Terminology

Personal Data: Every statement - whatever its source or form - can lead to the specific knowledge of an individual, or make them identifiable directly or indirectly when combined with other data, including, but not limited to, name, personal identification numbers, addresses, contact numbers, bank account and credit card numbers, static or moving images of the user, and other personal data.Data: A set of facts in their raw form or in an unorganized form such as numbers, letters, static images, videos, audio recordings, or emojis.Access to data: The ability to access logical and physical data and technical resources of the University for their use.Authentication: Confirming the identity of any user or process as a fundamental requirement to allow access to technical resources.Protected data: Data classified as (highly secret, secret, restricted)General Information: Data after processing (unprotected) that the University receives, produces, or deals with, regardless of its source, form, or nature.Data classification levels: Data classification levels as displayed in the data classification policy by the National Data Management Office are as follows: Highly Secret, Secret, Restricted, PublicData representative: is the person responsible for the data collected and maintained in business departments of the university.Security Controls: Devices and procedures and policies and physical guarantees used to ensure the safety of data and protect it and protect processing media and access to it.Data Disclosure: Enabling anyone – other than the University – to obtain personal data or use it or view it in any way for any purpose.User Data: Employee who deals with or accesses data, uses it, or updates it for the purpose of performing a task authorized by the university's authority.

goal policy

The purpose of this policy is:

  • Organizing the classification and protection of data at Najran University according to best global practices and in accordance with the instructions received from relevant authorities.
Organizing the process of using/reusing protected data and publishing general information.Specify the roles and responsibilities required from all parties at the university to ensure the optimal application of data classification.

scope of policy

These rules apply to all data that the University receives, generates, or handles, regardless of its source, form, or nature, including paper records, meetings, communications through social media and applications, emails, data stored on electronic media, audio or video tapes, maps, photographs, manuscripts, handwritten documents, or any other form of information.

Roles and Responsibilities

The Party

The Roles and Responsibilities

The Permanent Supreme Committee for Data Management and Governance

  • Approval of the Policy
  • The timeline plan for university data classification has been approved.
  • Address any difficulties or challenges that impede the data classification process.

    The Permanent Committee for Data Quality and Decision Support

  • Supervision of the University’s data ranking process in accordance with applicable systems, regulations, and ordinances, while enhancing secure access methods.
  • Proposed Solutions for Improving Data Classification Procedures.The recommendation is to escalate to the Permanent High Committee for Data Management and Governance when necessary.

    Data Management Office

  • Review the data classification policy periodically.
  • Proposal for the formation of subcommittees - in accordance with what requires the interest of work to complete the related data classification tasks and raise them for approval by the authorized party.Following up on the work of specialized committees responsible for data classification to ensure that all university data is classified by representatives from private businesses.
  • Proposal regarding procedural evidence for data classification and recommendation for its adoption by the Permanent Supreme Committee for Data Management and Governance.Follow up on periodic reports for subcommittees related to data classification. Ensure that the security standards used when exchanging data between internal and external entities of the university are verified.
  • Raise awareness among university staff (faculty members and employees) about the importance of data governance, its classification methods, exchange, dissemination, and publishing.
  • Business Departments (and all colleges and units in the University)

    The business departments at the University implement the University-approved data classification policy, which includes:
    • This encompasses the inventory and classification of all data assets (including all incoming paper transactions to the entity within the university that have not been registered in any of the university’s systems).
    • The agent representative should be fully informed on the nature of the administrative unit's data.Data classification review and approval of business administration levels.Data classification within the entity based on what is stated in this policy.

    Business Data Representative

    Each business administration assigns a data representative to perform the following tasks:

    • Data Classification: Classify the data collected by the entity and its affiliated units and offices.
  • Data aggregation: Ensuring that data classified from multiple sources is categorized at the highest classification levels used when classifying data individually. Collection of data: Confirming the classification of data collected from multiple sources at the highest classification levels used in classifying data individually.
  • ? Data classification formatting: Ensuring that exchange data is classified and protected in a coordinated manner.
  • ? Compliance with Data Classification (in coordination with Business Data Specialists): Ensuring that data is protected according to the specified controls.
  • Deanship of Digital Transformation - Knowledge Sources

    • Applying the controls to data according to the classifications approved by the Data Management Office.
  • Technical and Information Support for Business Departments, which includes, but is not limited to:
    • Database access for electronic systems at the University.Providing and updating metadata for databases for university electronic systems based on the approved models from the Data Management Office and sharing them with concerned organizational units.
    • Applying the necessary security and protection to electronic data in the university based on its classification.Report to the Cyber Security Administration and the Data Office about any violations observed that pose a threat to data security.
    • Perform regular data backups.Data recovery from backup media when needed.
  • Business Data Specific

    The Digital Transformation Deanship and the Knowledge Sources Administration, along with Cyber Security Management, under an authorization to carry out the following tasks:
  • Ensure that access control measures are applied and monitored, and reviewed in accordance with the data classification levels defined by the business data representative.Preparing periodic reports on the quality, integrity, confidentiality, and sharing of classified data with related departments.In compliance with data classification (in collaboration with data officers).Ensure the classification of data belonging to the entity and its protection, in accordance with the specified controls within this policy.
  • Cybersecurity Administration

    • Supervision and monitoring of data implementation according to the approved classification, ensuring alignment with policies and controls issued by the National Cybersecurity Authority.
    • Coordinate with the Financial Administration to provide the necessary software to detect and protect data leaks.
    • Monitoring of activities performed on data, recording them, including data related to the person accessing this data and periodic sharing with the Data Management Office to ensure compliance with the operation of this policy.

      Governance and Risk Management and Business Continuity

    • Review of compliance reports with the data classification policy and methods for preserving this data, as well as identifying the consequences of non-compliance with necessary security procedures to protect data and sharing these reports with the University Data Management Office.

    Internal Audit Department

    • Tracking the availability of reports on compliance with data classification policy by business departments in the university according to the schedule for implementing this policy.

    Data User

    • The user of the data is committed to complying with this policy and all policies related to the use of data in the Kingdom of Saudi Arabia.

    Data classification principles

    The first principle: Data availability

    The basis for data is that it should be available (in the developmental field) unless its nature or sensitivity requires higher levels of classification and protection, and extreme secrecy (in the political and security fields) unless its nature or sensitivity requires lower levels of classification and protection.

    The Second Principle: Necessity and Proportionality

    Data is classified into levels according to its nature, sensitivity level, and impact degree, taking into consideration the balance between its value and its level of secrecy.

    Third Principle: Classification at the Appropriate Time

    Data is classified upon its creation or receipt from other entities, and the classification occurs within a defined time period.

    The Fourth Principle: Higher Level of Protection

    A higher level of classification is adopted when the content includes a comprehensive set of data with different classification levels.

    The Fifth Principle: Separation of Duties

    Tasks and responsibilities of employees – with regard to the classification, access, disclosure, use, modification, or destruction of data – are separated in a way that prevents overlap of duties and avoids diffusion of responsibility.

    The Sixth Principle: The Need for Knowledge

    Access to data and its use are restricted based on actual need for knowledge, and for the minimum number of employees.

    The seventh principle: Least privilege

    The granting of employee authorities is at least restricted to the privileges necessary for performing the tasks and responsibilities assigned to them.

    Data classification levels

    Classification Level

    Impact Rating

    Highly confidential

    High

    Description

    The data is classified as highly confidential if access to it or disclosure of its content or material thereof results in grave and exceptional damage that cannot be remedied or compensated for on:

    • Including national interests, including breaches of agreements and treaties, or damage to the Kingdom's reputation or diplomatic relations and political affiliations, operational efficiency of security or military operations or the national economy or the national infrastructure or government activities.
  • The performance of public bodies causing harm to national interests.
  • The health and safety of individuals and a wide range of privacy for senior officialsThe resources are the environment or nature.Level of Ranking

    Impact Rating

    Secret

    Secondary

    Description

    The data is classified as confidential data if unauthorized access to it or disclosure of its content or elements leads to serious harm to:
    • National interests such as causing partial damage to the Kingdom's reputation or diplomatic relations and/or operational efficiency of national security, military or economic operations, or national infrastructure or government activities.
    • Financial losses at the organizational level leading to the bankruptcy or inability of entities to perform their tasks or significant loss of competitive capabilities or both
    • It causes serious harm or injury that affects the lives of a group of individuals.
    • This can cause long-term damage to environmental or natural resources.
    • Investigation of major issues specified by law, such as the financing of terrorism.
    • Ranking Level

      Impact Rating

      Restricted

      Low

      Description

      Data is classified as “restricted” if unauthorized access to this data or disclosure of it or its content would lead to:
      • Specific limited negative impact on the work of public authorities and economic activities in the Kingdom, as well as on the work of a specific individual.
      • Limited damage to nearby environmental or natural resources.

        Level of Classification

        Impact Rating

        Year

        There is no

        Description

        Classified as “public data” when access to it, disclosure of its content, or its contents do not result in any of the aforementioned effects in the event of no impact on the following:

        • The National Interest.
      • Activities of the bodies.
      • Individual interests.
      • Environmental Resources.
      • The classified data can be categorized into sub-levels based on the scope of impact as follows:
        • Restricted - Level ( : If the scope of impact is at a sector level or for a general economic activity.
        • Restricted - Level (in the scope of activities of multiple parties or interests of a group of individuals).Restricted – Level (j): If the scope of impact is at the level of activities of a single entity or the interests of a specific individual.And in the table below, there is clarification and determination of the correct classification level that the university can assess the impact resulting from unauthorized access to data or disclosure thereof or its content. For more information about the assessment process, you can refer to the necessary steps to classify the data. The university must conduct an impact assessment related to unauthorized access or disclosure processes. This list is not comprehensive.

  • Categories and Impact Rating Levels according to Data Classification Levels

    Restricted

    Data Classification Levels

    Highly confidential

    Year

    Main Impact Category, Sub-Impact Category, Considerations

    Level of Impact

    High

    Medium

    Low

    لا يوجد

    المصلحة الوطنية

    سمعة المملكة

    هل ستخضع المعلومات لاهتمام وسائل الإعلام المحلية أو الدولية؟ هل ستعطي انطباع سلبي؟

    تتأثر السمعة بشكل كبير

    تتأثر السمعة إلى حد ما

    لا تتأثر السمعة

    لا يوجد تأثير على المصالح الحيوية الوطنية

    العلاقات الدبلوماسية

    هل تُشكّل المعلومات خطرًا على العلاقات مع الدول الصديقة؟ هل ستزيد من حدة التوتر الدولي؟ هل يمكن أن تؤدي إلى احتجاجات أو عقوبات من دول أخرى؟

    قطع العلاقات الدبلوماسية والانتماءات السياسية أو تهديد الاتفاقيات وشروط المعاهدات أو كليهما

    تتأثر العلاقات الدبلوماسية سلبًا على المدى الطويل

    لن يحدث تأثير على العلاقات الدبلوماسية أو يحدث تأثير بسيط على المدى القصير

    مستويات تصنيف البيانات

    سري للغاية

    سري

    مقيد

    عام

    فئة الأثر الرئيسية ، فئة الأثر الفرعية، الاعتبارات

    مستوى الأثر

    عالي

    متوسط

    منخفض

    لا يوجد

    المصلحة الوطنية

    الأمن الوطني / النظام العام

    هل المعلومات - في حال نشرها - تساعد على تنظيم أعمال إرهابية أو ارتكاب جرائم خطيرة؟ هل تُشكل مصدر ذعر للجميع؟

    تتأثر الكفاءة التشغيلية للأمن العام أو العمليات الاستخباراتية للقوات العسكرية بشكل كبير

    تأثير طويل المدى على قدرة وكفاءة الجهات الأمنية بالتحقيق والترافع في الجرائم المنظمة الخطيرة التي تسبب عدم الاستقرار الداخلي

    تأثير لا يُذكر على الكفاءة التشغيلية للعمليات الأمنية على مستوي إقليمي أو محلي، والحيلولة دون اكتشاف الجرائم البسيطة على المدى القصير

    لا يوجد تأثير على المصالح الحيوية الوطنية

    الاقتصاد الوطني

    هل يؤدي الكشف عن المعلومات إلى خسائر اقتصادية على المستوى الوطني؟

    تأثير طويل المدى على الاقتصاد الوطني مع انخفاض لا يُمكن تداركه في الناتج المحلي الإجمالي أو أسعار الأسواق المالية أو نسبة البطالة أو القوة الشرائية أو المؤشرات الأخرى ذات الصلة مما ينعكس سلباً على جميع القطاعات في المملكة

    تأثير طويل المدى على الاقتصاد الوطني مع انخفاض يُمكن تداركه في الناتج المحلي الإجمالي ونسبة البطالة أو أسعار الأسواق المالية أو القوة الشرائية، مما ينعكس سلباً على قطاع واحد أو أكثر

    تأثير بسيط على الاقتصاد الوطني مع انخفاض يُمكن تداركه في وقت قصير في الناتج المحلي الإجمالي، ومعدل العمالة أو أسعار الأسواق المالية أو القوة الشرائية، مما ينعكس سلباً على قطاع واحد فقط

    البنى التحتية الوطنية

    هل الوصول إلى المعلومات يؤدي إلى تعطيل البنى التحتية الحيوية الوطنية مثل الطاقة، النقل، الاتصالات؟ في حال التعرض لهجمات إلكترونية، هل ستظل الخدمات الأساسية بالمملكة متاحة؟

    التوقف والتعطل في أمن وعمليات البنى التحتية الوطنية الحيوية، كما تتأثر العديد من القطاعات وتتعطل الحياة الطبيعية

    التوقف والتعطل -لفترة قصيرة - في أمن وعمليات البنى التحتية الوطنية الحيوية، كما يتأثر قطاع واحد أو أكثر

    لا يحدث ضرر أو تأثير قصير المدى على أمن وعمليات البنى التحتية المحلية / الإقليمية

    مهام الجهات الحكومية

    هل الكشف عنها سيودي  إلى الحد من إمكانية الجهات الحكومية من تنفيذ عملياتها ومهامها اليومية؟

    عدم قدرة جميع الجهات الحكومية من أداء مهامها وعملياتها الرئيسية لفترة طويلة

    عدم قدرة جهة حكومية واحدة أو أكثر على أداء واحدة أو أكثر من مهامها الرئيسية لفترة قصيرة

    عدم قدرة جهة حكومية أو أكثر من أداء مهمة واحدة أو أكثر من المهام غير الرئيسية لفترة قصيرة

    الجامعة وفروعها

    أعمال وخدمات الجامعة

    هل سيؤدي الكشف عن المعلومات إلى الحد من إمكانية الوحدات التنظيمية في الجامعة من تنفيذ عملياتها ومهامها اليومية؟

    عدم قدرة جميع الوحدات التنظيمية في الجامعة من أداء مهامها وعملياتها الرئيسية

    عدم قدرة أكثر من وحدة تنظيمية واحدة )مثال الجامعة ، فرع محدد، الخ.( على أداء واحدة أو أكثر من مهامها الرئيسية

    عدم قدرة وحدة تنظيمية واحدة )مثال الجامعة ، فرع محدد، الخ.( على أداء واحدة أو أكثر من مهامها الرئيسية

    لا يوجد تأثير على أنشطة الجامعة وفروعها

    البنى التحتية للجامعة

    هل الوصول إلى المعلومات يؤدي إلى تعطيل البنى التحتية الحيوية للجامعة) مثل تقنية المعلومات، الخ. في حال التعرض لهجمات إلكترونية، هل ستظل الخدمات الأساسية في الجامعة متاحة؟

    التوقف والتعطل في أمن وعمليات البنى التحتية في وحدة تنظيمية أو فرع أو أكثر، مما يؤدي الى تعطل الحياة الطبيعية

    التوقف والتعطل الجزئي في أمن وعمليات البنى التحتية في وحدة تنظيمية أو فرع أو أكثر

    يحدث ضرر أو تأثير بسيط على أمن وعمليات البنى التحتية للجامعة

    الخسائر المادية

    هل يؤدي الكشف عن المعلومات إلى خسائر مادية على مستوى الجامعة

    تأثير على الجامعة مع انخفاض لا يُمكن تداركه في الأصول او الدخل أو المؤشرات المالية الأخرى ذات الصلة

    تأثير على الجامعة مع انخفاض يُمكن تداركه في أصول أو مداخيل الجامعة المؤشرات المالية الأخرى ذات الصلة

    تأثير بسيط على الجامعة مع انخفاض يُمكن تداركه في وقت قصير في أصول أو مداخيل الجامعة أو المؤشرات المالية الأخرى ذات الصلة

    أنشطة  الجهات الأخرى

    أرباح الجهات الخاصة

    هل سيؤدي الكشف عن المعلومات إلى خسائر مالية أو إفلاس الجهات الخاصة التي تقوم بإدارة مرافق العامة؟ على سبيل المثال، احتمالية الاحتيال، وتحويلات الأموال غير القانونية، والمصادرة غير القانونية للأصول.

    تأثير سلبي كبير على الجهات الخاصة إلى الحد الذي يتسبب في الإضرار بالمصالح الحيوية الوطنية

    تكبد خسائر مالية فادحة مما قد يؤدي إلى الإفلاس

    ضرر محدود يتمثل في خسارة مالية محدودة للجهة أو لأيٍ من أصولها

    لا يوجد تأثير على أنشطة الجهات

    مهام الجهات الخاصة

    هل الكشف عنها سيؤدي إلى حدوث أضرار على الجهات الخاصة التي تقوم بإدارة المرافق العامة؟ هل سيؤدي ذلك إلى فقدان الدور الريادي أو خسارة أيٍ من الأصول؟

    عدم امكانية القيام بالمهام الرئيسية، وفقدان القدرة على التنافسية إلى حد كبير

    عدم امكانية أداء إحدى المهام الرئيسة، وفقدان القدرة على التنافسية بشكل محدود

    مستويات تصنيف البيانات

    سري للغاية

    سري

    مقيد

    عام

    فئة الأثر الرئيسية ، فئة الأثر الفرعية، الاعتبارات

    مستوى الأثر

    عالي

    متوسط

    منخفض

    لا يوجد

    الأفراد

    صحة /  سلامة الأفراد

    هل سيؤدي الكشف عن المعلومات إلى إفشاء أسماء أو مواقع أشخاص وما إلى ذلك؟ )على سبيل المثال، اسماء ومواقع العملاء السريين، والأشخاص الخاضعين لأنظمة حماية خاصة)

    خسارة عامة أو فادحة في الأرواح؛ فقدان حياة فرد أو مجموعة من الأفراد

    ضرر جسيم أو إصابة تهدد حياة الفرد

    إصابة بسيطة دون أي خطر يهدد حياة أو صحة الفرد

    لا يوجد تأثير على الأفراد

    الخصوصية

    هل سيؤدي الكشف عن المعلومات إلى انتهاك خصوصية الأفراد؟ هل سيؤدي ذلك إلى انتهاك أي حقوق ملكية فكرية؟

    الكشف عن البيانات الشخصية لشخصية مهمة مما يؤثر على المصلحة الوطنية

    الكشف عن البيانات الشخصية لشخصية مهمة

    الكشف عن البيانات الشخصية لفرد

    البيئة

    الموارد البيئية

    هل سيتم اُستخدم هذه المعلومات لتطوير خدمة أو منتج يمكن أن يؤدي إلى تدمير الموارد البيئية أو الطبيعية للمملكة؟

    تأثير كارثي لا يمكن تداركه على البيئة أو الموارد الطبيعية

    تأثير طويل المدى على البيئة أو الموارد الطبيعية

    تأثير قصير المدى أو محدودة على البيئة أو الموارد الطبيعية

    لا يوجد تأثير على البيئة

    Data classification guidelines

    • All unclassified data must be classified within a specified period according to an action plan prepared by the Data Management Office of the University and approved by the University President or his designee
    Unclassified data when created or received is treated as “restricted” until classified.Based on classification levels, appropriate security controls are determined and applied to protect data, to ensure its handling, processing, sharing, and disposal securely.Update security systems periodically to monitor classified data storage devices “highly secret,” “secret,” and “restricted,” to ensure the protection of this data from unauthorized access.
  • Data classified as "Highly Confidential", "Confidential", and "Restricted" must be protected when stored physically or electronically using approved methods from the National Cybersecurity Authority.

  • steps data classification

    1. تعيين ممثلي الأعمال:

    يتم بقرار من سعادة رئيس الجامعة أو من يفوضه اصدار قرار يحدد ممثلي بيانات الاعمال بمختلف الوحدات الإدارية بالجامعة بناء على ما يرفع من المشرف العام على مكتب البيانات/مدير مكتب البيانات.

    1. حصر بيانات الجامعة:
    • يتم حصر جميع البيانات التي تمتلكها الجامعة من خلال ممثلي بيانات الأعمال ومن خلال الجهات المشاركة مع الجامعة في تحديد وتوثيق بياناتها التي تمتلكها ويمكن تحديد مصادر البيانات بالجامعة كالتالي:

    مصادر بيانات داخلية

    تشمل إدارات الأعمال والنظم الداخلية التي تولد البيانات للجامعة من خلال تنفيذ إجراءات وخدمات العمل وتشمل المصادر على سبيل المثال لا الحصر: النسخ الورقية أو الرقمية للتقارير التي تعمل عليها الإدارات الداخلية أو البيانات المعرفة من خلال الأنظمة المستخدمة.

    مصادر بيانات خارجية

    تشمل الجهات الخارجية التي تقدم البيانات المتفق عليها للجامعة لتنفيذ إجراءات وخدمات العمل وتشمل هذه المصادر على سبيل المثال لا الحصر: مقدمي بيانات الطلاب، الجهات الحكومية ذات العلاقة والهيئات الرقابة الأخرى.








     

    • يتم تحديد قنوات تبادل البيانات والتي تشمل القنوات الآلية والقنوات اليدوية. حيث تشمل القنوات الآلية كافة القنوات الآلية وشبه الآلية مثل رسائل البريد الإلكتروني والرسائل القصيرة وغيرها من القنوات الخاصة بالأنظمة الالكترونية. بينما تشمل القنوات اليدوية جميع القنوات غير التقنية مثل الأقراص المدمجة ووحدات التخزين USB والأقراص الصلبة الخارجية والوثائق الورقية.
    1. إجراء عملية تقييم الأثر:

    يجب على ممثل بيانات الأعمال اتباع الخطوات اللازمة لعملية تقييم الأثر المحتمل الذي يترتب على:

    • الإفصاح عن هذه البيانات أو الوصول غير المصرح به لها.
    • إجراء تعديل على هذه البيانات أو إتلافها أو كليهما.
    • عدم الوصول إلى هذه البيانات في الوقت المناسب.

    تبدأ عملية تقييم الأثر بتطبيق مبدأ "الأصل في البيانات الاتاحة" (في المجال التنموي) مالم تقتض طبيعتها أو حساسيتها مستويات أعلى من التصنيف والحماية وسرية للغاية (في المجال السياسي والأمني) مالم تقتض طبيعتها أو حساسيتها مستويات أدني من التصنيف. يتمثل العنصر الأول من عملية تقييم الأثر في تحديد الفئة الرئيسية والفرعية للأثر المحتمل في أي من الفئات الرئيسية التالية:

    • المصلحة الوطنية
    • أنشطة الجهات
    • صحة أو سلامة الأفراد
    • الموارد البيئية
    1. تحديد مستوى الأثر:

    يتعين على ممثل بيانات الأعمال أن يحدد لكل أثر محتمل مستوى معين يعتمد تحديد المستوى على الآتي:

    • مدة الأثر وصعوبة السيطرة على الضرر.
    • فترة تدارك وإصلاح الأضرار بعد وقوعها.
    • حجم الأثر على مستوى وطني، مناطقي، عدة جهات، جهة واحدة، عدة أفراد .... الخ .
    • كما يمكن تحديد مستوى الأثر من خلال المعايير أدناه:
    • عالي يؤدي الوصول الى البيانات أو الإفصاح عنها إلى حدوث أضرار جسيمة أو خطيرة للغاية على المدى الطويل لا يمكن تداركها أو إصلاحها.
    • متوسط يؤدي الوصول إلى البيانات أو الإفصاح عنها إلى حدوث أضرار جسيمة أو خطيرة يصعب السيطرة عليها.
    • منخفض يؤدي الوصول إلى البيانات أو الإفصاح عنها إلى أضرار محدودة يمكن السيطرة عليها أو أضرار متقطعة على المدى القصير يمكن السيطرة عليها.
    • لا يوجد أثر، لا يؤدي الوصول إلى البيانات أو الإفصاح عنها إلى اي ضرر على المدى الطويل أو القصير.
    • يجب ان تكون جميع الاضرار المحتملة والمحددة خلال عملية تقييم الأثر محددة وقائمة على أدلة، في محاولة للحد من التقديرات الشخصية للمكلف بإجراء تصنيف البيانات. يحدد ممثل بيانات الاعمال مستوى تصنيف البيانات بناءً على الأثار المحددة ومستوياتها:
    • عالي، تصنف البيانات باعتبارها "سرية للغاية".
    • متوسط، تصنف البيانات على انها "سرية".
    • منخفض، يلزم إجراء المزيد من التقييمات (من خلال القيام بالخطوات 5، 6)
    • لا يوجد أثر، تصنف البيانات على أنّها بيانات "عامة".
    1. تحديد الأنظمة ذات العلاقة (فقط إذا كان مستوى الأثر منخفض):

    يجب إجراء تقييمات إضافية إذا كان مستوى الأثر المحدد “منخفض" وذلك بهدف زيادة مستوى تصنيف البيانات المصنفة على أنها بيانات “عامة" إلى الحد الأقصى. يجب على ممثل بيانات الأعمال في هذا الصدد، دراسة ما إذا كان الإفصاح عن هذه البيانات يتعارض مع أنظمة المملكة العربية السعودية مثل نظام مكافحة الجرائم المعلوماتية ونظام التجارة الإلكترونية ... الخ وإذا كان الإفصاح عن البيانات مخالفاً للأنظمة، فيجب حينها تصنيف البيانات على أنها بيانات “مقيّدة"، بخلاف ذلك يتعين على ممثل بيانات الأعمال مواصلة تنفيذ الخطوة 5.

    1. الموازنة بين مزايا الإفصاح عن البيانات والآثار السلبية (فقط إذا كانت الإجابة على الخطوة 5 “لا"):

    بعد التأكد من مستوى الأثر المنخفض وضمان أن الإفصاح لن يكون انتهاكاً لأي نظام نافذ، يجب أيضاً تقييم المزايا المحتملة للإفصاح عن مثل هذه البيانات والتأكد مما إذا كانت هذه المزايا ستفوق الآثار السلبية أم لا، وتشمل المزايا المحتملة استخدام البيانات لتطوير خدمات جديدة ذات قيمة مضافة، أو زيادة شفافية العمليات الحكومية أو زيادة مشاركة الأفراد مع الحكومة. وعليه:

    • إذا كانت المزايا أكبر من الآثار السلبية، تصنف البيانات على أنها "عامة".
    • إذا كانت المزايا أقل من الآثار السلبية، تصنف البيانات على أنها "مقيّدة".
    1. مراجعة مستوى التصنيف:

    يجب أن يفحص مراجع تصنيف البيانات -أحد منسوبي مكتب إدارة البيانات بالجامعة- جميع البيانات المصنفة لضمان أن يكون مستوى التصنيف المحدد من جانب ممثل بيانات الأعمال هو الأنسب، وتتم مراجعته خلال شهر واحد من التصنيف الأولي.

    1. تطبيق الضوابط المناسبة:

    تتمثل الخطوة الأخيرة من عملية تصنيف البيانات في حماية جميع البيانات وفقاً لمستوى التصنيف عن طريق تعميم نتائج التصنيف وتطبيق ضوابط تصنيف البيانات. بحيث يتم الانتهاء من عملية التصنيف عند تصنيف جميع البيانات التي تملكها الجامعة والتحقق من مستويات التصنيف وتطبيق الضوابط ذات الصلة.