Skip to content
Sentinel Unity
National baseline

NCA ECC: Essential Cybersecurity Controls

A national cybersecurity baseline, structured as domains and controls with an expectation of full coverage rather than selective adoption. Sentinel Unity holds it the same way it holds every other standard: as data, mapped to the controls you already test.

Issued by the National Cybersecurity Authority of Saudi Arabia. Held in the library as one framework among many, alongside whichever baseline applies to you.

  1. 1Questionnaire templateVersioned revisions, sections, question types
  2. 2CampaignRecurrence pattern set by the programme owner
  3. 3AssignmentsPer respondent, delegation permitted
  4. 4ResponsesEvidence attached per question
  5. 5Risk proposalFindings promoted into the risk register

Five

Domains

0 to 5

Maturity scored

Graded

Mapping to other standards

Versioned

Library releases

Structure

Five domains, governance through industrial systems

Each domain becomes part of the control tree, so an assessment can be scoped to one domain or run across all of them.

Cybersecurity Governance

Leadership accountability, strategy, policy direction, and organisational risk management.

  • Leadership role
  • Strategy
  • Policy direction
  • Risk management

Cybersecurity Defence

Identity, network, endpoint, and application protection across the estate.

  • Identity and access
  • Network protection
  • Endpoints
  • Applications

Cybersecurity Resilience

Continuity of operations: incident response, disaster recovery, and restoration.

  • Incident response
  • Disaster recovery
  • Restoration
  • Continuity testing

Third-Party & Cloud Security

Assurance over suppliers and hosted environments, before engagement and through the contract.

  • Supplier assessment
  • Cloud baseline
  • Contract clauses
  • Sub-suppliers

Industrial Control Systems

Operational technology security, where availability usually outranks confidentiality.

  • Industrial risk
  • Network separation
  • Response
  • Patching windows

Platform mapping

How the platform holds it

Nothing here is specific to this framework. Load a standard, map it, assess it, and the same mechanics apply.

Loaded from a workbook

Controls import from a header-based Excel file, so columns can arrive in any order and a revision is a re-import rather than a rebuild.

Published as a version

A library release stages a validated snapshot before it goes live, so content is reviewed before anyone assesses against it.

Graded mapping, not a tick

Each mapping to another standard carries a level, so partial coverage reads as partial rather than as done.

Applicability tags

Controls carry People, Process, Technology, Data, and Facility tags, which is what lets a facilities question reach a facilities owner.

Evidence that is reviewed

Evidence requirements are defined per control, and what gets uploaded passes a review step rather than being accepted on arrival.

Gaps become findings

A shortfall raises a finding with severity, an owner, and a remediation plan that can depend on other plans.

Maturity

How maturity is scored

Every control is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.

Level 0

Not Performed

The practice does not happen. Recorded as an explicit level rather than a blank.

Level 1

Performed Informally

It happens, but it depends on individuals and is neither planned nor tracked.

Level 2

Planned & Tracked

Planned, resourced, and monitored, though practice still varies between teams.

Level 3

Well Defined

A defined standard process, applied consistently across the organisation.

Level 4

Quantitatively Controlled

Measured against targets, with deviation detected from the measurements themselves.

Level 5

Continuously Improving

Improvement is fed by the measurements, changing the process rather than the reporting.

See a national baseline running beside your other frameworks

Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.

No commitment required. A typical demo runs 45 minutes.