Wadira: Find your way through Saudi data & privacy law.
Home › Frameworks › Cybersecurity › Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC-1:2021)
| Type | Framework |
|---|---|
| Issuing authority | National Cybersecurity Authority (NCA) |
| Framework | Cybersecurity |
| Tier | Rules, controls & standards |
| Legal status | Binding |
The Organizations' Social Media Accounts Cybersecurity Controls (OSMACC-1:2021) are the National Cybersecurity Authority's minimum cybersecurity requirements for the safe official use of social networks, developed in response to rising theft, misuse and impersonation of organisations' accounts.
The controls apply to government organisations in the Kingdom (ministries, authorities, establishments and related companies) and to private-sector organisations that own, operate or host sensitive national infrastructure; the NCA encourages all other organisations to adopt them. They comprise 3 main domains, 12 subdomains, 15 main controls and 38 subcontrols, aligned with the Essential Cybersecurity Controls (ECC): continuous ECC compliance is a prerequisite, and compliance, required under item 3 of Article 10 of the NCA's mandate, is assessed through means such as self-assessment and on-site audits. A separate NCA guide (GOSMACC-1:2023) supports implementation.
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13