NCA OSMACC: Social Media Account Security Controls

A guide to NCA OSMACC-1:2021 — the 15 controls protecting official Saudi social media accounts, from MFA and dedicated devices to impersonation monitoring.

GRC Vantage TeamGRC Vantage Team2026-08-2610 min read

The Organizations' Social Media Accounts Cybersecurity Controls (OSMACC – 1: 2021) are the NCA control set that security teams most often discover they do not own. Official social media accounts usually sit with communications or marketing, are logged into from personal phones, and appear in no asset register. The NCA treats them as technology assets requiring the same discipline as any other — and it named them explicitly in the NFCRM asset-reporting duty too.

The risk the NCA is addressing is specific and, in the Kingdom, demonstrated: theft of official accounts, their misuse, and impersonation of official organisations on social platforms. A hijacked ministry account is a public-trust incident that a firewall cannot prevent.

What the OSMACC is

The OSMACC extends the Essential Cybersecurity Controls and was developed after a study of cybersecurity best practice and analysis of previous incidents and attacks, under the NCA's mandate from Royal Decree No. 6801 dated 11/2/1439H. As with every NCA extension, continuous ECC compliance is a prerequisite.

ComponentCount
Main domains3
Subdomains12
Main controls15
Subcontrols38

Appendix A records the relationship precisely: controls were added to 12 ECC subdomains and to none of the other 17.

The three domains are Cybersecurity Governance (policies and procedures, risk management, human resources, awareness and training), Cybersecurity Defense (asset management, identity and access management, information system and processing facilities protection, mobile device security, data and information protection, event logs and monitoring, incident and threat management), and Third-Party and Cloud Computing Cybersecurity.

Who is in scope

Government organisations in the Kingdom — ministries, authorities, establishments and others, and the organisations and companies related to them — plus private sector organisations that own, operate or host sensitive national infrastructure. The NCA strongly encourages all other organisations to adopt the controls.

The applicability test is simply whether you use social networks: an organisation that uses them "must adhere to all the controls applicable to it".

The account hygiene controls

Subdomain 2-2 (Identity and Access Management) contains the controls that most directly prevent the incidents the OSMACC was written for:

  • 2-2-1-1 — use social media accounts designated for organisations, not individuals.
  • 2-2-1-2 — register using official information — an official, specific social media email address and official mobile number — and not personal information.
  • 2-2-1-3verify accounts wherever possible and maintain a consistent identity across all the organisation's accounts, so official accounts are recognisable and fraudulent or unofficial ones are discoverable.
  • 2-2-1-4 — a secure, unique password per account, changed regularly, with no password reuse.
  • 2-2-1-5multi-factor authentication on all logins.
  • 2-2-1-6 — security questions activated, updated and documented in a safe place.
  • 2-2-1-7 — access rights managed on business need, considering account sensitivity, level of access and the type of devices and systems used.
  • 2-2-1-8restricting access rights of service providers for social media management, monitoring or brand protection.
  • 2-2-1-9restricting access to specific devices.
  • 2-2-2 — identities and access rights reviewed at least annually.

Registering an official account against a named employee's personal email and mobile number is the single most common failure the OSMACC is designed to eliminate. When that person leaves, the organisation's public voice leaves with them — and recovery depends on a platform support ticket rather than a control.

Controls 2-2-1-2 and 2-2-1-6 together imply an operational arrangement worth planning: an official mailbox and a controlled mobile number dedicated to account registration and recovery, plus a secure store for the security-question answers, held so that access survives staff turnover.

Dedicated devices, no classified data, no personal use

The OSMACC draws a hard line around the devices used to run official accounts:

  • 1-4-1-1 — devices dedicated to the organisation's social media accounts must be securely used and protected, and must not contain classified data or be used for personal purposes.
  • 2-5-1-1 — technology assets used to manage the accounts must not contain classified data, per relevant regulations.
  • 1-4-1-5 — the accounts must not be used for personal purposes, such as browsing.
  • 1-4-1-6 — avoid accessing official accounts from untrusted public devices or networks.
  • 2-4-1-1 — mobile devices used for the accounts must be centrally managed through an MDM.
  • 2-4-1-2 — updates and security patches applied to those devices at least monthly.

The practical implication is a dedicated, MDM-enrolled device for social media management, separated from both personal use and from the classified data estate. That is a procurement item and a policy change, and it is usually the OSMACC control with the longest lead time.

Monitoring: including for impersonation

Subdomain 2-6 asks for something most SOCs do not currently do — watching the outside of the organisation as well as the inside:

  • 2-6-1-1 — activate all notifications and cybersecurity alerts on the accounts, plus event logs on related technology assets.
  • 2-6-1-2 — follow and monitor the accounts to ensure no unauthorised content is posted and no unauthorised login occurs.
  • 2-6-1-3monitor social networks to ensure the organisation is not being impersonated.
  • 2-6-1-4automated monitoring for changes in account pattern, indicators of compromise, publication of unauthorised content, or impersonation.

Incident readiness: a recovery plan for the accounts

Subdomain 2-7 adds one control, and it is the one to action first because it costs nothing but thought:

  • 2-7-1-1 — develop a plan to recover the organisation's social media accounts and to deal with cyber incidents affecting them.

Account recovery is not an ordinary incident-response path. The organisation does not control the platform, cannot restore from backup, and depends entirely on the provider's verification process — which typically requires the registered email, the registered mobile number, and documented proof of organisational ownership. Those artefacts have to exist before the incident, which is exactly why 2-2-1-2, 2-2-1-3 and 2-2-1-6 sit where they do. Awareness control 1-4-1-3 reinforces this by requiring staff to be trained on the restoration plan.

Subdomain 2-7 also carries the standard NCA reference to Royal Decree No. 37140 dated 14/8/1438H on incident management — so a hijacked official account is an incident with an external notification dimension, not just a communications problem. See our guide to SAMA, NCA and PDPL incident notification.

Third-party services

Subdomain 3-1 covers social media management, automated monitoring and brand protection services:

  • 3-1-1 — a need assessment for using such services, along with the associated cybersecurity risks, must be conducted.
  • 3-1-2-1non-disclosure clauses and secure removal of the organisation's data by the third party on service termination.
  • 3-1-2-2communication procedures for reporting vulnerabilities and cyber incidents.
  • 3-1-2-3 — a requirement that the third party complies with the organisation's cybersecurity requirements and policies protecting the accounts, and with related laws and regulations.

Note that 3-1-1 requires the need itself to be assessed before the service is engaged — an unusual formulation that makes "do we actually need an agency with posting rights?" a documented decision rather than an assumption.

Governance and cadence

RequirementFrequencyControl
Risk assessment for social media accountsAt least annually1-2-1-1
Risk assessment before permitting a new accountAt planning, before use1-2-1-2
Risk register entry monitoredAt least annually1-2-1-3
Account and related asset inventory updateAt least annually2-1-1-1
Identity and access rights reviewAt least annually2-2-2
Patching social media applicationsAt least monthly2-3-1-1
Patching mobile devicesAt least monthly2-4-1-2
Configuration and hardening reviewAt least annually2-3-1-2

Control 1-2-1-2 is the governance hook that stops the problem recurring: a cybersecurity risk assessment must happen during planning and before use of a new account is permitted. Account creation becomes a gated process rather than something a campaign team does on a Thursday.

How the NCA assesses compliance

The NCA evaluates OSMACC compliance through self-assessments and/or on-site audits, by the mechanisms it considers appropriate. Compliance is mandated under item 3 of article 10 of the NCA's mandate, and cannot be achieved without continuous ECC compliance where applicable.

An OSMACC readiness sequence

  1. Inventory every official account — including dormant ones, regional ones, and accounts opened for a single campaign. Add them to the asset register (2-1-1-1), which also feeds the NFCRM asset report to the NCA.
  2. Re-register accounts to organisational identities. Official mailbox, official mobile number, organisational ownership. This is the recovery path.
  3. Turn on MFA and remove password reuse, then store security-question answers in the organisation's secrets management.
  4. Provision dedicated, MDM-enrolled devices with no classified data and no personal use.
  5. Write the account recovery plan and rehearse it, including the platform's verification process and who holds the evidence of ownership.
  6. Stand up impersonation monitoring — and if that means a third-party service, run the need assessment and restrict its access rights first.
  7. Gate new accounts behind a risk assessment at planning stage.

How GRC Vantage supports OSMACC compliance

GRC Vantage's compliance module carries the OSMACC library mapped to its ECC parents, and treats social media accounts as first-class assets in the register — so they appear in the NFCRM asset report to the NCA rather than being remembered separately. Each account records its registration identity, its verification status, the devices authorised to access it and the last access review, which is the evidence set an on-site audit asks for.

New-account requests run through the 1-2-1-2 risk assessment as a workflow gate, and the recovery plan under 2-7-1-1 sits with the incident management playbooks so it is exercised alongside the rest of the response capability. Social media management and brand-protection providers are held in the vendor workflow with their restricted access rights and termination data-removal commitments tracked against the contract.

For the full family, see the NCA frameworks pillar guide. To scope an OSMACC assessment, talk to our team.

Want to see this in the platform?

Book a demo with the GRC Vantage team in Riyadh or Dammam.

See Compliance Management

Frequently asked questions

What is the NCA OSMACC?

The Organizations' Social Media Accounts Cybersecurity Controls (OSMACC – 1: 2021) are the NCA's minimum cybersecurity requirements for organisations using social networks officially. They comprise 3 main domains, 12 subdomains, 15 main controls and 38 subcontrols, and extend the Essential Cybersecurity Controls, which are a prerequisite.

Who must comply with OSMACC?

Government organisations in the Kingdom — ministries, authorities, establishments and others, and organisations and companies related to them — plus private sector organisations that own, operate or host sensitive national infrastructure. Any in-scope organisation that uses social networks must comply with all applicable controls.

Can staff run official accounts from personal phones?

No. Control 1-4-1-1 requires devices dedicated to the organisation's accounts to be protected and not used for personal purposes, 2-4-1-1 requires those mobile devices to be centrally managed through an MDM, and 2-2-1-9 restricts account access to specific devices.

Does OSMACC require monitoring for impersonation?

Yes. Subcontrol 2-6-1-3 requires monitoring social networks to ensure the organisation is not being impersonated, and 2-6-1-4 requires automated monitoring for changes in account pattern, indicators of compromise, unauthorised content and impersonation.

What does OSMACC require if an official account is hijacked?

Subcontrol 2-7-1-1 requires a plan to recover the organisation's social media accounts and to deal with cyber incidents affecting them, with staff trained on it under 1-4-1-3. The recovery path depends on the account having been registered with official organisational details under 2-2-1-2 and verified under 2-2-1-3.


Sources & References
Primary regulatory documents, international standards and guidance cited in this article
GRC Vantage Team
GRC Vantage Team
Saudi GRC Practitioners

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.