Skip to content
Sentinel Unity
Financial sector

SAMA CSF: Cyber Security Framework

A financial-sector cyber framework with an unusually heavy third-party emphasis, which is why it pairs naturally with a platform where vendor risk and control assessment sit on the same record rather than in two systems.

Issued by the Saudi Central Bank for the institutions it supervises. Held as an example of a sector regulator: your own is added the same way.

  1. Threat

    Organised crime group

    • Sophistication: high
    • Intent: financial
    • Confidence: corroborated
    exploits
  2. Vulnerability

    Unpatched edge appliance

    • Severity: critical
    • Found by: external scan
    • SLA bucket: 7 days
    affects
  3. Exposure

    3 asset instances

    • Internet-facing
    • Confidentiality: high
    • Owner: Network Ops

Control effectiveness is scored separately for design, operation, and implementation, so a well-designed control that is not operating does not quietly reduce the score.

Five

Domains

0 to 5

Maturity scored

Linked

To the vendor register

Graded

Mapping to other standards

Structure

Five domains

The third-party domain is the one that most often forces a second tool. Here it reads the same vendor records as the rest of the programme.

Leadership & Governance

Board and executive accountability, defined security leadership, strategy, and reporting lines.

  • Accountability
  • Strategy
  • Committee reporting

Risk Management

Appetite, assessment, and treatment, with residual position recorded rather than implied.

  • Appetite and tolerance
  • Assessment
  • Treatment
  • Residual position

Operations & Technology

Identity, network, endpoint, logging, and monitoring practice.

  • Identity
  • Network
  • Endpoints
  • Logging

Third-Party Security

Tiering, due diligence before engagement, contractual security, and ongoing monitoring.

  • Tiering
  • Due diligence
  • Contract obligations
  • Re-assessment

Resilience

Incident response and recovery, tested rather than documented.

  • Incident response
  • Recovery
  • Crisis management

Platform mapping

Where the third-party domain lands

The vendor mechanics below are the product's own, used for any framework with a supplier chapter.

Tier factors and scoring bands

Vendors are tiered by scored factors against a profile, so placement is reproducible rather than a judgement call made twice.

Knockout rules

A disqualifying answer stops the engagement instead of being averaged into an acceptable overall score.

Fourth-party links

Record who your suppliers depend on, so concentration one level below your own contracts becomes visible.

Contract obligations

Audit rights, notification windows, and security commitments become tracked obligations with categories, statuses, and review decisions.

Due diligence with validity

Requests carry a document type and a validity status, so an expired certificate stops counting as evidence on its expiry date.

Review schedules

Re-assessment timing follows rules tied to tier, rather than a reminder in someone's calendar.

Maturity

How maturity is scored

Every control, including the third-party domain, is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.

Level 0

Not Performed

The practice does not happen. Recorded as an explicit level rather than a blank.

Level 1

Performed Informally

It happens, but it depends on individuals and is neither planned nor tracked.

Level 2

Planned & Tracked

Planned, resourced, and monitored, though practice still varies between teams.

Level 3

Well Defined

A defined standard process, applied consistently across the organisation.

Level 4

Quantitatively Controlled

Measured against targets, with deviation detected from the measurements themselves.

Level 5

Continuously Improving

Improvement is fed by the measurements, changing the process rather than the reporting.

Run a sector framework and its vendor chapter on one record

Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.

No commitment required. A typical demo runs 45 minutes.