Data Classification Policy
Personal Data: Every statement - whatever its source or form - can lead to the specific knowledge of an individual, or make them identifiable directly or indirectly when combined with other data, including, but not limited to, name, personal identification numbers, addresses, contact numbers, bank account and credit card numbers, static or moving images of the user, and other personal data.Data: A set of facts in their raw form or in an unorganized form such as numbers, letters, static images, videos, audio recordings, or emojis.Access to data: The ability to access logical and physical data and technical resources of the University for their use.Authentication: Confirming the identity of any user or process as a fundamental requirement to allow access to technical resources.Protected data: Data classified as (highly secret, secret, restricted)General Information: Data after processing (unprotected) that the University receives, produces, or deals with, regardless of its source, form, or nature.Data classification levels: Data classification levels as displayed in the data classification policy by the National Data Management Office are as follows: Highly Secret, Secret, Restricted, PublicData representative: is the person responsible for the data collected and maintained in business departments of the university.Security Controls: Devices and procedures and policies and physical guarantees used to ensure the safety of data and protect it and protect processing media and access to it.Data Disclosure: Enabling anyone – other than the University – to obtain personal data or use it or view it in any way for any purpose.User Data: Employee who deals with or accesses data, uses it, or updates it for the purpose of performing a task authorized by the university's authority.
The purpose of this policy is:
- Organizing the classification and protection of data at Najran University according to best global practices and in accordance with the instructions received from relevant authorities.
These rules apply to all data that the University receives, generates, or handles, regardless of its source, form, or nature, including paper records, meetings, communications through social media and applications, emails, data stored on electronic media, audio or video tapes, maps, photographs, manuscripts, handwritten documents, or any other form of information.
|
The Party |
The Roles and Responsibilities |
The Permanent Supreme Committee for Data Management and Governance
|
|||
|
Business Data Representative |
Each business administration assigns a data representative to perform the following tasks:
|
Deanship of Digital Transformation - Knowledge Sources
|
Business Data Specific The Digital Transformation Deanship and the Knowledge Sources Administration, along with Cyber Security Management, under an authorization to carry out the following tasks: |
Cybersecurity Administration |
|
|
|
Data User
|
The first principle: Data availability
The basis for data is that it should be available (in the developmental field) unless its nature or sensitivity requires higher levels of classification and protection, and extreme secrecy (in the political and security fields) unless its nature or sensitivity requires lower levels of classification and protection.The Second Principle: Necessity and Proportionality
Data is classified into levels according to its nature, sensitivity level, and impact degree, taking into consideration the balance between its value and its level of secrecy.Third Principle: Classification at the Appropriate Time
Data is classified upon its creation or receipt from other entities, and the classification occurs within a defined time period.The Fourth Principle: Higher Level of Protection
A higher level of classification is adopted when the content includes a comprehensive set of data with different classification levels.The Fifth Principle: Separation of Duties
Tasks and responsibilities of employees – with regard to the classification, access, disclosure, use, modification, or destruction of data – are separated in a way that prevents overlap of duties and avoids diffusion of responsibility.The Sixth Principle: The Need for Knowledge
Access to data and its use are restricted based on actual need for knowledge, and for the minimum number of employees.The seventh principle: Least privilege
The granting of employee authorities is at least restricted to the privileges necessary for performing the tasks and responsibilities assigned to them.
|
Classification Level |
Impact Rating
Highly confidential
High
Description
The data is classified as highly confidential if access to it or disclosure of its content or material thereof results in grave and exceptional damage that cannot be remedied or compensated for on:
- Including national interests, including breaches of agreements and treaties, or damage to the Kingdom's reputation or diplomatic relations and political affiliations, operational efficiency of security or military operations or the national economy or the national infrastructure or government activities.
Impact Rating
Secret
Secondary
Description
The data is classified as confidential data if unauthorized access to it or disclosure of its content or elements leads to serious harm to:- National interests such as causing partial damage to the Kingdom's reputation or diplomatic relations and/or operational efficiency of national security, military or economic operations, or national infrastructure or government activities.
- Financial losses at the organizational level leading to the bankruptcy or inability of entities to perform their tasks or significant loss of competitive capabilities or both
- It causes serious harm or injury that affects the lives of a group of individuals.
- This can cause long-term damage to environmental or natural resources.
- Investigation of major issues specified by law, such as the financing of terrorism.
- Specific limited negative impact on the work of public authorities and economic activities in the Kingdom, as well as on the work of a specific individual. Limited damage to nearby environmental or natural resources.
- The National Interest.
- Activities of the bodies.
- Individual interests.
- Environmental Resources.
- Restricted - Level ( : If the scope of impact is at a sector level or for a general economic activity. Restricted - Level (in the scope of activities of multiple parties or interests of a group of individuals).Restricted – Level (j): If the scope of impact is at the level of activities of a single entity or the interests of a specific individual.And in the table below, there is clarification and determination of the correct classification level that the university can assess the impact resulting from unauthorized access to data or disclosure thereof or its content. For more information about the assessment process, you can refer to the necessary steps to classify the data. The university must conduct an impact assessment related to unauthorized access or disclosure processes. This list is not comprehensive.
Ranking Level
Impact Rating
Restricted
Low
Description
Data is classified as “restricted” if unauthorized access to this data or disclosure of it or its content would lead to:Level of Classification
Impact Rating
Year
There is no
Description
Classified as “public data” when access to it, disclosure of its content, or its contents do not result in any of the aforementioned effects in the event of no impact on the following:
The classified data can be categorized into sub-levels based on the scope of impact as follows:
Restricted
|
|
Data Classification Levels |
||||||||||
|
|
Highly confidential |
Year |
Main Impact Category, Sub-Impact Category, Considerations |
Level of Impact |
|||||||
|
High |
|||||||||||
|
Medium |
Low No available | ||||||||||
|
National Interest |
The Kingdom's Reputation Will the information be of interest to local or international media outlets? Will it give a negative impression? |
Reputation is significantly affected |
|
|
No impact on vital national interests |
Diplomatic Relations Could the information pose a threat to relations with friendly countries? Will it increase international tensions? Could it lead to protests or sanctions from other countries? |
|
|
|
||
Restricted
Year
|
|
Data Classification Levels |
|||||||||||||||||||||||||||||||||
|
|
|
Secret |
Main Impact Category, Sub-Impact Category, Considerations Level of Impact |
High |
Medium |
Low No available |
National Interest |
National Security / Public Order |
|
|
Long-term impact on the ability and efficiency of security authorities in investigating and prosecuting serious organized crimes that cause internal instability |
|
There is no impact on vital national interests |
National Economy Would revealing information lead to economic losses at the national level? |
|
|
National Infrastructure |
|
|
Interruptions and outages - for a short period - in national vital infrastructure security and operations, affecting one or more sectors No damage or short-term impact will occur to the security and operations of local/regional infrastructure. |
Government Agencies' Tasks Will revealing it lead to a reduction in the ability of government agencies to carry out their daily operations and tasks? |
|
A governmental entity’s or entities’ inability to perform one or more of its primary duties for a short period |
The inability of a governmental entity or more to perform one or more non-essential tasks for a short period
|
University and its Branches |
University Works and Services Would revealing information lead to a reduction in the ability of university units to carry out their daily operations and tasks? |
All units within the university are unable to perform their primary tasks and operations |
|
The inability of a single regulatory unit (such as a university, a specific branch, etc.) to perform one or more of its primary tasks |
There is no impact on the University's activities and branches. |
||||
|
University Infrastructure | ||||||||||||||||||||||||||||||||||
|
|
|
|
|
Material Losses |
|
|
Activities of Other Entities |
|||||||||||||||||||||||||||
|
Private sector profits |
|
|
|
No impact on agency activities Private Agencies’ Tasks Will disclosing it lead to harm for private entities that manage public facilities? Will this result in the loss of a pioneering role or the loss of any assets? |
|
|
|
|||||||||||||||||||||||||||
|
|
Data Classification Levels |
|||||||||||||||||||||||||||||||||
|
|
Highly confidential |
Sari Restricted |
Year |
Main Impact Category, Sub-Impact Category, Considerations |
Level of Impact |
High |
Medium |
Low No data |
Individuals |
|
|
|
|
No impact on individuals |
|
|
|
|
Environment |
|||||||||||||||
|
Environmental Resources Will this information be used to develop a service or product that could lead to the destruction of the Kingdom's environmental or natural resources? |
|
|
|
There is no environmental impact |
||||||||||||||||||||||||||||||
- All unclassified data must be classified within a specified period according to an action plan prepared by the Data Management Office of the University and approved by the University President or his designee
- Appointment of Business Representatives:
The decision to appoint data representatives for various administrative units within the University is made by the esteemed President of the University or by an authorized individual. This determination will be based on recommendations from the General Supervisor of the Data Office/Director of the Data Office.
- University data is restricted:
- All of the university's data, which is held through business data representatives and through parties participating with the university, are identified and documented by them. The University’s data sources can be defined as follows:
|
Internal Data Sources |
External Data Sources
- يتم تحديد قنوات تبادل البيانات والتي تشمل القنوات الآلية والقنوات اليدوية. حيث تشمل القنوات الآلية كافة القنوات الآلية وشبه الآلية مثل رسائل البريد الإلكتروني والرسائل القصيرة وغيرها من القنوات الخاصة بالأنظمة الالكترونية. بينما تشمل القنوات اليدوية جميع القنوات غير التقنية مثل الأقراص المدمجة ووحدات التخزين USB والأقراص الصلبة الخارجية والوثائق الورقية.
- إجراء عملية تقييم الأثر:
يجب على ممثل بيانات الأعمال اتباع الخطوات اللازمة لعملية تقييم الأثر المحتمل الذي يترتب على:
- الإفصاح عن هذه البيانات أو الوصول غير المصرح به لها.
- إجراء تعديل على هذه البيانات أو إتلافها أو كليهما.
- عدم الوصول إلى هذه البيانات في الوقت المناسب.
تبدأ عملية تقييم الأثر بتطبيق مبدأ "الأصل في البيانات الاتاحة" (في المجال التنموي) مالم تقتض طبيعتها أو حساسيتها مستويات أعلى من التصنيف والحماية وسرية للغاية (في المجال السياسي والأمني) مالم تقتض طبيعتها أو حساسيتها مستويات أدني من التصنيف. يتمثل العنصر الأول من عملية تقييم الأثر في تحديد الفئة الرئيسية والفرعية للأثر المحتمل في أي من الفئات الرئيسية التالية:
- المصلحة الوطنية
- أنشطة الجهات
- صحة أو سلامة الأفراد
- الموارد البيئية
- تحديد مستوى الأثر:
يتعين على ممثل بيانات الأعمال أن يحدد لكل أثر محتمل مستوى معين يعتمد تحديد المستوى على الآتي:
- مدة الأثر وصعوبة السيطرة على الضرر.
- فترة تدارك وإصلاح الأضرار بعد وقوعها.
- حجم الأثر على مستوى وطني، مناطقي، عدة جهات، جهة واحدة، عدة أفراد .... الخ .
- كما يمكن تحديد مستوى الأثر من خلال المعايير أدناه:
- عالي يؤدي الوصول الى البيانات أو الإفصاح عنها إلى حدوث أضرار جسيمة أو خطيرة للغاية على المدى الطويل لا يمكن تداركها أو إصلاحها.
- متوسط يؤدي الوصول إلى البيانات أو الإفصاح عنها إلى حدوث أضرار جسيمة أو خطيرة يصعب السيطرة عليها.
- منخفض يؤدي الوصول إلى البيانات أو الإفصاح عنها إلى أضرار محدودة يمكن السيطرة عليها أو أضرار متقطعة على المدى القصير يمكن السيطرة عليها.
- لا يوجد أثر، لا يؤدي الوصول إلى البيانات أو الإفصاح عنها إلى اي ضرر على المدى الطويل أو القصير.
- يجب ان تكون جميع الاضرار المحتملة والمحددة خلال عملية تقييم الأثر محددة وقائمة على أدلة، في محاولة للحد من التقديرات الشخصية للمكلف بإجراء تصنيف البيانات. يحدد ممثل بيانات الاعمال مستوى تصنيف البيانات بناءً على الأثار المحددة ومستوياتها:
- عالي، تصنف البيانات باعتبارها "سرية للغاية".
- متوسط، تصنف البيانات على انها "سرية".
- منخفض، يلزم إجراء المزيد من التقييمات (من خلال القيام بالخطوات 5، 6)
- لا يوجد أثر، تصنف البيانات على أنّها بيانات "عامة".
- تحديد الأنظمة ذات العلاقة (فقط إذا كان مستوى الأثر منخفض):
يجب إجراء تقييمات إضافية إذا كان مستوى الأثر المحدد “منخفض" وذلك بهدف زيادة مستوى تصنيف البيانات المصنفة على أنها بيانات “عامة" إلى الحد الأقصى. يجب على ممثل بيانات الأعمال في هذا الصدد، دراسة ما إذا كان الإفصاح عن هذه البيانات يتعارض مع أنظمة المملكة العربية السعودية مثل نظام مكافحة الجرائم المعلوماتية ونظام التجارة الإلكترونية ... الخ وإذا كان الإفصاح عن البيانات مخالفاً للأنظمة، فيجب حينها تصنيف البيانات على أنها بيانات “مقيّدة"، بخلاف ذلك يتعين على ممثل بيانات الأعمال مواصلة تنفيذ الخطوة 5.
- الموازنة بين مزايا الإفصاح عن البيانات والآثار السلبية (فقط إذا كانت الإجابة على الخطوة 5 “لا"):
بعد التأكد من مستوى الأثر المنخفض وضمان أن الإفصاح لن يكون انتهاكاً لأي نظام نافذ، يجب أيضاً تقييم المزايا المحتملة للإفصاح عن مثل هذه البيانات والتأكد مما إذا كانت هذه المزايا ستفوق الآثار السلبية أم لا، وتشمل المزايا المحتملة استخدام البيانات لتطوير خدمات جديدة ذات قيمة مضافة، أو زيادة شفافية العمليات الحكومية أو زيادة مشاركة الأفراد مع الحكومة. وعليه:
- إذا كانت المزايا أكبر من الآثار السلبية، تصنف البيانات على أنها "عامة".
- إذا كانت المزايا أقل من الآثار السلبية، تصنف البيانات على أنها "مقيّدة".
- مراجعة مستوى التصنيف:
يجب أن يفحص مراجع تصنيف البيانات -أحد منسوبي مكتب إدارة البيانات بالجامعة- جميع البيانات المصنفة لضمان أن يكون مستوى التصنيف المحدد من جانب ممثل بيانات الأعمال هو الأنسب، وتتم مراجعته خلال شهر واحد من التصنيف الأولي.
- تطبيق الضوابط المناسبة:
تتمثل الخطوة الأخيرة من عملية تصنيف البيانات في حماية جميع البيانات وفقاً لمستوى التصنيف عن طريق تعميم نتائج التصنيف وتطبيق ضوابط تصنيف البيانات. بحيث يتم الانتهاء من عملية التصنيف عند تصنيف جميع البيانات التي تملكها الجامعة والتحقق من مستويات التصنيف وتطبيق الضوابط ذات الصلة.