Cyber Matterz
NCA ECC Compliance
The Essential Cyber Security Controls (ECC) were introduced by the National Cyber Security Authority (NCA) of Saudi Arabia in 2018. This framework was meticulously crafted following an in-depth analysis of various national and international Cyber Security Frameworks and Standards. The NCA ECC serves as a cornerstone in ensuring that organizations actively contribute to and uphold the Cyber Security initiative, safeguarding national interests, critical infrastructure, and government services. Its primary objective is to establish baseline Cyber Security requirements for information and technology assets across organizations in Saudi Arabia. Rooted in industry-leading practices, these controls aim to assist organizations in mitigating Cyber Security Risks effectively. NCA ECC consists of below domains:
1. 5 Cyber Security Main Domains.
2. 29 Cyber Security Sub-Domains.
3. 114 Cyber Security Controls.
These controls were formulated following a thorough examination of legal and regulatory requirements, global best practices in Cyber Security, analysis of incidents, and attacks on government establishments, considering perspectives from prominent business firms. In conjunction with the ECC Standard, the National Cyber Security Authority of Saudi Arabia introduced the Critical Systems Cyber Security Controls (CSCC) in 2019. The CSCC, mandated by the NCA, sets the minimum Cyber Security requirements for critical systems within national organizations.
Cyber Matterz ApproachTo NCA ECC Compliance
Initial study
Scope Definition
Gap Analysis
Awareness Training
Asset Classification
Risk Assessment
Risk Treatment
Documentation Support
Policy rollout support
Rollout User Training
Pre-Assessment
NCA ECC Compliance Audit
Continual support
Why
Cyber Matterz?
- Issuing audit certificates and reports for enhanced organizational market branding and acceptance.
- Providing a secure cloud-based portal with two-factor authentication for reporting and progress tracking.
- Operating as a vendor-neutral consultancy and advisory service company.
- Strictly adhering to a no outsourcing policy.
- Specializing in risk management, compliance solutions, and consultancy services.
- Focusing on areas such as cyber resilience, data protection, and cybersecurity solutions.
- Employing a pragmatic approach to ensure compliance.
- Backed by over a decade of industry experience and expertise.