Laws & RegulationsNCA CCC (Saudi Arabia)
In ForceGovernment entities, Critical national infrastructure, Cloud service providers
NCA Cloud Computing Cybersecurity Controls (CCC-1:2020)
Also known as: NCA CCC (Saudi Arabia)
Saudi National Cybersecurity Authority controls for cloud computing security. Mandatory for government entities and critical national infrastructure using cloud services. Establishes 4 domains of cloud security controls covering governance, compliance, data protection, and operational security.
Jurisdiction
Saudi Arabia
Regulator
—
Effective
1/1/2020
Sector
Government entities, Critical national infrastructure, Cloud service providers
Full Text / Summary
Saudi Arabia's National Cybersecurity Authority (NCA) Cloud Computing Cybersecurity Controls (CCC-1:2020) establish mandatory cybersecurity requirements for cloud service providers (CSPs) and cloud service consumers (CSCs) in Saudi Arabia. The Controls apply to all government entities and critical national infrastructure operators using cloud services, and to cloud service providers offering services in Saudi Arabia. CCC-1:2020 covers 10 domains: governance; compliance; asset management; identity and access management; physical security; operations security; communications security; incident management; business continuity; and supply chain. Cloud service providers must achieve NCA certification before providing services to government entities. The Controls require CSPs to store government data within Saudi Arabia unless explicitly approved for cross-border transfer. CSCs must conduct due diligence on CSPs, include security requirements in contracts, and maintain oversight of cloud security. The NCA also issues the Essential Cybersecurity Controls (ECC-1:2018) as the baseline cybersecurity framework for all government entities.