{"id":2650,"date":"2026-10-01T05:32:00","date_gmt":"2026-10-01T05:32:00","guid":{"rendered":"https:\/\/www.newevol.io\/resources\/?p=2650"},"modified":"2026-09-30T10:59:49","modified_gmt":"2026-09-30T10:59:49","slug":"sama-cybersecurity-framework-siem-saudi-banks","status":"publish","type":"post","link":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/","title":{"rendered":"SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks"},"content":{"rendered":"<p>The Saudi Central Bank (SAMA) Cyber Security Framework mostly reads as a governance document. It covers leadership, risk management, operations, and third-party security, and describes each area in terms of principles, objectives, and control considerations. A bank&#8217;s security team has to go one step further and ask what those controls mean day to day.<\/p>\n<p>Many of the controls describe work that has to happen continuously: monitoring, centralized logging, incident handling, collecting evidence, and reporting. A written policy cannot show that this work is happening. Operational systems can, and in most banks the <strong><a href=\"https:\/\/www.newevol.io\/platform\/newevol.php\">Security Information and Event Management (SIEM) platform<\/a><\/strong> is the main one.<\/p>\n<p>This article connects SAMA cybersecurity framework SIEM expectations to things a bank can buy, configure, test, and demonstrate.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_66_1 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title ez-toc-toggle\" style=\"cursor: pointer\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #0a0a0a;color:#0a0a0a\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #0a0a0a;color:#0a0a0a\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 eztoc-toggle-hide-by-default' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#What_the_SAMA_Cybersecurity_Framework_Means_for_SIEM\" title=\"What the SAMA Cybersecurity Framework Means for SIEM\">What the SAMA Cybersecurity Framework Means for SIEM<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#Translating_SAMA_Controls_into_Platform_Requirements\" title=\"Translating SAMA Controls into Platform Requirements\">Translating SAMA Controls into Platform Requirements<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#Continuous_Monitoring_Requirements\" title=\"Continuous Monitoring Requirements\">Continuous Monitoring Requirements<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#Log_Collection_and_Retention\" title=\"Log Collection and Retention\">Log Collection and Retention<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#Incident_Classification_and_Response\" title=\"Incident Classification and Response\">Incident Classification and Response<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#Regulatory_Reporting_and_Evidence\" title=\"Regulatory Reporting and Evidence\">Regulatory Reporting and Evidence<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#What_Auditors_and_Assessors_Need_to_See\" title=\"What Auditors and Assessors Need to See\">What Auditors and Assessors Need to See<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#SIEM_Procurement_Checklist_for_Saudi_Banks\" title=\"SIEM Procurement Checklist for Saudi Banks\">SIEM Procurement Checklist for Saudi Banks<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#Questions_to_Ask_Before_Selecting_a_SIEM\" title=\"Questions to Ask Before Selecting a SIEM\">Questions to Ask Before Selecting a SIEM<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#Conclusion\" title=\"Conclusion\">Conclusion<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#FAQs\" title=\"FAQs\">FAQs<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#1_What_SIEM_capabilities_do_Saudi_banks_need_for_SAMA_compliance\" title=\"1. What SIEM capabilities do Saudi banks need for SAMA compliance?\">1. What SIEM capabilities do Saudi banks need for SAMA compliance?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#2_Does_SAMA_require_banks_to_use_a_specific_SIEM_platform\" title=\"2. Does SAMA require banks to use a specific SIEM platform?\">2. Does SAMA require banks to use a specific SIEM platform?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#3_How_does_SIEM_support_SAMA_cybersecurity_controls\" title=\"3. How does SIEM support SAMA cybersecurity controls?\">3. How does SIEM support SAMA cybersecurity controls?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#4_What_logs_should_a_Saudi_bank_collect_for_security_monitoring\" title=\"4. What logs should a Saudi bank collect for security monitoring?\">4. What logs should a Saudi bank collect for security monitoring?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#5_How_can_SIEM_help_during_a_SAMA_cybersecurity_assessment\" title=\"5. How can SIEM help during a SAMA cybersecurity assessment?\">5. How can SIEM help during a SAMA cybersecurity assessment?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#6_Why_is_log_retention_important_for_SAMA_compliance\" title=\"6. Why is log retention important for SAMA compliance?\">6. Why is log retention important for SAMA compliance?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#7_What_evidence_should_a_bank_maintain_for_cybersecurity_monitoring\" title=\"7. What evidence should a bank maintain for cybersecurity monitoring?\">7. What evidence should a bank maintain for cybersecurity monitoring?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"What_the_SAMA_Cybersecurity_Framework_Means_for_SIEM\"><\/span>What the SAMA Cybersecurity Framework Means for SIEM<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The framework applies to SAMA member organizations, including banks. It is principle-based.&nbsp;It does not require any specific SIEM product or vendor<strong>.<\/strong>&nbsp;It sets out control expectations and a maturity model, and SAMA has stated that member organizations should reach at least maturity Level 3. At that level, controls must be defined, approved, and implemented, and their operation must be demonstrable.<\/p>\n<p>This matters for SIEM planning. Under the framework&#8217;s operations and technology domain, the most relevant subdomains are&nbsp;cyber security event management, <strong><a href=\"https:\/\/www.newevol.io\/solutions\/incident-investigation-response.php\">cyber security incident management<\/a><\/strong>, and&nbsp;threat management. They deal with monitoring, detection, and response, and a SIEM is usually the most practical way to put them into operation and show evidence that they work.<\/p>\n<p>Throughout this article, we separate two things:<\/p>\n<ul>\n<li><strong>Explicit requirements:<\/strong>&nbsp;what the SAMA framework or a related circular actually states.<\/li>\n<li><strong>Recommended capabilities:<\/strong>&nbsp;SIEM functions a bank will likely need to show that those requirements are met.<\/li>\n<\/ul>\n<p>Always check requirements against the framework version, circulars, and SAMA guidance that currently apply to your institution.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Translating_SAMA_Controls_into_Platform_Requirements\"><\/span>Translating SAMA Controls into Platform Requirements<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Compliance means showing that a control is working, not only that it is written down. A useful way to plan is to trace each control through four stages:<\/p>\n<p class=\"flow\">Control expectation &rarr; Operational requirement &rarr; SIEM capability &rarr; Assessment evidence<\/p>\n<div class=\"table-wrap\">\n<table class=\"table table-bordered\">\n<thead>\n<tr>\n<th>Control Expectation<\/th>\n<th>Operational Requirement<\/th>\n<th>SIEM Capability<\/th>\n<th>Evidence<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Security events are monitored<\/td>\n<td>Continuous collection and review of events<\/td>\n<td>Real-time ingestion, correlation, alerting<\/td>\n<td>Alert history, monitoring records<\/td>\n<\/tr>\n<tr>\n<td>Incidents are managed and classified<\/td>\n<td>Consistent triage and severity assignment<\/td>\n<td>Case management, classification workflows<\/td>\n<td>Incident tickets with timestamps<\/td>\n<\/tr>\n<tr>\n<td>Privileged access is controlled<\/td>\n<td>Oversight of administrator activity<\/td>\n<td>Privileged-user monitoring rules<\/td>\n<td>Privileged-access event reports<\/td>\n<\/tr>\n<tr>\n<td>Security records are protected<\/td>\n<td>Logs cannot be tampered with<\/td>\n<td>Integrity controls, role-based access<\/td>\n<td>Audit logs, configuration records<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>The last column in this table is what assessors test.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Continuous_Monitoring_Requirements\"><\/span>Continuous Monitoring Requirements<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Banking environments run all the time, and attackers do too. The framework&#8217;s event management expectations include establishing security event monitoring, typically through a <strong><a href=\"https:\/\/www.sattrix.com\/managed-services\/soc-as-a-service.php\">Security Operations Center (SOC)<\/a><\/strong>. For an operating bank, that usually means round-the-clock SOC monitoring, whether the SOC is run in-house or outsourced.<\/p>\n<p>When evaluating a SIEM for continuous security monitoring, look for:<\/p>\n<ul>\n<li><strong>24\/7 security event monitoring<\/strong>&nbsp;with dependable ingestion and health alerts when a data source stops sending logs<\/li>\n<li><strong>Centralized event collection<\/strong>&nbsp;across on-premises systems, cloud workloads, endpoints, core banking and payment applications, network devices, and security tools<\/li>\n<li><strong>Real-time alerting and correlation<\/strong>, so related events from different systems show up as one meaningful detection<\/li>\n<li><strong>Suspicious activity detection<\/strong>&nbsp;using rules, behavioral analytics, and threat intelligence<\/li>\n<li><strong>Authentication and access monitoring<\/strong>, such as failed logins, impossible travel, and unusual access times<\/li>\n<li><strong>Privileged-user monitoring<\/strong>&nbsp;of administrators, service accounts, and emergency access<\/li>\n<li><strong>Investigation tools<\/strong>&nbsp;that let analysts pivot across users, hosts, and IP addresses<\/li>\n<\/ul>\n<p><strong>Evidence an assessor may expect:<\/strong>&nbsp;monitoring dashboards, alert histories, analyst investigation records, incident tickets linked to alerts, and records showing how data-source outages were detected and fixed.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Log_Collection_and_Retention\"><\/span>Log Collection and Retention<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Log management underpins everything else. If logs are incomplete or unreliable, detection, investigation, and audit evidence all suffer.<\/p>\n<p>Key SIEM requirements include:<\/p>\n<ul>\n<li><strong>Centralized log collection<\/strong>&nbsp;from every system in scope<\/li>\n<li><strong>Log integrity<\/strong>, such as hashing, write-once storage, or equivalent protection against unauthorized changes<\/li>\n<li><strong>Consistent timestamps<\/strong>, with synchronized time sources so incident timelines can be trusted<\/li>\n<li><strong>Searchable history<\/strong>, so analysts and auditors can query older records quickly<\/li>\n<li><strong>Access controls on logs<\/strong>, with access restricted and every access recorded<\/li>\n<li><strong>Backup and recovery<\/strong>&nbsp;of security records<\/li>\n<li><strong>Audit trails<\/strong>&nbsp;of administrative actions inside the SIEM itself<\/li>\n<\/ul>\n<p><strong>Retention needs particular care.<\/strong>&nbsp;Do not assume one fixed retention period. What you must keep can depend on the SAMA framework and related circulars, other Saudi rules such as the National Cybersecurity Authority&#8217;s controls where they apply, legal and litigation-hold obligations, and your own internal policy. Some of these set specific minimums and others leave the period to the institution.<\/p>\n<p><strong>Define your retention requirements before you choose a SIEM.<\/strong>&nbsp;Retention affects storage architecture, licensing costs, search performance, and how data is split between hot and archive tiers. If you only discover after deployment that the platform cannot keep searchable data long enough, the fix is expensive.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Incident_Classification_and_Response\"><\/span>Incident Classification and Response<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The framework&#8217;s incident management expectations cover identifying incidents, classifying them, responding, and reviewing afterward. A SIEM should support the full incident lifecycle:<\/p>\n<ul>\n<li><strong>Incident identification<\/strong>, including promotion of alerts into incidents<\/li>\n<li><strong>Severity classification and categorization<\/strong>&nbsp;that match the bank&#8217;s approved classification scheme<\/li>\n<li><strong>Alert-to-incident workflows<\/strong>&nbsp;with clear ownership<\/li>\n<li><strong>Escalation paths<\/strong>&nbsp;based on severity and type<\/li>\n<li><strong>Case management<\/strong>&nbsp;that records investigation steps and timelines<\/li>\n<li><strong>Evidence preservation<\/strong>, so relevant logs and artifacts are kept with the case<\/li>\n<li><strong>Response tracking<\/strong>&nbsp;of containment, eradication, and recovery actions<\/li>\n<li><strong>Closure and post-incident review<\/strong>, including root cause and lessons learned<\/li>\n<\/ul>\n<p>The result should be an auditable record showing&nbsp;what happened, when it happened, who investigated, what actions were taken, and how the incident was resolved. That record needs to exist when an incident is reviewed, not be rebuilt from memory afterward.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Regulatory_Reporting_and_Evidence\"><\/span>Regulatory Reporting and Evidence<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The SAMA framework includes obligations to notify SAMA about security incidents. Its incident management section says SAMA should be informed immediately when an incident classified as medium or high has occurred and been identified, and that a formal incident report should follow once operations have resumed. SAMA may issue more specific timelines, templates, or channels through circulars. Confirm the reporting process that currently applies to you, and do not rely on general assumptions.<\/p>\n<p>A SIEM can support regulatory reporting and internal governance through:<\/p>\n<ul>\n<li>Incident reports and timelines produced from case records<\/li>\n<li>Management dashboards showing trends, open incidents, and SLA performance<\/li>\n<li>Compliance reports mapped to specific controls<\/li>\n<li>Summaries of security events for committees and the board<\/li>\n<li>Audit trails and evidence exports for regulators and auditors<\/li>\n<li>Reporting workflows with review and approval steps<\/li>\n<\/ul>\n<p>Avoid manual spreadsheets and screenshots&nbsp;as your main evidence. They are slow to produce, easy to get wrong, hard to verify, and often inconsistent between reporting periods. Evidence generated by the system, with timestamps and audit trails, is far easier to defend.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_Auditors_and_Assessors_Need_to_See\"><\/span>What Auditors and Assessors Need to See<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This is where many banks run into trouble. Compare two statements:<\/p>\n<blockquote>\n<p>&#8220;We have a policy for this control.&#8221;<\/p>\n<\/blockquote>\n<blockquote>\n<p>&#8220;Here is system-generated evidence showing that this control operated as required.&#8221;<\/p>\n<\/blockquote>\n<p>The first shows the control was designed. Only the second shows it is working. If a control exists in policy but cannot be shown through reliable operational records, you have an assessment gap, and this matters most at the maturity levels SAMA expects.<\/p>\n<p>Typical evidence includes:<\/p>\n<ul>\n<li>Log records and searchable log history<\/li>\n<li>Monitoring dashboards and alert history<\/li>\n<li>Incident tickets, investigation notes, and response records<\/li>\n<li>User activity logs and privileged-access events<\/li>\n<li>Configuration records and retention settings<\/li>\n<li>Escalation records and management notifications<\/li>\n<li><strong><a href=\"https:\/\/www.newevol.io\/solutions\/compliance-audit-readiness.php\">Compliance reports<\/a><\/strong> and audit trails of SIEM administration<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"SIEM_Procurement_Checklist_for_Saudi_Banks\"><\/span>SIEM Procurement Checklist for Saudi Banks<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<div class=\"table-wrap\">\n<table class=\"table table-bordered\">\n<thead>\n<tr>\n<th>Requirement<\/th>\n<th>What the Bank Should Look For<\/th>\n<th>Evidence<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Continuous monitoring<\/td>\n<td>Real-time event collection and alerting<\/td>\n<td>Monitoring records<\/td>\n<\/tr>\n<tr>\n<td>Centralized logging<\/td>\n<td>Logs from relevant security and IT systems<\/td>\n<td>Searchable log history<\/td>\n<\/tr>\n<tr>\n<td>Log retention<\/td>\n<td>Configurable retention aligned with applicable requirements<\/td>\n<td>Retention configuration<\/td>\n<\/tr>\n<tr>\n<td>Log integrity<\/td>\n<td>Tamper protection, restricted access<\/td>\n<td>Integrity checks, access logs<\/td>\n<\/tr>\n<tr>\n<td>Time synchronization<\/td>\n<td>Consistent timestamps across sources<\/td>\n<td>NTP configuration, normalized timelines<\/td>\n<\/tr>\n<tr>\n<td>Incident management<\/td>\n<td>Classification, investigation, and escalation<\/td>\n<td>Incident records<\/td>\n<\/tr>\n<tr>\n<td>Reporting<\/td>\n<td>Configurable regulatory and management reports<\/td>\n<td>Generated reports<\/td>\n<\/tr>\n<tr>\n<td>Auditability<\/td>\n<td>Immutable or protected audit trails<\/td>\n<td>Audit logs<\/td>\n<\/tr>\n<tr>\n<td>Threat detection<\/td>\n<td>Correlation, analytics, threat intelligence<\/td>\n<td>Detection alerts<\/td>\n<\/tr>\n<tr>\n<td>Investigation<\/td>\n<td>Search, timelines, and entity context<\/td>\n<td>Investigation records<\/td>\n<\/tr>\n<tr>\n<td>Privileged-user monitoring<\/td>\n<td>Dedicated rules for admin and service accounts<\/td>\n<td>Privileged-access reports<\/td>\n<\/tr>\n<tr>\n<td>Data-source health<\/td>\n<td>Alerts when log sources stop reporting<\/td>\n<td>Source health records<\/td>\n<\/tr>\n<tr>\n<td>Control mapping<\/td>\n<td>Reports mapped to SAMA controls<\/td>\n<td>Control-mapped reports<\/td>\n<\/tr>\n<tr>\n<td>Data residency<\/td>\n<td>Deployment options that meet Saudi data localization expectations<\/td>\n<td>Architecture documentation<\/td>\n<\/tr>\n<tr>\n<td>Deployment flexibility<\/td>\n<td>On-premises, cloud, or hybrid support<\/td>\n<td>Deployment design<\/td>\n<\/tr>\n<tr>\n<td>Third-party integration<\/td>\n<td>Visibility into vendor and outsourced access<\/td>\n<td>Third-party activity logs<\/td>\n<\/tr>\n<tr>\n<td>Arabic and local support<\/td>\n<td>Local support and language capability where needed<\/td>\n<td>Support agreements<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2><span class=\"ez-toc-section\" id=\"Questions_to_Ask_Before_Selecting_a_SIEM\"><\/span>Questions to Ask Before Selecting a SIEM<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ol>\n<li>Can the platform demonstrate continuous monitoring, including detection of data-source gaps?<\/li>\n<li>Which data sources are supported natively, including core banking, payments, and cloud platforms?<\/li>\n<li>How is log integrity protected, and can tampering be detected?<\/li>\n<li>How is retention configured and enforced, and what does long-term searchable storage cost?<\/li>\n<li>Can incidents be classified using our own severity model and tracked through closure?<\/li>\n<li>Can the platform produce audit-ready evidence without manual assembly?<\/li>\n<li>Can reports be mapped to specific SAMA control requirements?<\/li>\n<li>How quickly can historical events be searched, for example 12 months back?<\/li>\n<li>Does the platform support on-premises, cloud, and hybrid deployments with data kept in the Kingdom?<\/li>\n<li>How are privileged-user activities monitored and reported?<\/li>\n<li>Can evidence be exported in formats suitable for regulatory review?<\/li>\n<li>What happens when a control fails or a monitoring gap occurs? Is it alerted and recorded?<\/li>\n<\/ol>\n<p>Ask vendors to demonstrate these capabilities using your own scenarios, not just to confirm them in writing.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span>Conclusion<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>SAMA compliance does not end with documented policies and procedures. A Saudi bank needs operational systems that monitor activity continuously, protect security records, manage incidents, generate reports, and produce reliable evidence whenever controls are reviewed.<\/p>\n<p>When you evaluate options for SAMA cybersecurity <strong><a href=\"https:\/\/www.newevol.io\/resources\/blog\/cyber-security\/siem-for-beginners\/\">framework SIEM<\/a><\/strong> needs, focus on what you can configure, test, and demonstrate. The right platform, whether NewEvol or another solution that meets your requirements, should turn cybersecurity controls from written intentions into&nbsp;measurable, continuously monitored, and auditable operational practices.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"FAQs\"><\/span>FAQs<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"1_What_SIEM_capabilities_do_Saudi_banks_need_for_SAMA_compliance\"><\/span><span style=\"font-size: 70%;\">1. What SIEM capabilities do Saudi banks need for SAMA compliance?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Centralized log collection, continuous monitoring and alerting, correlation, incident classification and case management, protected log retention, privileged-user monitoring, and reporting and evidence export mapped to controls.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"2_Does_SAMA_require_banks_to_use_a_specific_SIEM_platform\"><\/span><span style=\"font-size: 70%;\">2. Does SAMA require banks to use a specific SIEM platform?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>No. The framework is principle-based and does not name products. Banks choose technology that lets them meet and demonstrate the control expectations.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"3_How_does_SIEM_support_SAMA_cybersecurity_controls\"><\/span><span style=\"font-size: 70%;\">3. How does SIEM support SAMA cybersecurity controls?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>It puts event management, incident management, and threat management expectations into operation. It also produces the system records that show those controls are working.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"4_What_logs_should_a_Saudi_bank_collect_for_security_monitoring\"><\/span><span style=\"font-size: 70%;\">4. What logs should a Saudi bank collect for security monitoring?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Typically authentication and access logs, privileged activity, firewall and network logs, endpoint and EDR telemetry, core banking and payment application logs, cloud platform logs, and alerts from security tools. Base the final scope on your risk assessment.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"5_How_can_SIEM_help_during_a_SAMA_cybersecurity_assessment\"><\/span><span style=\"font-size: 70%;\">5. How can SIEM help during a SAMA cybersecurity assessment?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>It gives assessors evidence of control operation: alert histories, incident records, retention settings, audit trails, and control-mapped reports. Without it, teams often fall back on manually assembled screenshots.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"6_Why_is_log_retention_important_for_SAMA_compliance\"><\/span><span style=\"font-size: 70%;\">6. Why is log retention important for SAMA compliance?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Retained logs support investigations, incident reconstruction, and audit evidence. Retention periods can come from SAMA requirements, other Saudi regulations, and internal policy, so confirm which apply before sizing your SIEM.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"7_What_evidence_should_a_bank_maintain_for_cybersecurity_monitoring\"><\/span><span style=\"font-size: 70%;\">7. What evidence should a bank maintain for cybersecurity monitoring?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Monitoring dashboards, alert and incident records, investigation notes, escalation records, privileged-access reports, configuration and retention settings, and audit trails of SIEM administration.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Saudi Central Bank (SAMA) Cyber Security Framework mostly reads as a governance document. It covers leadership, risk management, operations, and third-party security, and describes each area in terms of principles, objectives, and control considerations. A bank&#8217;s security team has to go one step further and ask what those controls mean day to day. Many&hellip; <a class=\"more-link\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/\">Continue reading <span class=\"screen-reader-text\">SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks<\/span><\/a><\/p>\n","protected":false},"author":6,"featured_media":2652,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,15],"tags":[],"class_list":["post-2650","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-siem","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks - NewEvol<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks - NewEvol\" \/>\n<meta property=\"og:description\" content=\"The Saudi Central Bank (SAMA) Cyber Security Framework mostly reads as a governance document. It covers leadership, risk management, operations, and third-party security, and describes each area in terms of principles, objectives, and control considerations. A bank&#8217;s security team has to go one step further and ask what those controls mean day to day. Many&hellip; Continue reading SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/\" \/>\n<meta property=\"og:site_name\" content=\"NewEvol\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/NewEvolPlatform\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-01T05:32:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T10:59:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/ne-blog-21.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Krunal Medapara\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@krunalpatel17\" \/>\n<meta name=\"twitter:site\" content=\"@NewEvolPlatform\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Krunal Medapara\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/\",\"url\":\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/\",\"name\":\"SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks - NewEvol\",\"isPartOf\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/ne-blog-21.jpg\",\"datePublished\":\"2026-10-01T05:32:00+00:00\",\"dateModified\":\"2026-09-30T10:59:49+00:00\",\"author\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/7929a2b0ea108d69f18541bb94a98680\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#primaryimage\",\"url\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/ne-blog-21.jpg\",\"contentUrl\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/ne-blog-21.jpg\",\"width\":1920,\"height\":900,\"caption\":\"SAMA cybersecurity\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.newevol.io\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.newevol.io\/resources\/#website\",\"url\":\"https:\/\/www.newevol.io\/resources\/\",\"name\":\"NewEvol\",\"description\":\"Innovation in Motion\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.newevol.io\/resources\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/7929a2b0ea108d69f18541bb94a98680\",\"name\":\"Krunal Medapara\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2022\/03\/krunal-mendapara-1-scaled.jpg\",\"contentUrl\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2022\/03\/krunal-mendapara-1-scaled.jpg\",\"caption\":\"Krunal Medapara\"},\"description\":\"Krunal Mendapara is the Chief Technology Officer, responsible for creating product roadmaps from conception to launch, driving the product vision, defining go-to-market strategy, and leading design discussions.\",\"sameAs\":[\"https:\/\/www.newevol.io\/\",\"https:\/\/x.com\/krunalpatel17\"],\"url\":\"https:\/\/www.newevol.io\/resources\/author\/krunal-medapara\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks - NewEvol","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/","og_locale":"en_US","og_type":"article","og_title":"SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks - NewEvol","og_description":"The Saudi Central Bank (SAMA) Cyber Security Framework mostly reads as a governance document. It covers leadership, risk management, operations, and third-party security, and describes each area in terms of principles, objectives, and control considerations. A bank&#8217;s security team has to go one step further and ask what those controls mean day to day. Many&hellip; Continue reading SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks","og_url":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/","og_site_name":"NewEvol","article_publisher":"https:\/\/www.facebook.com\/NewEvolPlatform\/","article_published_time":"2026-10-01T05:32:00+00:00","article_modified_time":"2026-09-30T10:59:49+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/ne-blog-21.jpg","type":"image\/jpeg"}],"author":"Krunal Medapara","twitter_card":"summary_large_image","twitter_creator":"@krunalpatel17","twitter_site":"@NewEvolPlatform","twitter_misc":{"Written by":"Krunal Medapara","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/","url":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/","name":"SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks - NewEvol","isPartOf":{"@id":"https:\/\/www.newevol.io\/resources\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#primaryimage"},"image":{"@id":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/ne-blog-21.jpg","datePublished":"2026-10-01T05:32:00+00:00","dateModified":"2026-09-30T10:59:49+00:00","author":{"@id":"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/7929a2b0ea108d69f18541bb94a98680"},"breadcrumb":{"@id":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#primaryimage","url":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/ne-blog-21.jpg","contentUrl":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/ne-blog-21.jpg","width":1920,"height":900,"caption":"SAMA cybersecurity"},{"@type":"BreadcrumbList","@id":"https:\/\/www.newevol.io\/resources\/blog\/sama-cybersecurity-framework-siem-saudi-banks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.newevol.io\/resources\/"},{"@type":"ListItem","position":2,"name":"SAMA Cybersecurity Framework: SIEM Requirements for Saudi Banks"}]},{"@type":"WebSite","@id":"https:\/\/www.newevol.io\/resources\/#website","url":"https:\/\/www.newevol.io\/resources\/","name":"NewEvol","description":"Innovation in Motion","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.newevol.io\/resources\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/7929a2b0ea108d69f18541bb94a98680","name":"Krunal Medapara","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/image\/","url":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2022\/03\/krunal-mendapara-1-scaled.jpg","contentUrl":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2022\/03\/krunal-mendapara-1-scaled.jpg","caption":"Krunal Medapara"},"description":"Krunal Mendapara is the Chief Technology Officer, responsible for creating product roadmaps from conception to launch, driving the product vision, defining go-to-market strategy, and leading design discussions.","sameAs":["https:\/\/www.newevol.io\/","https:\/\/x.com\/krunalpatel17"],"url":"https:\/\/www.newevol.io\/resources\/author\/krunal-medapara\/"}]}},"_links":{"self":[{"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/posts\/2650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/comments?post=2650"}],"version-history":[{"count":1,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/posts\/2650\/revisions"}],"predecessor-version":[{"id":2651,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/posts\/2650\/revisions\/2651"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/media\/2652"}],"wp:attachment":[{"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/media?parent=2650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/categories?post=2650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/tags?post=2650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}