Inovasys, founded in 2014, has been a leader in providing advanced technology solutions. By 2020, it became known as a service provider. The company aims to be the best partner for businesses looking to improve their operations with digital technology.
Digital Transformation Insights Hub
The Rosetta Stone: Building Your Unified Control Framework
Compliance chaos is not caused by too many regulators. It is caused by too many disconnected approaches. If you are answering to NCA, PDPL, and SAMA separately, you are multiplying work instead of strengthening security. The solution is not another spreadsheet. It is one unified control framework that translates your single security program into the language of every regulator.
Okay, let's recap. In Article 1, we stared into the Alphabet Soup of KSA regulators. In Article 2, we went on a Crown Jewels hunt and drew a hard line in the sand called scope.
We know what we need to protect.
Now what?
This is the point where most companies take their hard won Crown Jewels list and immediately dissolve into chaos.
Someone opens the 300 line NCA ECC spreadsheet. Someone else opens the SAMA CSF spreadsheet. A third person opens the PDPL requirements. And they all start trying to do compliance in their own separate silos.
This is where good intentions go to die in a mountain of Excel files.
You will have three different teams asking your network admin the same question about firewall rules, just worded three different ways. You will write an Access Control Policy for NCA and a separate Access Control Policy for SAMA. It becomes duplicated effort, version control confusion, and sometimes conflicting rules.
It is inefficient. And it has to stop.
The Aha Moment: It Is One Job, Not Three
You are not running an NCA program or a PDPL program. You are running one security program. You have one firewall. You have one way of granting access.
Your job is to build one set of strong, smart, defensible controls and then prove to each regulator that your single approach satisfies their specific requirements.
To do this, you need a Rosetta Stone.
The original Rosetta Stone was a single slab of rock with the same royal decree carved into it in three different scripts. Because scholars knew one script, they could use it to unlock and translate the others.
Your Unified Control Framework, UCF, is your security program’s Rosetta Stone. It is one central document, one source of truth, that lists your single set of controls. Then, it translates each control into the language of every regulator.
How to Build Your Rosetta Stone in 3 Steps
This is the most important work you will do. It is not a technical tool. It is a strategic exercise.
Step 1: Pick Your Baseline
A rookie mistake is to open a blank spreadsheet and start writing. Never do this.
Instead, you pick a strong, comprehensive framework to be your baseline or master language. Here in KSA, the choice is obvious: the NCA Essential Cybersecurity Controls ECC.
It is locally mandated, robust, and a powerful foundation for a mature security program. This becomes the spine of your framework.
Step 2: The Magic of Mapping
Now, you list your controls, the things you actually do, based on that NCA spine. Then, you add new columns for every other regulator you answer to.
Your goal is to fill in the blanks. You read a PDPL requirement and realize it is another way of describing an NCA control you are already performing.
Let’s see it in action:
| Our Single Control | What We Actually Do (The Policy) | NCA ECC | PDPL | SAMA CSF |
|---|---|---|---|---|
| Access Control | We have a documented policy. All user access is reviewed by a manager quarterly. | 1-4-2 | Art. 19 | 2.1.3 |
| Data Encryption | All Crown Jewel data, as defined in our scope, is encrypted at rest using AES 256. | 2-5-1 | Art. 20 | 3.4.1 |
| Risk Assessment | We conduct a formal risk assessment on all critical systems annually. | 1-1-1 | Art. 19 | 1.1.1 |
Look at that.
You do not have three different access control policies. You have one.
You do not conduct three different risk assessments. You conduct one.
You have simply mapped that one activity to three different regulatory books.
Step 3: The Payoff: Audit Once, Report Many
This is where you get your life back.
The SAMA auditor comes in and says, Show me how you comply with SAMA CSF 2.1.3.
The old way was panic. Search for the SAMA spreadsheet. Confirm the latest version of the policy.
The new way is calm. Here is our Unified Control Framework. Our master Access Control policy satisfies requirement 2.1.3. Here is the supporting evidence from our last review.
Next week, the PDPL auditor asks, How do you protect personal data under Article 19?
You pull out the exact same document. The same framework. The same controls.
This is audit once, report many. You do the work once, and you prove it everywhere.
You are no longer juggling. You are in control.
The machine is designed. The Rosetta Stone is carved. Your fortress is structured, and all regulators have a map they can understand.
But a blueprint is not a building.
A policy in a binder does not stop a hacker.
How do you operationalize these controls?
How do you ensure they work every day?
And how do you prove resilience when an incident inevitably happens?
That is the final piece: making your program breathe.
FAQs
1. What is a Unified Control Framework in practical terms?
It is a centralized control register that maps one set of organizational security controls to multiple regulatory requirements, eliminating duplication and confusion.
2. Why use NCA ECC as the baseline in KSA?
Because it is locally mandated, comprehensive, and aligns well with SAMA CSF and PDPL requirements, making mapping more efficient.
3. Does mapping mean fewer controls?
No. It means fewer duplicate documents. You still maintain strong controls; you simply organize and translate them efficiently.
4. Is this approach suitable for regulated financial institutions?
Yes. It is especially valuable for banks and fintech organizations answering to SAMA, NCA, and PDPL simultaneously, as it reduces audit fatigue and increases consistency.
