The SAMA Cyber Threat Intelligence Principles — Cyber Threat Intelligence Principles for Financial Sector, issued under Circular 43065348 of 27 February 2022 and recorded In-Force in the SAMA Rulebook — turn one subdomain of the Cyber Security Framework into a discipline of its own. SAMA describes the document as an extension of the Framework’s Threat Management subdomain, 3.3.16, and makes it mandatory for all Member Organizations, including those that outsource their CTI capability.
Its nineteen principles are arranged in four domains that follow the kinds of intelligence they produce: Core CTI (Principles 1–11) covers the intelligence life cycle from roles and requirements through collection, processing, analysis, sharing and delivery to continuous improvement and integration; Strategic CTI (12–14) covers the threat landscape, strategic attack scenarios and requests for information; Operational CTI (15–17) covers the attack chain, TTPs and malware and tools; and Technical and Tactical CTI (18–19) covers indicators of compromise and vulnerability monitoring.
This guide sets out all nineteen principles as SAMA names them, explains what each domain is for and what the Cyber Security Framework already required, describes how the principles are assessed alongside the Framework’s maturity model, and lays out how to build or contract a CTI capability that satisfies them.

What the SAMA Cyber Threat Intelligence Principles are for
The introduction frames CTI as the ability to collect, analyse and share data about cyber threats so that an organisation can anticipate attacks and protect critical information assets, and states the document’s aim as scaling up CTI practice across the SAMA-regulated financial sector. Three scoping statements matter. The principles are mandatory for all Member Organizations regulated by SAMA. All principles should be applied, with a phased approach to full implementation at the organisation’s discretion. And they apply also to Member Organizations that outsource their CTI capability — the obligation follows the organisation, not the provider. Our guide to the SAMA CSF domains covers subdomain 3.3.16, which required a threat intelligence process before the principles set out what one contains.
SAMA Cyber Threat Intelligence Principles, domain 1: Core CTI
The Core principles are described as a prerequisite to the practice of CTI, informing the other three domains, and they follow the intelligence life cycle — planning, collection, processing, analysis, dissemination — plus improvement and integration.
| Principle | Title | What SAMA asks for |
|---|---|---|
| 1 | Define Roles and Responsibilities | A dedicated team to produce and disseminate threat intelligence, with skilled resources, purpose-specific advanced tools and a defined budget; communication channels to cyber security, business, risk and external organisations |
| 2 | Define Threat Intelligence Planning and Collection Requirements | Threat intelligence requirements that guide production — scope (organisational, sectoral, national), the intelligence to be produced for security and business objectives |
| 3 | Select and Validate Relevant Sources | Sources selected against the requirements, with the source types defined and validated for the intelligence they are likely to produce |
| 4 | Collect Data Through Intelligence Sources | Collection across diverse sources — OSINT, TECHINT, SOCMINT, HUMINT, deep and dark web |
| 5 | Define Specific Standard Operating Procedures | SOPs for the CTI activities |
| 6 | Process and Classify Information | Collected intelligence processed and classified, manually or automatically, and stored securely |
| 7 | Analyze Information | Quantitative and qualitative analytical techniques applied to produce actionable intelligence |
| 8 | Share Intelligence | Specific sharing standards for dissemination, using the delivery methods the document’s annex describes |
| 9 | Deliver Actionable Threat Intelligence | Decisions and actions implemented on the intelligence produced, to build the resilience of the sector |
| 10 | Continuously Improve Methods of Intelligence | The CTI capability and performance maintained and improved |
| 11 | Integrate CTI | CTI integrated into situational awareness and other security processes |
Domains 2 to 4: Strategic, Operational, Technical and Tactical
| Domain | Principle | Title | What SAMA asks for |
|---|---|---|---|
| Strategic | 12 | Identify a Cyber Threat Landscape | The landscape relevant to the organisation: vulnerable assets, threats, risks, threat actors and trends, including events shaping the sector’s landscape; threat actors’ origin, intent, motivation and capabilities; assessment and prioritisation |
| Strategic | 13 | Identify Strategic Cyber Attack Scenarios | Realistic scenarios of likely attacks, involving one or more threat actors and one or more of the organisation’s assets |
| Strategic | 14 | Elaborate Requests for Information and Tailored Threat Assessments | RFIs and tailored assessments answering specific stakeholder questions |
| Operational | 15 | Define the Attack Chain | The phases of an attack defined and taxonomised on an industry framework — the kill chain, the unified kill chain |
| Operational | 16 | Identify TTPs | The tactics, techniques and procedures of relevant threat actors analysed from collected information |
| Operational | 17 | Identify Malware and Tools | Malware and tools used by threat actors identified during analysis |
| Technical and Tactical | 18 | Collect IoCs | Indicators of compromise identified, collected, aggregated and implemented in the defence infrastructure, with details of malware and tool implementation to test detection and mitigation |
| Technical and Tactical | 19 | Monitor and Report Vulnerabilities | Constant monitoring of newly announced and zero-day vulnerabilities exploited by threat actors, reported to the relevant internal parties |
SAMA’s own descriptions distinguish the domains by purpose: strategic CTI identifies the objectives, motivations and intent of threat actors; operational CTI their modus operandi, behaviour and techniques; technical and tactical CTI the technical components and indicators of attacks. A programme that produces only IoC feeds has Domain 4 and nothing else.
SAMA Cyber Threat Intelligence Principles vs what the CSF already required
| CSF subdomain | Requirement | What the CTI Principles add |
|---|---|---|
| 3.3.16 Threat Management | A threat intelligence process to identify, assess and respond to threats | The nineteen principles that define what the process contains, with a dedicated team, requirements, sources and outputs |
| 3.3.14 Cyber Security Event Management | A security event management process with a SOC | Principle 11 integrates CTI into monitoring; Principle 18 feeds IoCs into the defence infrastructure |
| 3.3.17 Vulnerability Management | Identification and mitigation of vulnerabilities | Principle 19 adds monitoring of announced and zero-day vulnerabilities and reporting to the relevant parties |
| 3.3.15 Cyber Security Incident Management | Incident identification, response and recovery | Operational CTI — attack chain, TTPs, malware — informs response |
| 3.2.1 Cyber Security Risk Management | Risk identification, analysis, response, monitoring | Strategic CTI — the threat landscape and attack scenarios — is the threat input to risk assessment |
Because the SAMA Cyber Threat Intelligence Principles extend the Framework, they are assessed with it: the Framework’s self-assessment and maturity model apply, and the CTI capability’s maturity is read through subdomain 3.3.16 and the subdomains it feeds. Our guide to SAMA compliance covers the model.
Building or contracting the capability
- Start with Principles 1 and 2. The team, budget, tools and channels, and the intelligence requirements — everything else is scoped by them, and an outsourced provider cannot write your requirements for you.
- Map sources to requirements (3 and 4). Commercial feeds, sector sharing, national sources, open and dark web; each source justified by a requirement it serves.
- Write the SOPs and the classification scheme (5 and 6). Collection, handling and storage of intelligence, including sensitivity marking for sharing.
- Produce all three intelligence types. A quarterly threat landscape and attack scenarios (12–13), an attack-chain taxonomy with TTP profiles of the actors that matter (15–17), and operational IoC and vulnerability feeds (18–19) — with RFIs answered on demand (14).
- Close the loop (7–11). Analysis that produces decisions, sharing standards, evidence that actions were taken, improvement metrics, and integration into the SOC, risk assessment and incident response.
- If outsourcing, keep the obligations. The principles apply to organisations that outsource CTI; the contract must deliver the outputs, and the organisation must retain the requirements, the integration and the decisions — and treat the arrangement under the outsourcing rules. Our guide to SAMA outsourcing covers that.
Frequently asked questions
What are the SAMA Cyber Threat Intelligence Principles?
Cyber Threat Intelligence Principles for Financial Sector, issued by the Saudi Central Bank under Circular 43065348 on 27 February 2022: nineteen mandatory principles in four domains — Core CTI (1–11), Strategic (12–14), Operational (15–17) and Technical and Tactical (18–19) — extending subdomain 3.3.16 of the Cyber Security Framework.
Who must implement them?
All Member Organizations regulated by SAMA, including those that outsource their CTI capability; a phased approach to full implementation is at the organisation’s discretion.
How do they relate to the Cyber Security Framework?
SAMA describes the document as an extension of the Framework’s Threat Management subdomain; the Framework required a threat intelligence process, and the principles define what that process must contain and produce.
What does the Core domain require?
A dedicated CTI team with tools and budget, defined intelligence requirements, validated sources, collection across OSINT, TECHINT, SOCMINT, HUMINT and the dark web, SOPs, processing and classification, analysis, sharing standards, actionable delivery, continuous improvement and integration.
Can we rely on a commercial threat feed?
A feed satisfies parts of the Technical and Tactical domain. The Core, Strategic and Operational domains require requirements, a threat landscape, attack scenarios, TTP analysis and integration that a feed does not provide, and the obligations remain with the organisation even when CTI is outsourced.
Where this leaves you
Implement the SAMA Cyber Threat Intelligence Principles as the four-domain capability they describe: a team with requirements and validated sources at the core, a strategic view of the landscape and the scenarios, an operational view of how the relevant actors attack, and the technical indicators and vulnerabilities that reach the defence infrastructure — integrated into the SOC, the risk assessment and incident response, and retained by the organisation even when the production is outsourced, because the principles are mandatory and assessed through the Framework they extend.
References
- SAMA Rulebook — Cyber Threat Intelligence Principles for Financial Sector (Circular 43065348, 27 February 2022) — Introduction, scope and Principles 1–19.
- SAMA Rulebook — Cyber Security Framework — Subdomain 3.3.16 Threat Management.
More on SAMA
- The SAMA Cyber Threat Intelligence Principles — you are here
- SAMA compliance: the maturity levels
- The SAMA CSF domains
- The SAMA IT Governance Framework
- The SAMA Business Continuity Management Framework
- SAMA CSF vs NCA ECC
The threat intelligence policy and SOPs, the intelligence requirements register, the source validation record, the threat landscape and attack scenario templates and the IoC and vulnerability handling procedures are in the SAMA Compliance Toolkit, or start with the free templates.