PofoliaShared via Pofolia

Scientific Reports· 2026Q1

RCMS: a robust cybersecurity metamodel for cloud computing in Saudi Arabia

Arafat Al-Dhaqm, Ahmad Alshammari, Abdulalem Ali, Maged Nasser et al.

Short summary

A new cybersecurity metamodel for cloud computing in Saudi Arabia, named RCMS, has been developed to address gaps in existing frameworks and align with local regulatory requirements, incorporating 17 concepts mapped to Vision 2030, NCA, and SAMA obligations.

AI-generated from the title and abstract; the full text is not read.

Key points

  • Developed RCMS, a cybersecurity metamodel tailored for cloud computing in Saudi Arabia.
  • RCMS incorporates 17 concepts covering AI security, threat detection, data protection, and authentication.
  • Concepts are mapped to Saudi Vision 2030, NCA ECC-1:2018, and SAMA Cyber Security Framework.
  • Metamodel was appraised against 13 security frameworks and 8 metamodels.

AI-generated from the title and abstract; the full text is not read.

Abstract

Abstract Cloud computing underpins Saudi Arabia’s Vision 2030, making cybersecurity an escalating national concern. Existing security frameworks incorporate relevant measures but lack cloud-specific constructs in identified areas and are not localized to Saudi regulatory requirements. This study has two objectives: to review existing cybersecurity approaches for cloud computing using the PRISMA methodology, appraising their strengths and weaknesses against a stated rubric; and to develop a high-level cybersecurity metamodel for cloud computing in Saudi Arabia, designated RCMS, through a metamodeling approach with modeling rules that include four compliance constraints expressed against NCA and SAMA obligations. RCMS defines seventeen concepts spanning AI-enhanced security, threat detection and incident response, data confidentiality and integrity, encryption, identity and device authentication, multi-cloud and critical infrastructure security, and data classification and residency. Each concept is mapped to Vision 2030 themes, NCA ECC-1:2018 controls and SAMA Cyber Security Framework domains. RCMS was appraised against thirteen security frameworks and eight security metamodels, and was instantiated for banking, healthcare and energy. The instantiations, and the accompanying threat modeling walkthrough, are illustrative and author-constructed; no measured deployment is reported. Practitioners can use RCMS to derive solution models for specific security challenges; scalability and reusability remain design intentions awaiting independent evaluation.

The authors' abstract, as published at the source. Scientific Reports, 2026 · DOI ↗

TakeawaysPremium
Ask the paperFree account

Continue with a free account

Ask the paper: 3 free questions a day about this paper; save it, get its citation, new summaries every day for your field. Takeaways are Premium.

Continue free on the web

Sign in with Google or Apple; no card needed. You come back to this paper.

On your phone:

Field: Information Systems

Information SystemsComputer Science