Governance. Risk. Compliance. Cybersecurity.
Controls & Requirements

Controls & Requirements — NCA ECC

NCA ECC requires a defined, evidenced and continuously monitored control set. MAST maintains a unified control catalogue that maps each requirement to your existing controls — eliminating duplication.

  • ISO/IEC 27001 Certified
  • ISO/IEC 27701 Certified
  • ISO 9001 Certified

Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation

Control domains

  • Cybersecurity governance
  • Cybersecurity defence
  • Cybersecurity resilience
  • Third-party and cloud computing cybersecurity
  • Industrial control systems cybersecurity
NCA ECC control coverage by domain

Horizontal bar chart titled "NCA ECC control coverage by domain". Values: Cybersecurity governance 70%, Cybersecurity defence 83%, Cybersecurity resilience 96%, Third-party and cloud computing cybe 79%, Industrial control systems cybersecu 92%.

  • Cybersecurity governance
    70%
  • Cybersecurity defence
    83%
  • Cybersecurity resilience
    96%
  • Third-party and cloud computing cybe
    79%
  • Industrial control systems cybersecu
    92%

How we document each control

  • Statement of control and intent
  • Owner, executor and reviewer (RACI)
  • Frequency, trigger and operating window
  • Evidence type, location and retention
  • Linked risks and KRIs
  • Audit history and last test result
Control record fields

Checklist titled "Control record fields" with 6 items, every item marked complete: Statement of control and intent; Owner, executor and reviewer (RACI); Frequency, trigger and operating window; Evidence type, location and retention; Linked risks and KRIs; Audit history and last test result.

  • Statement of control and intent
  • Owner, executor and reviewer (RACI)
  • Frequency, trigger and operating window
  • Evidence type, location and retention
  • Linked risks and KRIs
  • Audit history and last test result

Mapping to adjacent frameworks

Our catalogue maps each control to ISO 27001, ISO 27701, SOC 2, NIST CSF, PCI DSS, CBUAE, SAMA, NCA ECC and ADHICS v2. One implementation, many audits.