Cybersecurity Governance
Leadership accountability, strategy, policy direction, and organisational risk management.
- Leadership role
- Strategy
- Policy direction
- Risk management
A national cybersecurity baseline, structured as domains and controls with an expectation of full coverage rather than selective adoption. Sentinel Unity holds it the same way it holds every other standard: as data, mapped to the controls you already test.
Issued by the National Cybersecurity Authority of Saudi Arabia. Held in the library as one framework among many, alongside whichever baseline applies to you.
Five
Domains
0 to 5
Maturity scored
Graded
Mapping to other standards
Versioned
Library releases
Structure
Each domain becomes part of the control tree, so an assessment can be scoped to one domain or run across all of them.
Leadership accountability, strategy, policy direction, and organisational risk management.
Identity, network, endpoint, and application protection across the estate.
Continuity of operations: incident response, disaster recovery, and restoration.
Assurance over suppliers and hosted environments, before engagement and through the contract.
Operational technology security, where availability usually outranks confidentiality.
Platform mapping
Nothing here is specific to this framework. Load a standard, map it, assess it, and the same mechanics apply.
Controls import from a header-based Excel file, so columns can arrive in any order and a revision is a re-import rather than a rebuild.
A library release stages a validated snapshot before it goes live, so content is reviewed before anyone assesses against it.
Each mapping to another standard carries a level, so partial coverage reads as partial rather than as done.
Controls carry People, Process, Technology, Data, and Facility tags, which is what lets a facilities question reach a facilities owner.
Evidence requirements are defined per control, and what gets uploaded passes a review step rather than being accepted on arrival.
A shortfall raises a finding with severity, an owner, and a remediation plan that can depend on other plans.
Maturity
Every control is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.
Level 0
Not Performed
The practice does not happen. Recorded as an explicit level rather than a blank.
Level 1
Performed Informally
It happens, but it depends on individuals and is neither planned nor tracked.
Level 2
Planned & Tracked
Planned, resourced, and monitored, though practice still varies between teams.
Level 3
Well Defined
A defined standard process, applied consistently across the organisation.
Level 4
Quantitatively Controlled
Measured against targets, with deviation detected from the measurements themselves.
Level 5
Continuously Improving
Improvement is fed by the measurements, changing the process rather than the reporting.
Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.
No commitment required. A typical demo runs 45 minutes.