Leadership & Governance
Board and executive accountability, defined security leadership, strategy, and reporting lines.
- Accountability
- Strategy
- Committee reporting
A financial-sector cyber framework with an unusually heavy third-party emphasis, which is why it pairs naturally with a platform where vendor risk and control assessment sit on the same record rather than in two systems.
Issued by the Saudi Central Bank for the institutions it supervises. Held as an example of a sector regulator: your own is added the same way.
Organised crime group
Unpatched edge appliance
3 asset instances
Control effectiveness is scored separately for design, operation, and implementation, so a well-designed control that is not operating does not quietly reduce the score.
Five
Domains
0 to 5
Maturity scored
Linked
To the vendor register
Graded
Mapping to other standards
Structure
The third-party domain is the one that most often forces a second tool. Here it reads the same vendor records as the rest of the programme.
Board and executive accountability, defined security leadership, strategy, and reporting lines.
Appetite, assessment, and treatment, with residual position recorded rather than implied.
Identity, network, endpoint, logging, and monitoring practice.
Tiering, due diligence before engagement, contractual security, and ongoing monitoring.
Incident response and recovery, tested rather than documented.
Platform mapping
The vendor mechanics below are the product's own, used for any framework with a supplier chapter.
Vendors are tiered by scored factors against a profile, so placement is reproducible rather than a judgement call made twice.
A disqualifying answer stops the engagement instead of being averaged into an acceptable overall score.
Record who your suppliers depend on, so concentration one level below your own contracts becomes visible.
Audit rights, notification windows, and security commitments become tracked obligations with categories, statuses, and review decisions.
Requests carry a document type and a validity status, so an expired certificate stops counting as evidence on its expiry date.
Re-assessment timing follows rules tied to tier, rather than a reminder in someone's calendar.
Maturity
Every control, including the third-party domain, is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.
Level 0
Not Performed
The practice does not happen. Recorded as an explicit level rather than a blank.
Level 1
Performed Informally
It happens, but it depends on individuals and is neither planned nor tracked.
Level 2
Planned & Tracked
Planned, resourced, and monitored, though practice still varies between teams.
Level 3
Well Defined
A defined standard process, applied consistently across the organisation.
Level 4
Quantitatively Controlled
Measured against targets, with deviation detected from the measurements themselves.
Level 5
Continuously Improving
Improvement is fed by the measurements, changing the process rather than the reporting.
Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.
No commitment required. A typical demo runs 45 minutes.