Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NCA ECC defense domain subdomains from asset management to incident management

NCA ECC Defense Domain: Controls Explained 2026

The NCA ECC defense domain is the largest part of the Essential Cybersecurity Controls issued by Saudi Arabia’s National Cybersecurity Authority. Where the governance domain sets direction and accountability, the defense domain contains the technical and operational protections: knowing what assets you have, controlling who can reach them, protecting networks and data, and detecting and responding to attacks. For most organisations subject to the controls, it is where most of the implementation effort goes.

This guide explains what the NCA ECC defense domain covers, walks through its subdomains, and shows what evidence to gather for an assessment. Structure details reflect the ECC-2:2024 edition as described in secondary summaries, so check numbering against the official text before you cite it.

Free gap assessment

How much of ECC-2:2024 is actually in place?

Score all 28 subdomains, free, plus the other NCA control sets that apply alongside the ECC.

Run the free NCA ECC gap assessment →  or  View premium report sample

Where the defense domain sits in the ECC

The ECC is published by the NCA and is available on the NCA website. Published summaries of the 2024 edition describe four main domains: cybersecurity governance, cybersecurity defense, cybersecurity resilience, and third-party and cloud computing cybersecurity. The earlier 2018 edition also had a fifth domain for industrial control systems, which has been removed from the essential controls and is covered by separate controls for operational technology. See our guides to ECC-2:2024 and the NCA cybersecurity controls for the full picture.

The defense domain is the one that ties most closely to day-to-day technology operations. It is where security engineers, network teams and system administrators find their obligations.

Subdomains of the NCA ECC defense domain

Summaries of the domain list fifteen subdomains. The table groups them by theme, using the names commonly used in the published text.

ThemeSubdomainsTypical evidence
Assets and accessAsset management; identity and access managementAsset register; access review records; MFA configuration
Systems and networksInformation system and processing facilities protection; network security management; mobile device security; email protection; web application securityHardening standards; network diagrams; firewall rules; email filtering settings
Data protectionData and information protection; cryptography; backup and recoveryClassification records; key management procedure; restore test results
Testing and monitoringVulnerability management; penetration testing; event log and monitoring managementScan reports; test reports; SIEM or log review records
ResponseCybersecurity incident and threat managementIncident plan; incident log; threat intelligence subscriptions
PhysicalPhysical securityAccess logs; visitor records; site controls

Asset management and access control

Everything else in the defense domain depends on knowing what you protect. The asset management subdomain expects an inventory of information and technology assets, with owners, and rules for acceptable use and return. Keep the register current by linking it to procurement and offboarding, and reconcile it against discovery scans at least periodically.

Identity and access management then controls who can use those assets. Expect requirements around user provisioning and removal, least privilege, privileged access management, multi-factor authentication for remote and privileged access and periodic review of access rights. Auditors sample joiners, movers and leavers, so make sure access is removed within a defined time and that reviews are recorded with names and dates.

Systems, network, email and web protection

These subdomains cover the technical hardening of your environment. Systems should be built to approved secure configurations, kept patched and protected against malware. Networks should be segmented, with firewall rules reviewed and remote access secured. Email needs filtering, authentication controls and protection against phishing. Web applications, particularly those exposed to the internet, need secure development, testing and protection. Mobile devices used for work need management and protection, including controls on personal devices.

Evidence includes configuration standards, baseline scans, network diagrams, firewall review records, patch reports, email security settings and web application test results. The strongest evidence is a record showing a control working over time, not a policy statement.

Data protection, cryptography and backup

The data and information protection subdomain expects classification and handling rules aligned to the organisation’s own data and to applicable Saudi law and NCA guidance. Cryptography controls cover approved algorithms, key management and protection of data in transit and at rest. Backup and recovery requires regular backups of critical systems, protection of the backups themselves and periodic restore testing. For related controls on data specifically, see our guide to the data cybersecurity controls.

Restore tests are frequently missing at assessment. A backup that has never been restored is an assumption, not a control, so schedule tests and keep the results.

Vulnerability management and penetration testing

These subdomains require you to find and fix weaknesses systematically. Vulnerability management involves regular scanning, risk-based prioritisation and defined timelines for remediation. Penetration testing checks defences from an attacker’s viewpoint and is expected at a defined frequency for critical systems and internet-facing applications. Keep the scan reports, the tickets showing remediation and the retest results. A list of findings with no follow-up is a weak point.

Logging, monitoring and incident management

Event log and monitoring management requires that security-relevant events be collected, protected and reviewed, with alerting for suspicious activity. Incident and threat management requires a plan, roles, classification of incidents, escalation and reporting routes, lessons learned and use of threat intelligence. Your plan should include how and when incidents are reported to the NCA where required. Test it with a tabletop exercise and keep the record.

Physical security within the defense domain

Physical controls protect facilities that house information and technology assets. Typical expectations include controlled entry, visitor management, monitoring of sensitive areas and protection of equipment and cabling. For data centres and server rooms, keep access lists and logs and review them regularly.

Prioritising work in the NCA ECC defense domain

You will rarely fix everything at once, so sequence the work. Start with controls that other controls depend on: the asset inventory, privileged access and logging. Then address controls where a failure would cause the most harm, such as internet-facing systems, remote access and backups of critical data. Leave lower-risk refinements, such as documentation polish, until the foundations are in place. Record the plan so an assessor can see that gaps are known and scheduled.

Assign every subdomain of the NCA ECC defense domain to a named owner in IT, security or facilities, and review progress monthly. Report the position to senior management using simple status colours, and escalate any control that cannot be met within the planned time so that a business owner can accept the risk formally. The NCA ECC defense domain rewards steady, evidenced progress over last-minute effort before an assessment.

A hypothetical example of preparing for the defense domain

The following is a hypothetical example invented for illustration. A Saudi logistics company prepares for an NCA assessment. Using the fifteen subdomains as a checklist, its security manager builds a tracker with the control, the owner, the evidence, its date and the status. The tracker shows strong network and email controls but three gaps: the asset inventory omits cloud workloads, privileged access reviews last took place 14 months ago, and there is no evidence of a backup restore test.

The team runs a discovery scan and adds cloud accounts to the inventory, completes the access review in two weeks, and performs a restore test of its finance database. It stores each result in the evidence folder against the control. When the assessor arrives, every subdomain has a dated record, and the remaining finding concerns the frequency of penetration testing, which the company documents in an agreed plan.

Common mistakes with the NCA ECC defense domain

Frequent problems include an incomplete asset inventory, access reviews that are overdue, technical settings that differ from the written standard, backups never tested, scans without remediation records, logs collected but never reviewed, incident plans never exercised, and evidence that is a policy rather than a record of the control working. Another is treating the domain as an IT task only. Business owners must accept the risks where a control cannot be met.

Assessing yourself against the defense domain

A self-assessment is the best preparation. Rate each control as implemented, partly implemented, not implemented or not applicable, with evidence. Our guide to an NCA ECC self-assessment shows how to structure it, and the implementation guide describes how to close gaps. Recheck after each change and before formal assessment.

Templates for the NCA ECC defense domain

Ready-made documents make it faster to produce the policies, procedures and registers that support the domain. The NCA Cybersecurity Toolkit provides templates aligned to NCA requirements. Whatever you use, tie each document to the control it supports and keep evidence dated and traceable.

NCA ECC defense domain FAQ

What does the NCA ECC defense domain include?

Published summaries describe fifteen subdomains covering asset management, identity and access, system, network, email, mobile and web protection, data protection, cryptography, backup, vulnerability management, penetration testing, logging, incident management and physical security.

Is the defense domain the largest part of the ECC?

Yes, in terms of subdomains and controls it is the largest domain in the summaries of ECC-2:2024, which is why it takes most implementation effort.

What evidence do assessors expect?

Dated records showing that controls operate: registers, reviews, scan and test reports, restore results, log reviews and incident exercises, not only policies.

Does the domain apply to cloud systems?

Yes. Cloud assets fall within the defense controls as well as the third-party and cloud domain, so include them in your inventory and reviews.

Where can I find the official text?

On the National Cybersecurity Authority website. Always check the current edition and control numbers there before citing them in your documents.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.