nca.gov.sa New Cloud Cybersecurity Controls Released Amidst Data Localization Changes
Article Content
- •The Cloud Cybersecurity Controls (CCC – 2: 2024) were updated to enhance national cybersecurity.
- •The CCC sets minimum cybersecurity requirements for Cloud Service Providers and Tenants.
- •The Cloud Controls Matrix (CCM) provides a comprehensive framework for assessing cloud security.
On July 24, 2026, the Cloud Cybersecurity Controls (CCC – 2: 2024) were updated to address data localization requirements affecting Cloud Service Providers (CSPs) and Cloud Service Tenants (CSTs). This update aims to enhance national cybersecurity goals by establishing minimum cybersecurity requirements for cloud computing services. The CCC serves as an extension to the existing ECC framework, focusing on mitigating cyber risks associated with cloud services. The update was last modified on June 24, 2026, and is intended to help CSPs and CSTs ensure secure cloud operations. The Cloud Controls Matrix (CCM) was also released on the same day, providing a comprehensive framework for assessing cloud security controls and aligning with industry standards. The CCM includes 197 control objectives across 17 domains, guiding organizations in implementing necessary security measures. Both frameworks are crucial for organizations looking to bolster their cloud security posture in light of evolving threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…