Compliance with Saudi NCA-ECC based on ISO/IEC 27001

被引:2
作者
Alsahafi, Tahani [1 ]
Halboob, Waleed [2 ]
Almuhtadi, Jalal [3 ,4 ]
机构
[1] Arab East Coll Grad Studies, Dept Adm & Educ, Riyadh 13544, Saudi Arabia
[2] King Saud Univ, Ctr Excellence Informat Assurance, POB 92144, Riyadh 11653, Saudi Arabia
[3] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh, Saudi Arabia
[4] King Saud Univ, Saudi Arabia &College Comp & Informat Sci, Riyadh 12372, Saudi Arabia
来源
TEHNICKI VJESNIK-TECHNICAL GAZETTE | 2022年 / 29卷 / 06期
关键词
compliance; digital forensics; essential cybersecurity controls (ECC); governance; incident response; information security management system (ISMS); ISO; IEC; 27001; risk management; SECURITY MANAGEMENT-SYSTEM;
D O I
10.17559/TV-20220307162849
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Organizations are required to implement an information security management system (ISMS) for making a central cybersecurity framework, reducing costs, treating risks, and so on. Several ISMS standards have been issued and implemented locally and internationally. In Saudi Arabia, the most widely implemented international ISMS is ISO/IEC 27001. Currently, the Saudi National Cybersecurity Authority (NCA) issued a local framework called Essential Cybersecurity Controls (NCA-ECC). Therefore, many ISO/IEC 27001 certified organizations in Saudi Arabia are trying to convert from ISO/IEC 27001 to NCA-ECC or comply with both frameworks. Nevertheless, cybersecurity experts need to know which cybersecurity controls are already implemented, based on the ISO/IEC 27001, and which are not. This paper first measures the extent to which certified ISO/IEC 27001 Saudi organizations comply with the NCA-ECC. Second, it presents a framework for complying with the required unimplemented or partially implemented NCA-ECC controls. The framework can also help organization to be in compliance with both frameworks, if required. Three ISO/IEC 27001-certified Saudi public universities are selected as samples. The data is collected by interviewing the cybersecurity officers in the selected universities. This research shows that certified ISO/IEC 27001 organizations are approximately 64% in compliance with the NCA-ECC. The presented framework can help any ISO/IEC 27001 certified Saudi organization convert from ISO/IEC 27001 to NCA-ECC in a quick and cost-effective manner by considering only NCA-ECC nonconformities.
引用
收藏
页码:2090 / 2097
页数:8
相关论文
共 22 条
  • [1] Al Sheikh A., 2017, Cyber security framework Saudi Arabian monetary authority
  • [2] Al-Badarneh YH, 2017, IEEE WCNC
  • [3] Al-Omeri M., 2017, 23 ANN C EXHIBITION, P33
  • [4] Al-Shetty E, 2014, EGYPT INFORM J, V13, P11
  • [5] Cybersecurity maturity assessment framework for higher education institutions in Saudi Arabia
    Almomani, Iman
    Ahmed, Mohanned
    Maglaras, Leandros
    [J]. PEERJ COMPUTER SCIENCE, 2021, 7
  • [6] [Anonymous], 2018, NCA ESS ASSESSMENT T
  • [7] [Anonymous], 2013, 270012013 ISOIEC
  • [8] Bamfleh F, 2002, FUTURE DIRECTIONS LI, V9, P1
  • [9] Bourekkache S., 2019, Journal of Digital Information Management, V17, P133
  • [10] Dexter J., 2002, CYBER SECURITY MANAG