Wadira: Find your way through Saudi data & privacy law.
Home › Frameworks › Cybersecurity › Guide to Data Cybersecurity Controls (DCC) Implementation
| Type | Guideline |
|---|---|
| Issuing authority | National Cybersecurity Authority (NCA) |
| Framework | Cybersecurity |
| Tier | Guidelines & circulars |
| Legal status | Guidance |
The Guide to Data Cybersecurity Controls (DCC) Implementation (GDCC-1:2023) is the National Cybersecurity Authority's public implementation guide for the Data Cybersecurity Controls, intended to help in-scope organisations put the controls into effect.
It sets out the DCC's domains and subdomains (cybersecurity governance, cybersecurity defence, and third-party and cloud computing cybersecurity), covering areas such as cybersecurity in human resources, awareness and training, identity and access management, protection of information systems and processing facilities, mobile-device security, data and information protection, cryptography, secure data disposal, cybersecurity for printers, scanners and copy machines, periodic review and audit, and third-party cybersecurity. After explaining the guideline's structure it provides implementation guidance under each domain in turn. The DCC extend the NCA's Essential Cybersecurity Controls (ECC) baseline with requirements focused on protecting data across its lifecycle, and the guide belongs to the NCA's wider series of implementation guides.
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13