSP, in accordance with the rela Support the CST in cases legal proceedings and forensics, protecting the chain of custody that falls under the management and responsibility of the CSP, in accordance with the related law and regulatory requirements.
- 2-12-P-1-6 Real-time reporting to the CST of incidents that may affect CST; if the in cident is discovered. Real-time reporting to the CST of incidents that may affect CST; if the in cident is discovered.
- 2-12-P-1-7 Support for CSTs to handle security incidents according to the agreement between the CSP and CST. Support for CSTs to handle security incidents according to the agreement between the CSP and CST.
- 2-12-P-1-8 Measuring and monitoring cybersecurity incident metrics and monitor compliance with contracts and legislative requirements Measuring and monitoring cybersecurity incident metrics and monitor compliance with contracts and legislative requirements
2-13 · Physical Security 1
2-13-P-1
In addition to subcontrols in the ECC control 2-14-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for physical security, as a minimum:
In addition to subcontrols in the ECC control 2-14-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for physical security, as a minimum:
3 sub-controls
- 2-13-P-1-1 Continual monitoring of access to CSP’s sites and buildings. Continual monitoring of access to CSP’s sites and buildings.
- 2-13-P-1-2 Preventing unauthorized access to devices in the Cloud Technology Stack. Preventing unauthorized access to devices in the Cloud Technology Stack.
- 2-13-P-1-3 Disposal of cloud infrastructure hardware, in particular, storage equipment (external or internal), by adopting relevant legislation and best practices. Disposal of cloud infrastructure hardware, in particular, storage equipment (external or internal), by adopting relevant legislation and best practices.
2-14 · Web Application Security 1
2-14-P-1
In addition to subcontrols in the ECC control 2-15-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for web application security, as a min
In addition to subcontrols in the ECC control 2-15-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for web application security, as a minimum: 28 Cloud Cybersecurity Controls
1 sub-control
- 2-14-P-1-1 Protecting information involved in application service transactions against possible risks (e.g.: incomplete transmission, mis-routing, unauthorized message alteration, unauthorized disclosure….). Protecting information involved in application service transactions against possible risks (e.g.: incomplete transmission, mis-routing, unauthorized message alteration, unauthorized disclosure….).
2-15 · Key Management 8
2-15-P-1
Cybersecurity requirements for key management process within the CSP shall be identified, documented and approved.
Cybersecurity requirements for key management process within the CSP shall be identified, documented and approved.
2-15-P-2
Cybersecurity requirements for key management process within the CSP shall be applied.
Cybersecurity requirements for key management process within the CSP shall be applied.
2-15-P-3
In addition to the ECC subcontrol 2-8-3-2, cybersecurity requirements for key manage ment within the CSP shall cover, at minimum, the following:
In addition to the ECC subcontrol 2-8-3-2, cybersecurity requirements for key manage ment within the CSP shall cover, at minimum, the following:
3 sub-controls
- 2-15-P-3-1 as it is considered as optional 8 With exception of subcontrol as it is considered as optional 8 With exception of subcontrol
- 2-15-P-3-2 A secure cryptographic key retrieval mechanism in case of cryptographic key lost (such as backup of keys and enforcement of trusted key storage, strictly external to cloud). A secure cryptographic key retrieval mechanism in case of cryptographic key lost (such as backup of keys and enforcement of trusted key storage, strictly external to cloud).
- 2-15-P-3-3 Activating and monitoring of all audit trails of keys. Activating and monitoring of all audit trails of keys.
2-15-P-4
Cybersecurity requirements for key management within the CSP shall be reviewed period ically.
Cybersecurity requirements for key management within the CSP shall be reviewed period ically.
2-15-T-1
Cybersecurity requirements for key management within the CST shall be identified, docu mented and approved.
Cybersecurity requirements for key management within the CST shall be identified, docu mented and approved.
2-15-T-2
Cybersecurity requirements for key management within the CST shall applied.
Cybersecurity requirements for key management within the CST shall applied.
2-15-T-3
In addition to the ECC subcontrol 2-8-3-2, cybersecurity requirements for key manage ment within the CST shall cover, at minimum, the following:
In addition to the ECC subcontrol 2-8-3-2, cybersecurity requirements for key manage ment within the CST shall cover, at minimum, the following:
2 sub-controls
- 2-15-T-3-1 Ensure well-defined ownership for cryptographic keys. Ensure well-defined ownership for cryptographic keys.
- 2-15-T-3-2 A secure data retrieval mechanism in case of cryptographic encryption key lost (such as backup of keys and enforcement of trusted key storage, strictly external to cloud). A secure data retrieval mechanism in case of cryptographic encryption key lost (such as backup of keys and enforcement of trusted key storage, strictly external to cloud).
2-15-T-4
Cybersecurity requirements for key management within the CST shall be applied and re viewed periodically.
Cybersecurity requirements for key management within the CST shall be applied and re viewed periodically.
2-16 · System Development Security 4
2-16-P-1
Cybersecurity requirements for system development within the CSP shall be identified, documented and approved.
Cybersecurity requirements for system development within the CSP shall be identified, documented and approved.
2-16-P-2
Cybersecurity requirements for system development within the CSP shall be applied.
Cybersecurity requirements for system development within the CSP shall be applied.
2-16-P-3
Cybersecurity requirements for system development within the CSP shall include as a min imum the following controls along the development lifecycle:
Cybersecurity requirements for system development within the CSP shall include as a min imum the following controls along the development lifecycle:
2 sub-controls
- 2-16-P-3-1 Considering cybersecurity requirements of the Cloud Technology Stack and relevant systems in the design and implementation of the cloud com puting services. Considering cybersecurity requirements of the Cloud Technology Stack and relevant systems in the design and implementation of the cloud com puting services.
- 2-16-P-3-2 Protecting system development environments, testing environments (in cluding data used in testing environment), and integration platforms. Protecting system development environments, testing environments (in cluding data used in testing environment), and integration platforms.
2-16-P-4
Cybersecurity requirements for system development within the CSP shall be applied and reviewed periodically.
Cybersecurity requirements for system development within the CSP shall be applied and reviewed periodically.
2-17 · Storage Media Security 4
2-17-P-1
Cybersecurity requirements for usage of information and data media within the CSP shall be identified, documented and approved.
Cybersecurity requirements for usage of information and data media within the CSP shall be identified, documented and approved.
2-17-P-2
Cybersecurity requirements for usage of information and data media within the CSP shall be applied.
Cybersecurity requirements for usage of information and data media within the CSP shall be applied.
2-17-P-3
Cybersecurity requirements for usage of information and data media within the CSP shall cover, at minimum, the following:
Cybersecurity requirements for usage of information and data media within the CSP shall cover, at minimum, the following:
6 sub-controls
- 2-17-P-3-1 Enforcement of sanitization of media, prior to disposal or reuse. Enforcement of sanitization of media, prior to disposal or reuse.
- 2-17-P-3-2 Using secure means when disposing of media. Using secure means when disposing of media.
- 2-17-P-3-3 Provision to maintain confidentiality and integrity of data on removable media. Provision to maintain confidentiality and integrity of data on removable media.
- 2-17-P-3-4 Human readable labelling of media, to explain its classification and the sen sitivity of the information it contains. Human readable labelling of media, to explain its classification and the sen sitivity of the information it contains.
- 2-17-P-3-5 Controlled and physically secure storage of removable media. Controlled and physically secure storage of removable media.
- 2-17-P-3-6 Restriction and control of usage of portable media inside the Cloud Tech nology Stack. Restriction and control of usage of portable media inside the Cloud Tech nology Stack.
2-17-P-4
Cybersecurity requirements for usage of information and data media within the CSP shall be applied and reviewed periodically
Cybersecurity requirements for usage of information and data media within the CSP shall be applied and reviewed periodically. 30 Cloud Cybersecurity Controls 3-1 Cybersecurity Resilience Aspects of Business Continuity Management (BCM) Objective To ensure the inclusion of the cybersecurity resiliency requirements within the CSPs’ and CSTs’ business continuity management and to remediate and minimize the impacts on systems, information processing facilities and critical e-services from disasters caused by cybersecurity incidents. Controls
2-2 · Identity and Access Management 2
2-2-P-1
In addition to subcontrols in the ECC control 2-2-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for identity and access management requ
In addition to subcontrols in the ECC control 2-2-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for identity and access management requirements, as a minimum:
12 sub-controls
- 2-2-P-1-1 Identity and access management of generic accounts credentials for ac countability cannot be assigned for a specific individual. Identity and access management of generic accounts credentials for ac countability cannot be assigned for a specific individual.
- 2-2-P-1-10 Capability to immediately interrupt a remote access session and prevent any future access for a user. Capability to immediately interrupt a remote access session and prevent any future access for a user.
- 2-2-P-1-11 Provision to CSTs of Multi-factor authentication services for privileged cloud users. Provision to CSTs of Multi-factor authentication services for privileged cloud users.
- 2-2-P-1-12 Assurance of restricted and controlled access to storage systems and means (such as Storage Area Network (SAN)). Assurance of restricted and controlled access to storage systems and means (such as Storage Area Network (SAN)).
- 2-2-P-1-2 Secure session management, including session authenticity, session lockout, and session timeout termination Secure session management, including session authenticity, session lockout, and session timeout termination. Cybersecurity Defense 2 20 Cloud Cybersecurity Controls
- 2-2-P-1-3 Multi-factor authentication for privileged users, and candidates of personnel with access to Cloud Technology Stack. Multi-factor authentication for privileged users, and candidates of personnel with access to Cloud Technology Stack.
- 2-2-P-1-4 Formal process to detect and prevent unauthorized access (e.g Formal process to detect and prevent unauthorized access (e.g. unsuccessful login attempt threshold).
- 2-2-P-1-5 Utilizing secure methods and algorithms for saving and processing pass words, such as: Secure Hashing functions. Utilizing secure methods and algorithms for saving and processing pass words, such as: Secure Hashing functions.
- 2-2-P-1-6 Secure management of third party personnel’s accounts. Secure management of third party personnel’s accounts.
- 2-2-P-1-7 Access control enforced to management systems, administrative consoles. Access control enforced to management systems, administrative consoles.
- 2-2-P-1-8 Masking of displayed authentication inputs, especially passwords, to pre vent shoulder surfing. Masking of displayed authentication inputs, especially passwords, to pre vent shoulder surfing.
- 2-2-P-1-9 Getting CST’s approval before accessing any CST-related asset by the CSP or CSP’s third parties. Getting CST’s approval before accessing any CST-related asset by the CSP or CSP’s third parties.
2-2-T-1
In addition to subcontrols in the ECC control 2-2-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for identity and access management requ
In addition to subcontrols in the ECC control 2-2-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for identity and access management requirements, as a minimum:
5 sub-controls
- 2-2-T-1-1 Identity and access management for all cloud credentials along their full lifecycle. Identity and access management for all cloud credentials along their full lifecycle.
- 2-2-T-1-2 Confidentiality of cloud user identification, cloud credential and cloud access rights information, including the requirement on users to keep them private (for employed, third par Confidentiality of cloud user identification, cloud credential and cloud access rights information, including the requirement on users to keep them private (for employed, third party and CST personnel).
- 2-2-T-1-3 Secure session management, including session authenticity, session lockout, and session timeout termination on the cloud. Secure session management, including session authenticity, session lockout, and session timeout termination on the cloud.
- 2-2-T-1-4 Multi-factor authentication for privileged cloud users. Multi-factor authentication for privileged cloud users.
- 2-2-T-1-5 Formal process to detect and prevent unauthorized access to cloud (such as a threshold of unsuccessful login attempts). 21 Cloud Cybersecurity Controls Formal process to detect and prevent unauthorized access to cloud (such as a threshold of unsuccessful login attempts). 21 Cloud Cybersecurity Controls
2-3 · Information System and Information Processing Facilities Protection 2
2-3-P-1
In addition to subcontrols in the ECC control 2-3-3, the CSP shall cover the following ad ditional subcontrols for cybersecurity requirements for information system and processing
In addition to subcontrols in the ECC control 2-3-3, the CSP shall cover the following ad ditional subcontrols for cybersecurity requirements for information system and processing facilities protection requirements, as a minimum:
12 sub-controls
- 2-3-P-1-1 Ensuring that all configurations are applied in accordance to CSP’s cyber security standards. Ensuring that all configurations are applied in accordance to CSP’s cyber security standards.
- 2-3-P-1-10 Provide cloud computing services from within the KSA, including systems used for storage, processing, and disaster recovery centers. Provide cloud computing services from within the KSA, including systems used for storage, processing, and disaster recovery centers.
- 2-3-P-1-11 Provide cloud computing services from within the KSA, including systems used for monitoring, and support. Provide cloud computing services from within the KSA, including systems used for monitoring, and support.
- 2-3-P-1-12 Modern technologies, such as Endpoint Detection and Response (EDR) technologies, to ensure that the information servers and devices of CSP’s information processing systems and devi Modern technologies, such as Endpoint Detection and Response (EDR) technologies, to ensure that the information servers and devices of CSP’s information processing systems and devices of are ready for rapid response to incidents. 22 Cloud Cybersecurity Controls
- 2-3-P-1-2 Assurance of separation and isolation of data, environments and information systems across CSTs, to prevent data commingling. Assurance of separation and isolation of data, environments and information systems across CSTs, to prevent data commingling.
- 2-3-P-1-3 Adopting of cybersecurity principles for technical system configurations adhering to the minimum functionality principle. Adopting of cybersecurity principles for technical system configurations adhering to the minimum functionality principle.
- 2-3-P-1-4 Ability of the Cloud Technology Stacks to securely handle input validation, exceptions and failure. Ability of the Cloud Technology Stacks to securely handle input validation, exceptions and failure.
- 2-3-P-1-5 Full isolation of security functions and applications from other functions and applications in the Cloud Technology Stack. Full isolation of security functions and applications from other functions and applications in the Cloud Technology Stack.
- 2-3-P-1-6 Notification to CSTs with cybersecurity requirements provided by the CSP that are useable by the CST. Notification to CSTs with cybersecurity requirements provided by the CSP that are useable by the CST.
- 2-3-P-1-7 Detection and prevention of unauthorized changes to softwares, and sys tems. Detection and prevention of unauthorized changes to softwares, and sys tems.
- 2-3-P-1-8 Complete isolation and protection of multiple guest environments. Complete isolation and protection of multiple guest environments.
- 2-3-P-1-9 The community cloud services provided to CSTs (government organiza tions and CNI organizations) shall be isolated from any other cloud com puting provided to organizations outside the scope of work. The community cloud services provided to CSTs (government organiza tions and CNI organizations) shall be isolated from any other cloud com puting provided to organizations outside the scope of work.
2-3-T-1
In addition to subcontrols in the ECC control 2-3-3, the CST shall cover the following ad ditional subcontrols for cybersecurity requirements for information system and processing
In addition to subcontrols in the ECC control 2-3-3, the CST shall cover the following ad ditional subcontrols for cybersecurity requirements for information system and processing facilities protection requirements, as a minimum:
1 sub-control
- 2-3-T-1-1 Verifying that the CSP isolates the community cloud services provided to CSTs (government organizations and CNI organizations) from any other cloud computing provided to organizati Verifying that the CSP isolates the community cloud services provided to CSTs (government organizations and CNI organizations) from any other cloud computing provided to organizations outside the scope of work.
2-4 · Networks Security Management 2
2-4-P-1
In addition to subcontrols in the ECC control 2-5-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for networks security management requir
In addition to subcontrols in the ECC control 2-5-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for networks security management requirements, as a minimum:
6 sub-controls
- 2-4-P-1-1 Monitoring of traffic across the external and internal networks to detect anomalies. Monitoring of traffic across the external and internal networks to detect anomalies.
- 2-4-P-1-2 Network isolation and protection of Cloud Technology Stack network from other internal and external networks. Network isolation and protection of Cloud Technology Stack network from other internal and external networks.
- 2-4-P-1-3 Protection from denial of service attacks (including Distributed Denial of Service (DDoS)). Protection from denial of service attacks (including Distributed Denial of Service (DDoS)).
- 2-4-P-1-4 Protection of data transmitted through the network; from and to the Cloud Technology Stack network using cryptography primitives; for management and administrative access. Protection of data transmitted through the network; from and to the Cloud Technology Stack network using cryptography primitives; for management and administrative access.
- 2-4-P-1-5 Access control between different network segments. Access control between different network segments.
- 2-4-P-1-6 Isolation between cloud service delivery network, cloud management net work and CSP enterprise network. Isolation between cloud service delivery network, cloud management net work and CSP enterprise network.
2-4-T-1
In addition to subcontrols in the ECC control 2-5-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for networks security management requir
In addition to subcontrols in the ECC control 2-5-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for networks security management requirements, as a minimum:
1 sub-control
- 2-4-T-1-1 Protecting the connection channel with CSP. Protecting the connection channel with CSP.
2-5 · Mobile Devices Security 2
2-5-P-1
In addition to subcontrols in the ECC control 2-6-3, the CSP shall cover the following addi tional subcontrols for cybersecurity requirements for mobile device security, as a minimum:
In addition to subcontrols in the ECC control 2-6-3, the CSP shall cover the following addi tional subcontrols for cybersecurity requirements for mobile device security, as a minimum:
4 sub-controls
- 2-5-P-1-1 Inventory of all end user and mobile devices. Inventory of all end user and mobile devices.
- 2-5-P-1-2 as it is considered as optional 5 With exception of subcontrol as it is considered as optional 5 With exception of subcontrol
- 2-5-P-1-3 Screen locking for end user devices. Screen locking for end user devices.
- 2-5-P-1-4 Data sanitation and secure disposal for end-user devices, especially for those with exposure to the Cloud Technology Stack. Data sanitation and secure disposal for end-user devices, especially for those with exposure to the Cloud Technology Stack.
2-5-T-1
In addition to subcontrols in the ECC control 2-6-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for mobile device security, as a min imum:
In addition to subcontrols in the ECC control 2-6-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for mobile device security, as a min imum:
1 sub-control
- 2-5-T-1-1 Data sanitation and secure disposal for end-user devices with access to the cloud services. Data sanitation and secure disposal for end-user devices with access to the cloud services.
2-6 · Data and Information Protection 2
2-6-P-1
In addition to subcontrols in the ECC control 2-7-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for data and information protection req
In addition to subcontrols in the ECC control 2-7-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for data and information protection requirements, as a minimum:
5 sub-controls
- 2-6-P-1-1 Prohibiting the use of Cloud Technology Stack’s data in any environment other than production environment, except after applying strict controls for protecting that data, such as: Prohibiting the use of Cloud Technology Stack’s data in any environment other than production environment, except after applying strict controls for protecting that data, such as: data masking or data scrambling techniques.
- 2-6-P-1-2 Provision to CSTs of securely data storage processes, procedures, and tech nologies to comply with related legal and regulatory requirements. Provision to CSTs of securely data storage processes, procedures, and tech nologies to comply with related legal and regulatory requirements.
- 2-6-P-1-3 Disposal of CST’s data should be performed in a secure manner on termi nation or expiry of the contract with the CSP. Disposal of CST’s data should be performed in a secure manner on termi nation or expiry of the contract with the CSP.
- 2-6-P-1-4 Commitment to maintain the confidentiality of the CST’s data and infor mation, according to related legal and regulatory requirements. Commitment to maintain the confidentiality of the CST’s data and infor mation, according to related legal and regulatory requirements.
- 2-6-P-1-5 Providing CSTs with secure means to export and transfer data and virtual infrastructure Providing CSTs with secure means to export and transfer data and virtual infrastructure
2-6-T-1
In addition to subcontrols in the ECC control 2-7-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for protecting CST’s data and infor ma
In addition to subcontrols in the ECC control 2-7-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for protecting CST’s data and infor mation in cloud computing , as a minimum: 24 Cloud Cybersecurity Controls
2 sub-controls
- 2-6-T-1-1 Exit Strategy to ensure means for secure disposal of data on termination or expiry of the contract with the CSP. Exit Strategy to ensure means for secure disposal of data on termination or expiry of the contract with the CSP.
- 2-6-T-1-2 Using secure means to export and transfer data and virtual infrastructure. Using secure means to export and transfer data and virtual infrastructure.
2-7 · Cryptography 2
2-7-P-1
In addition to subcontrols in the ECC control 2-8-3, the CSP shall cover the following ad ditional subcontrols for cryptography, as a minimum:
In addition to subcontrols in the ECC control 2-8-3, the CSP shall cover the following ad ditional subcontrols for cryptography, as a minimum:
2 sub-controls
- 2-7-P-1-1 Technical mechanisms and cryptographic primitives for strong encryption, in according to the advanced level in the National Cryptographic Standards (NCS-1:2020). Technical mechanisms and cryptographic primitives for strong encryption, in according to the advanced level in the National Cryptographic Standards (NCS-1:2020).
- 2-7-P-1-2 Certification authority and issuance capability in a secure manner, or usage of certificates from a trusted certification authority. Certification authority and issuance capability in a secure manner, or usage of certificates from a trusted certification authority.
2-7-T-1
In addition to subcontrols in the ECC control 2-8-3, the CST shall cover the following ad ditional subcontrols for cryptography, as a minimum:
In addition to subcontrols in the ECC control 2-8-3, the CST shall cover the following ad ditional subcontrols for cryptography, as a minimum:
2 sub-controls
- 2-7-T-1-1 as it is considered as optional Table 3. CST’s commitments to cybersecurity controls for cloud computing 35 Cloud Cybersecurity Controls Annex No as it is considered as optional Table 3. CST’s commitments to cybersecurity controls for cloud computing 35 Cloud Cybersecurity Controls Annex No. (B): Terminologies and Definitions Annex B below shows some of the terminologies contained herein, and the meanings ascribed thereto. Table 4. Terms and Definitions Terminology Definition Asset Anything tangible or intangible that has value to the CSPs and CSTs. There are many types of assets, and some of which include obvious things, such as: persons, machineries, utilities, patents, software and services. The term could also include less obvious things, such as: information and characteristics (for example, CSP’s and CST’s repu tation and public image, as well as skill and knowledge). Attack Any kind of malicious activity that attempts to achieve unauthorized access, collection, disabling, prevention, destroy or sabotage of the information system resources or the information itself. Audit Independent review and examination of records and activities in or der to assess the effectiveness of cybersecurity controls and to ensure adherence to policies, operational procedures, standards and relevant legislative and regulatory requirements. Authentication Ensure user's identity, process or device, which is often a prerequisite for allowing access to resources in the system. Authorization Identification and verification of the rights/licenses of the user to access and allow him/her to view the information and technical re sources of the CSPs and CSTs as defined in the rights/user licenses. Availability Ensure timely access to information, data, systems and applications. Backup Files, devices, data and procedures available for use in case of failure or loss, or in case of deletion or suspension of their original copies. Closed-Circuit Television (CCTV) CCTV, also known as video surveillance, uses video cameras to send a signal to a specific location on a limited set of screens. This term is often referred to as the surveillance technique in areas that may need to be monitored where physical security is an important requirement thereto. 36 Cloud Cybersecurity Controls Terminology Definition Change Management It is a service management system that ensures a systematic and pro active approach using effective standard methods and procedures (for example, change in infrastructure, networks, etc.). Change Manage ment helps all stakeholders, including individuals and teams alike, move from their current state to the next desired state, and also helps reduce the impact of relevant incidents on service. Classification Categorizing the data prepared, collected, processed, or exchanged by the organizations for the provision of services or conduct of busi nesses, including data received from or exchanged with persons out side organizations, and the data that is prepared for the interest of organizations or related to the sensitive infrastructure. Data related to organizations is classified, using a top down approach, level 1, level 2, level 3, or level 4. Classified Data Any data classified at any of the following levels: level 1, level 2, level 3, or level 4. Cloud Computing Is a model which enables convenient, on-demand network access to a shared pool of configurable computing resources (e.g. networks, servers, storage, applications and services) that can be rapidly provi sioned and released with minimal management effort or service pro vider interaction. Cloud models are composed of five Essential Char acteristics: On-demand self-service, Broad network access, Resource pooling, Rapid elasticity, and Measured service. There are three types of cloud computing services delivery models: • Cloud Software as a Service (SaaS). • Cloud Platform as a Service (PaaS). • Cloud Infrastructure as a Service (IaaS). There are four deployment models: Private Cloud, Community Cloud, Public Cloud, and Hybrid Cloud. 37 Cloud Cybersecurity Controls Terminology Definition Cloud Computing Compliance Control Catalogue (C5) C5 is developed by the German Federal Office for Information Secu rity (BSI) to set minimum requirements to secure cloud services in order to establish a framework of trust between cloud providers and their customers. Cloud Computing Services Is the delivery of various services via the Internet and can be acces sible through different platforms (desktops, laptops, smart phones.. etc.). These services include applications and infrastructures such as servers, databases and networking to support, among other things, communication, data analysis, processing, sharing and storage. Cloud Controls Matrix (CCM) CCM is developed by the Cloud Security Alliance (CSA) to provide fundamental security principles to help the CSTs assessing the security risks of cloud services provided by the CSP. Cloud Customer In this document referred to as “Cloud Service Tenant (CST)”, is any natural or legal person (such as companies) who subscribes to the cloud computing services provided by the service provider. Cloud Service Provider (CSP) Any natural or legal person (such as companies) who provides cloud computing services to the public, either directly or indirectly through data centers (both inside and outside KSA) and manages them in whole or in part. Configuration Management DataBase (CMDB) Configuration Management DataBase, concept defined originally by the ITIL operations standard and consisting in database used to store configuration records of systems throughout their Lifecycle. Cloud Technology Stack (CTS) Layered architecture of technologies that are essential to implement cloud computing services: (Data Center infrastructure, LAN, storage/ compute/ hyper convergence hardware, hypervisor, cloud manage ment platform, virtual appliances, OSs, application software, O&M platforms, cloud security technologies etc.…) 38 Cloud Cybersecurity Controls Terminology Definition Compromise Disclosure of or obtaining information by unauthorized persons, which are unauthorized to be leaked or obtained, or violation of the cybersecurity policy of the Organization through disclosure, change, sabotage or loss of anything, either intentionally or unintentionally. The expression “security violation” means disclosure of, obtaining, leaking, altering or use of sensitive data without authorization (in cluding cryptographic keys and other critical cybersecurity stand ards). Confidentiality Maintaining authorized restrictions on access to and disclosure of information, including means of protecting privacy/personal infor mation. Confidential Data/ Information The information (or data) that is highly sensitive and important, according to the classification of the CSPs and CSTs, intended for use by them. One of the methods that can be used to classify this type of information is to measure the extent of the damage when it is disclosed, accessed in an unauthorized manner, damaged or sabotaged, as this may result in material or moral damage to the CSPs and CSTs or its clients, affecting the lives of persons related to that information or affecting and damaging the security of the state or its national economy or national capabilities. Sensitive information includes all information whose disclosure in unauthorized manner, loss or sabotage results in accountability or statutory penalties. Critical National Infrastructure (CNI) These are the assets (i.e. facilities, systems, networks, processes, and key operators who operate and process them), whose loss or vulnerability to security breaches may result in: • Significant negative impact on the availability, integration or delivery of basic services, including services that could result in serious loss of property and/or lives and/or injuries, alongside observance of significant economic and/or social impacts. • Significant impact on national security and/or national defense and/or state economy or national capacities. 39 Cloud Cybersecurity Controls Terminology Definition Cryptography These are the rules that include the principles, methods and means of storing and transmitting data or information in a particular form in order to conceal its semantic content, prevent unauthorized use or prevent undetected modification so that only the persons concerned can read and process the same. Cyber-Attack Intentional exploitation of computer systems and networks, and those CSPs and CSTs whose work depends on digital ICT, in order to cause damage. Cyber Risks Risks that harm the CSPs’ and CSTs’ processes (including the CSPs’ and CSTs’ vision, mission, management, image or reputation), assets, individuals, other organizations or the State due to unauthorized ac cess, use, disclosure, disruption, modification or destruction of infor mation and/or information systems. Cybersecurity Resilience Overall ability of the CSPs and CSTs to withstand cyber incidents and the causes of damage, and recovery therefrom. Cybersecurity Pursuant to the provisions of NCA's Regulation issued by virtue of the Royal Decree No. (6801) of (11/02/1439), cybersecurity is protec tion of networks, IT systems, operational technologies systems and their components of hardware and software, their services and the data they contain, from any penetration, disruption, modification, ac cess, use or unauthorized exploitation. The concept of cybersecurity also includes information security, digital security, etc. Cyberspace The interconnected network of IT infrastructure, including the Internet, communications networks, computer systems and Internet- connected devices, as well as the associated hardware and control devices. The term can also refer to a virtual world or domain such as a simple concept. Data Any information, records, statistics or documents that are photocopied, recorded and stored electronically. Data and Information Classification Setting the sensitivity level of data and information that results in security controls for each level of classification. Data and information sensitivity levels are set according to predefined categories where data and information is created, modified, improved, stored or transmitted. The classification level is an indication of the value or importance of the data and information of the Organization. 40 Cloud Cybersecurity Controls Terminology Definition Defense-in-Depth This is a concept of information assurance where multiple levels of security controls are used (as a defense) within the IT/OT system. Disaster Recovery Programs and plans designed to restore the organization's critical business functions and services to an acceptable situation, following exposure to cyber-attacks or disruption of such services. Effectiveness Effectiveness refers to the degree to which a planned impact is achieved. Planned activities are considered effective if these activi ties are already implemented, and the planned results are considered effective if the results are already achieved. KPIs can be used to mea sure and evaluate the level of effectiveness. Event Something that happens in a specific place (such as network, systems, applications, etc.) at a specific time. FedRAMP US Government assessment and authorization process for U.S. federal agencies designed to ensure security is in place when accessing cloud computing products and services. FedRAMP certifies cloud service providers to handle data in one of three impact levels: • FedRAMP Low - loss of confidentiality, integrity, and availability would result in limited adverse effects on an agency’s operations, assets, or individuals. • FedRAMP Moderate - loss of confidentiality, integrity, and avail ability would result in serious adverse effects on an agency’s oper ations, assets, or individuals. • FedRAMP High - Law Enforcement and Emergency Services sys tems, Financial systems, Health systems, and any other system where loss of confidentiality, integrity, or availability could be ex pected to have a severe or catastrophic adverse effect on organiza tional operations, organizational assets, or individuals. Identification A means for identification of the identity of the user, process or de vice, which is usually a prerequisite for granting access to resources in the system. 41 Cloud Cybersecurity Controls Terminology Definition Incident A security breach through violation of cybersecurity policies, accept able use policies, practices or cybersecurity controls or requirements. Integrity Protection against unauthorized modification or destruction of in formation, including ensuring information non-repudiation and re liability. (Inter)National Requirements The international requirements are requirements developed by an in ternational organization or organization, which are highly-used in a statutory manner all over the world (such as: PCI, SWIFT, etc.). The national requirements are requirements developed by a regulato ry organization within the KSA for statutory use (such as: the «ECC – 1: 2018»). ISO/IEC 27000 This series developed by the International Organization for Standard ization (ISO) and the International Electrotechnical Commission (IEC) to provide best practice recommendations to establish, imple ment, maintain and continually improve information security man agement system (ISMS). Key Performance Indicator (KPI) A type of performance measurement tool that assesses the success of an activity or organization towards achievement of specific objectives. Labelling Display of information (by specific and standard naming and coding) that is placed on the CSP’s and CST’s assets (such as devices, applica tions, documents, etc.) to be used to refer to some information relat ed to the classification, ownership, type and other asset management information. Level 1 A classification level applies to data classified as a (top secret) based on what is issued by the competent organization. Level 2 A classification level applies to data classified as a (secret) based on what is issued by the competent organization. 42 Cloud Cybersecurity Controls Terminology Definition Level 3 A classification level applies to data classified as a (confidential) based on what is issued by the competent organization. Level 4 A classification level applies to data classified as a (public) based on what is issued by the competent organization. Multi-Factor Authentication (MFA) A security system that verifies user identity, which requires the use of several separate elements of identity verification mechanisms. Verification mechanisms include several elements: • Knowledge: (something ONLY the user knows «like password»); • Possession: (something ONLY used by the user «such as a program or device generating random numbers or SMSs for login records, which are called: One-Time-Password); and • Inherent Characteristics: (a characteristic of the user ONLY, such as fingerprint). Multi-Tier Cloud Security Standard for Singapore (MTCS SS) This standard aims to encourage the adoption of sound risk management and security practices for cloud computing. MTCS SS has three levels of security, Level 1 being the base and Level 3 being the most stringent: • Level 1 – Designed for non-business critical data and systems, with baseline security controls to address security risks and threats in potentially low impact information systems using cloud services. • Level 2 – Designed to address the need of most organizations running critical data and systems through a set of more stringent security controls. These address security risks and threats in potentially moderate impact information systems using cloud service. • Level 3 – Designed for regulated organizations with specific requirements, which supplement or address security risks and threats in high impact information systems using cloud services. 43 Cloud Cybersecurity Controls Terminology Definition Staff Persons working with CSPs or CSTs (including official and temporary staff and contractors). Outsourcing Obtaining (goods or services) by contracting with a supplier or ser vice provider. Penetration Testing Testing a computer system, network, website application or smart phone application to look for the vulnerabilities that the attacker can exploit. Physical Security Physical security describes security measures designed to prevent unauthorized access to the organization’s facilities, equipment and resources, and to protect individuals and property from damage or harm (such as espionage, theft or terrorist attacks). Physical security involves the use of multiple-tier of interconnected systems, including CCTV, security guards, security limits, locks, ac cess control systems and many other technologies. Policy A document whose clauses specify a general obligation, direction or intent as formally expressed by the Authorizing Official of the orga nization. Cybersecurity Policy is a document whose clauses reflect official com mitment of the Senior Management to implement and improve the cybersecurity program in the organization, which includes the objec tives of the CSPs and CSTs regarding the cybersecurity program, its controls and requirements, and the mechanism for improving and developing the same. Privileged Access Management The process of managing high-risk powers on organization's systems, which often require special treatment to minimize risks that may arise from misuse thereof. Procedure A document with a detailed description of the steps necessary to perform specific operations or activities in compliance with relevant standards and policies. Procedures are defined as part of operations. Process A set of interrelated or interactive activities that translated input into output. Such activities are influenced by the policies of the CSPs and CSTs. 44 Cloud Cybersecurity Controls Terminology Definition RACI Matrix Responsible, Accountable, Consulted, Informed Matrix. Matrix that maps each player in a process, capability or function with the degree of involvement and responsibility undertaken in the process. Recovery A procedure or process to restore or control something that is suspended, damaged, stolen or lost. Security Information and Event Management (SIEM) A system that manages and analyses security events logs in real time in order to provide monitoring of threats, analysis of the results of interrelated rules for event logs and reports on logs data, and incident response. System Development Security Any application, platform, middleware, operating system, hypervisor, network stack and any other software that is part of the Cloud Technology Stack. Third-Party Any organization acting as a party in a contractual relationship to provide goods or services (this includes suppliers and service providers). Threat Any circumstance or events likely to adversely affect the business of the CSPs and CSTs (including its mission, functions, credibility or reputation), assets or employees, through exploiting an information system through unauthorized access to, destruction, disclosure, al teration or denial of services, in addition to the ability of the threat source to succeed in exploiting one of the vulnerabilities of a particu lar information system, which includes cyber threats. Vulnerability Any kind of vulnerability in the computer system, its programs or applications, in a set of procedures or anything that makes cyberse curity vulnerable. 45 Cloud Cybersecurity Controls Annex No. (C): List of the Abbreviations Annex C below shows some of the abbreviations, and their meanings, used in the controls herein. Table 5. List of Abbreviations Abb. Full Version BCM Business Continuity Management CCC Cloud Cybersecurity Controls CCTV Closed-Circuit Television CMDB Configuration Management DataBase CNI Critical National Infrastructure CSP Cloud Service Provider CST Cloud Service Tenant CTS Cloud Technology Stack DDoS Distributed Denial of Service ECC Essential Cybersecurity Controls IaaS Infrastructure as a Service MFA Multi-Factor Authentication PaaS Platform as a Service SAN Storage Area Network SaaS Software as a Service SIEM Security Information and Event Management 46 Cloud Cybersecurity Controls 47 Cloud Cybersecurity Controls
- 2-7-T-1-2 Encryption of data and information transferred to or transferred out of the cloud according to the relevant law and regulatory requirements. Encryption of data and information transferred to or transferred out of the cloud according to the relevant law and regulatory requirements.
2-8 · Backup and Recovery Management 1
2-8-P-1
In addition to subcontrols in the ECC control 2-9-3, the CSP shall cover the following ad ditional subcontrols for cybersecurity requirements for backup and recovery management, as a minimum:
In addition to subcontrols in the ECC control 2-9-3, the CSP shall cover the following ad ditional subcontrols for cybersecurity requirements for backup and recovery management, as a minimum:
2 sub-controls
- 2-8-P-1-1 Securing access, storage and transfer of CST’s data backups and its medi ums, and protecting it against damage, amendment or unauthorized access. Securing access, storage and transfer of CST’s data backups and its medi ums, and protecting it against damage, amendment or unauthorized access.
- 2-8-P-1-2 Securing access, storage and transfer of Cloud Technology Stack backups and its mediums, and protecting it against damage, amendment or unau thorized access Securing access, storage and transfer of Cloud Technology Stack backups and its mediums, and protecting it against damage, amendment or unau thorized access. 25 Cloud Cybersecurity Controls
2-9 · Vulnerabilities Management 2
2-9-P-1
In addition to subcontrols in the ECC control 2-10-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for vulnerability management re quirements, as a minimum:
In addition to subcontrols in the ECC control 2-10-3, the CSP shall cover the following additional subcontrols for cybersecurity requirements for vulnerability management re quirements, as a minimum:
2 sub-controls
- 2-9-P-1-1 Assessing and remediating vulnerabilities on external components of Cloud Technology Stack at least once every month, and at least once every three months for internal components o Assessing and remediating vulnerabilities on external components of Cloud Technology Stack at least once every month, and at least once every three months for internal components of Cloud Technology Stack.
- 2-9-P-1-2 Notification to CSTs of identified vulnerabilities that may affecting them, and safeguards in place. Notification to CSTs of identified vulnerabilities that may affecting them, and safeguards in place.
2-9-T-1
In addition to subcontrols in the ECC control 2-10-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for vulnerability management re quirements, as a minimum:
In addition to subcontrols in the ECC control 2-10-3, the CST shall cover the following additional subcontrols for cybersecurity requirements for vulnerability management re quirements, as a minimum:
2 sub-controls
- 2-9-T-1-1 Assessing and remediating vulnerabilities cloud services and at least once every three months. Assessing and remediating vulnerabilities cloud services and at least once every three months.
- 2-9-T-1-2 Management of CSP-notified vulnerabilities safeguards in place. Management of CSP-notified vulnerabilities safeguards in place.
3-1 · 3-1 2
3-1-P-1
In addition to subcontrols in the ECC control 3-1-3, the CSP shall cover the following ad ditional subcontrols for cybersecurity requirements for cybersecurity resilience aspects
In addition to subcontrols in the ECC control 3-1-3, the CSP shall cover the following ad ditional subcontrols for cybersecurity requirements for cybersecurity resilience aspects of business continuity management, as a minimum:
2 sub-controls
- 3-1-P-1-1 Developing and implementing disaster recovery and business continuity procedures in a secure manner. Developing and implementing disaster recovery and business continuity procedures in a secure manner.
- 3-1-P-1-2 Developing and implementing procedures to ensure resilience and continuity of cybersecurity systems dedicated to the protection of Cloud Technology Stack. Developing and implementing procedures to ensure resilience and continuity of cybersecurity systems dedicated to the protection of Cloud Technology Stack.
3-1-T-1
In addition to subcontrols in the ECC control 3-1-3, the CST shall cover the following ad ditional subcontrols for cybersecurity requirements for cybersecurity resilience aspects
In addition to subcontrols in the ECC control 3-1-3, the CST shall cover the following ad ditional subcontrols for cybersecurity requirements for cybersecurity resilience aspects of business continuity management, as a minimum:
1 sub-control
- 3-1-T-1-1 Developing and implementing disaster recovery and business continuity procedures related to cloud computing, in a secure manner Developing and implementing disaster recovery and business continuity procedures related to cloud computing, in a secure manner. Cybersecurity Resilience 3 31 Cloud Cybersecurity Controls
4-1 · Supply Chain and Third-Party Cybersecurity 1
4-1-P-1
In addition to implementing the ECC controls 4-1-2 and 4-1-3, the CSP shall cover the fol lowing additional subcontrols for third-party cybersecurity requirements, as a minimum:
In addition to implementing the ECC controls 4-1-2 and 4-1-3, the CSP shall cover the fol lowing additional subcontrols for third-party cybersecurity requirements, as a minimum:
4 sub-controls
- 4-1-P-1-1 as it is considered as optional CST Controls: Table (3) below shows CST’s commitments to cloud cybersecurity controls (section no as it is considered as optional CST Controls: Table (3) below shows CST’s commitments to cloud cybersecurity controls (section no. 10 «Cloud Cybersecurity Controls») by levels. Optional (Recommended) Mandatory Subdomains and Controls Level 1 Level 2 Level 3 Level 4
- 4-1-P-1-2 Requirement to provide security documentation for any equipment or services from suppliers and third-party providers. Requirement to provide security documentation for any equipment or services from suppliers and third-party providers.
- 4-1-P-1-3 Third party providers compliant with law and regulatory requirements rel evant to their scope. Third party providers compliant with law and regulatory requirements rel evant to their scope.
- 4-1-P-1-4 Risk management and security governance on third-party providers as part of general cybersecurity risk management and governance Risk management and security governance on third-party providers as part of general cybersecurity risk management and governance. Third party Cybersecurity 4 32 Cloud Cybersecurity Controls 11. Annexes Annex No. (A): Cloud Cybersecurity Controls Levels Cybersecurity controls for cloud services are divided into four levels using a top down approach, level 1, level 2, level 3, and level 4: • Level 1: A classification level applies to data classified as a (top secret) based on what is issued by the competent authority. • Level 2: A classification level applies to data classified as a (secret) based on what is issued by the competent authority. • Level 3: A classification level applies to data classified as a (confidential) based on what is issued by the competent authority. • Level 4: classification level applies to data classified as a (public) based on what is issued by the competent authority. Please note that the highest level of classification should be adopted when the content of an integrated set of data includes different levels. 33 Cloud Cybersecurity Controls Subdomains and Controls Level 1 Level 2 Level 3 Level 4 ECC Controls
Ready to assess against NCA CCC?
Start free trial →