Skip to main content
Version: 1.0.0-beta

CSCC Compliance

AIIA supports the Cloud Security Cybersecurity Controls (CSCC) framework issued by NCA for cloud service providers and cloud consumers in Saudi Arabia.

Framework Details

PropertyValue
CodeCSCC-1:2019
NameCloud Security Cybersecurity Controls
Issuing BodyNCA
CountrySaudi Arabia
CategoryRegulatory

CSCC Domains

DomainFocus Area
Cloud GovernancePolicies, risk management, compliance
Cloud Security ArchitectureNetwork security, data protection, encryption
Cloud Identity & AccessAuthentication, authorization, privilege management
Cloud Data ProtectionClassification, handling, residency requirements
Cloud OperationsMonitoring, incident response, change management
Cloud Business ContinuityDisaster recovery, availability, resilience

Usage in AIIA

Follow the same workflow as other frameworks:

  1. Enable CSCC in Compliance → Frameworks
  2. Map your cloud controls to CSCC requirements
  3. Assess compliance status per requirement
  4. Track progress via the compliance dashboard

Cross-Framework Mapping

CSCC shares controls with:

  • NCA ECC — cybersecurity governance and defense
  • ISO 27017 — cloud security
  • CSA STAR — cloud security alliance framework

Cloud-Specific Considerations

CSCC compliance is particularly relevant for:

  • Organizations using cloud services in Saudi Arabia
  • Cloud service providers serving Saudi clients
  • Hybrid deployments combining on-premises and cloud