PMBOK
Global standard for project management practices and governance
SAMA CSF
Saudi regulatory framework for financial cybersecurity
Quick Verdict
PMBOK provides voluntary project management principles globally, while SAMA CSF mandates cybersecurity controls for Saudi finance. Organizations adopt PMBOK for standardized delivery; SAMA CSF for regulatory compliance and resilience.
PMBOK
A Guide to the Project Management Body of Knowledge
Key Features
- Five Process Groups organizing project lifecycle activities
- Ten Knowledge Areas covering management disciplines
- ITTO framework for process inputs outputs traceability
- Tailoring for predictive adaptive hybrid approaches
- Principles and performance domains for value delivery
SAMA CSF
SAMA Cyber Security Framework Version 1.0
Key Features
- Six-level maturity model with Level 3 baseline
- Four domains covering governance to third-party risks
- Principle-based controls aligned with NIST and ISO
- Mandatory CISO appointment and board oversight
- Self-assessment and periodic SAMA audits required
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
PMBOK Details
What It Is
PMBOK® Guide, published by PMI, is a standard and guide documenting generally accepted project management practices. It applies to all project types across industries, evolving from process-based (6th edition: five Process Groups, ten Knowledge Areas) to principle-based (7th/8th editions: 12 principles, performance domains). Core approach emphasizes tailoring for predictive, adaptive, or hybrid lifecycles.
Key Components
- **Process GroupsInitiating, Planning, Executing, Monitoring/Controlling, Closing.
- **Knowledge AreasIntegration, Scope, Schedule, Cost, Quality, Resources, Communications, Risk, Procurement, Stakeholders (~49 processes with ITTOs).
- **Modern elements6-7 performance domains (governance, stakeholders, etc.), principles like value focus, stewardship.
- No formal certification for standard; aligns with PMP® credentialing.
Why Organizations Use It
Drives predictability, reduces overruns (high-performers 3x more likely to standardize), embeds risk/compliance controls. Provides governance baseline, common language, competitive edge in procurement/regulated sectors. Builds stakeholder trust via traceability, benefits realization.
Implementation Overview
Phased rollout: assess gaps, tailor processes, pilot, train (PMP-aligned), deploy tools/PMO. Suits all sizes/industries; 12-24 months typical. Focuses on maturity models like OPM3, continuous improvement.
SAMA CSF Details
What It Is
The Saudi Arabian Monetary Authority Cyber Security Framework (SAMA CSF) Version 1.0 (May 2017) is a mandatory regulatory framework for SAMA-regulated financial institutions in Saudi Arabia. Its primary purpose is to ensure cybersecurity resilience through governance, risk management, and controls, using a principle-based, outcome-oriented approach with a six-level maturity model (minimum Level 3: Structured and Formalized).
Key Components
- Four main **domainsCyber Security Leadership & Governance, Risk Management & Compliance, Operations & Technology, Third-Party Cyber Security.
- Numerous subdomains with principles, objectives, and control considerations (114+ subcontrols).
- Built on NIST CSF, ISO 27001, PCI-DSS; compliance via self-assessment and SAMA audits.
Why Organizations Use It
- Mandatory for banks, insurers, finance firms to avoid penalties, audits, fines.
- Enhances resilience, reduces incident risks, enables strategic advantages like partnerships.
- Builds trust, efficiency via metrics (KPIs/KRIs), aligns with Vision 2030 digital goals.
Implementation Overview
- Phased roadmap: gap analysis, risk assessment, control deployment, monitoring.
- Applies to all sizes of SAMA entities in Saudi Arabia; requires board oversight, CISO, documentation pyramid.
- Self-assessments, periodic SAMA reviews; no external certification but auditable maturity evidence.
Key Differences
| Aspect | PMBOK | SAMA CSF |
|---|---|---|
| Scope | Project lifecycle, processes, knowledge areas | Cybersecurity governance, risk, operations, third-party |
| Industry | All industries globally | Saudi financial sector only |
| Nature | Voluntary global standard/guide | Mandatory regulatory framework |
| Testing | Self-tailoring, no formal audits | Periodic self-assessments, SAMA audits |
| Penalties | None, professional certification impact | Fines, supervisory actions, license risks |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about PMBOK and SAMA CSF
PMBOK FAQ
SAMA CSF FAQ
You Might also be Interested in These Articles...

NIST 800-53 Private Sector ROI Uncovered: 2025 Podcast Deep Dive into Control Family Impact on $10M+ Breach Aversions
Uncover NIST 800-53 ROI in healthcare & finance: RA, SI, IR controls break even after 1-2 incidents ($100K-$10M savings). Podcast deep dive with CISO metrics fo

Using CIS Controls v8.1 as a ‘Compliance On-Ramp’: Map One Security Program to NIST CSF, ISO 27001, PCI DSS, and NIS2
Use CIS Controls v8.1 as your compliance on-ramp. Map one security program to NIST CSF, ISO 27001, PCI DSS, and NIS2 without duplicating work via practical mapp

Proving CIS Controls v8.1 Works: A KPI & Evidence Framework for Board Reporting, Audits, and Continuous Assurance
Prove CIS Controls v8.1 effectiveness with KPI catalog, evidence checklist & reporting cadence. Ideal for board reports, audits & cyber-insurance. Measure outco
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
IATF 16949 vs AS9120B
Discover IATF 16949 vs AS9120B: Automotive QMS power vs aerospace distributor precision. Unpack core tools, risk mgmt, traceability diffs. Elevate compliance now!
ISO 27017 vs ISO 30301
Compare ISO 27017 vs ISO 30301: Cloud security code vs records management system. Uncover key differences, benefits for CSPs, and choose the right standard for compliance. Boost your strategy now!
FISMA vs AS9120B
Compare FISMA vs AS9120B: Federal cybersecurity (NIST RMF) meets aerospace quality (traceability, counterfeit prevention). Master compliance, risks & strategies for secure ops. Explore now!