Cybersecurity Policy – Najran University
Authority: Cybersecurity Administration
Reference: The National Information Technology Security Agency
Version: 1.2
Date: 10/01/2022
Document Classification: Internal – Restricted

1. General Policy:
This policy aims to provide cybersecurity requirements based on best practices and standards related to documenting and adhering to cybersecurity requirements in Najran University, to reduce cyber risks and protect technical and informational assets from internal and external threats. This is achieved by focusing on the following key objectives:
- Information Confidentiality
- Information Integrity
- Information Availability

This policy also aims to comply with all regulatory requirements specific to Najran University, as well as relevant legislative and regulatory requirements, and to follow the National Cybersecurity Controls issued by the National Information Technology Security Agency (ECC-1:2018).

2. Objectives:
1. Comply with legal and regulatory requirements alongside the requirements of the National Information Technology Security Agency.
2. Achieve the essential controls for Cybersecurity (ECC-1:2018) issued by the National Information Technology Security Agency.
3. Disseminate cybersecurity requirements and clarify them for all university personnel to ensure understanding and compliance.

3. Scope of Work and Applicability:
This policy applies to all information and technical assets in Najran University, including:
- Computers (office, portable, and tablet).
- Network infrastructure and communication systems.
- Electronic platforms and applications.
- Databases and stored information.
- Any devices or systems related to the university’s digital activities.

This policy is the primary reference for all cybersecurity policies and procedures related to technical project management, human resources, suppliers, system change management, and other operations that affect the university’s information and technical assets.

4. Policy Elements:
The Cybersecurity Administration at Najran University must develop, review, and implement the following elements periodically:

4-1. Development of Cybersecurity Policies:
- Develop clear cybersecurity standards and policies based on risk assessment in the university.
- Adopt these policies from relevant regulatory bodies within the university and obtain approval from the University Administration.

4-2. Cybersecurity Strategy (Cybersecurity Strategy):
- Develop a comprehensive strategy aimed at protecting the university of Najran’s technical and information assets. - Include objectives, policies, executive policies, and elements related to governance and operations within the framework of the strategy.
4-3. Cybersecurity Roles and Responsibilities:
- Identify clear tasks and responsibilities for all parties involved in implementing cybersecurity controls within the university. - Ensure a organizational structure that performs ongoing oversight, follow-up, and evaluation of cybersecurity effectiveness.
4-4. Cybersecurity Risk Management:
- Create a methodological program to identify and assess cybersecurity risks. - Develop controls and procedures for dealing with risks according to priorities, ensuring the protection of technical and information assets.
4-5. Information Technology Projects in Cybersecurity:
- Integrate cybersecurity requirements into all systems and applications development projects within the University of Najran. - Ensure that projects comply with relevant legislation and regulatory policies. - Follow accredited methodologies for developing, testing, and securing systems before deploying them into operation.
4-6. Regulatory Compliance:
- Ensure that the university’s cybersecurity programs comply with all relevant national laws and regulations. - Monitor legislative and regulatory changes and update policies and plans as needed.
4-7. Cybersecurity Periodical Assessment and Audit:
- Conduct periodic assessments and audits to ensure that cybersecurity controls are being implemented within the university. - Document audit results and take corrective measures when deficiencies or vulnerabilities are detected.
4-8. Cybersecurity in Human Resources:
- Ensure that employees and contractors of the University of Najran are aware of cybersecurity risks and how to deal with them. - Include cybersecurity requirements in recruitment, training, performance evaluation, and promotion procedures. - Enforce controls for visitor hosting and necessary security permits before allowing access to sensitive locations.
4-9. Cybersecurity Awareness and Training Program:
- Prepare a periodic training package aimed at raising security awareness among university staff. - Include educational content about the most dangerous cyberattacks and methods for countering them.- Measuring the effectiveness of training and updating it regularly according to new developments and threats.

4-10. Asset Management Policy:
- Preparing an accurate and updated record of all information and technical assets at Najran University.
- Classifying these assets based on their level of confidentiality and importance, and identifying the responsible parties for them.
- Monitoring procedures for the safe purchase and disposal of obsolete or damaged assets.

4-11. Identity and Access Management Policy:
- Establishing controls to identify and manage digital identities of users of systems and authenticate access.
- Applying the principle of least privilege in granting access rights.
- Monitoring login activities, recording them, and analyzing them to detect early attempts at intrusion or misuse.

4-12. Information System and Processing Facilities Protection Policy:
- Enforcing controls to protect computer systems (servers, workstations, processing devices) from cyber threats.
- Implementing rules for the periodic update and patching of systems and applications.
- Securing operating environments (Production, Staging, Development) to prevent security breaches.

4-13. Email Protection Policy:
- Applying email protection mechanisms such as filters, spam/malware detection systems, and encryption techniques when needed.
- Enforcing two-factor authentication (2FA) for access to employees’ email accounts.
- Training users to recognize suspicious emails and how to report them.

4-14. Networks Security Management Policy:
- Designing a network architecture that controls access and separates sensitive departments in the university.
- Implementing firewalls, intrusion detection systems (IDS/IPS), and data encryption technologies (VPN, SSL/TLS).
- Monitoring the network continuously to detect anomalous activities and potential threats.

4-15. Mobile Devices Security Policy:
- Enforcing security measures on mobile devices (smartphones, tablets, laptops) when used to access university resources.
- Implementing mobile device management (MDM) solutions to secure and configure devices.
- Blocking the use of personal or work-based “BYOD” patterns unless approved by the cybersecurity administration and implementing the necessary controls.

4-16. Data and Information Protection Policy:- Organize the classification of sensitive data and encrypt it when transferring and storing according to international standards. - Define controls for information sharing with internal and external parties to ensure its safety and confidentiality. - Implement periodic backup procedures and restoration testing to guarantee data availability in case of disasters or incidents.
4-17. Cryptography Policy and Its Standards:
- Choose internationally approved encryption algorithms and apply them to protect confidential data. - Manage encryption keys securely and document key lifecycle procedures. - Document the operations and procedures related to encryption to ensure compliance with the university’s requirements and regulatory bodies.
4-18. Backup and Recovery Management Policy:
- Identify and document backup procedures for databases and core systems serving the University. - Test recovery (Disaster Recovery) procedures periodically to verify system readiness in case of a disaster. - Maintain offsite, encrypted backups to ensure their safety.
4-19. Vulnerabilities Management Policy:
- Conduct periodic scans of systems and applications using accredited tools to discover security vulnerabilities. - Classify vulnerabilities according to their severity level and apply appropriate fixes within specified timelines according to a schedule. - Document the results of inspections and repairs, and follow up on open requests until all vulnerabilities are completely closed.
4-20. Penetration Testing Policy and Its Standards:
- Implement periodic penetration testing operations to simulate actual cyberattacks. - Focus on critical assets (such as servers containing confidential data or electronic payment systems). - Issue a professional report that clarifies the identified weaknesses and technical recommendations for addressing them.
4-21. Cybersecurity Event Logs and Monitoring Management Policy:
- Collect cybersecurity event logs from all sources (firewalls, servers, intrusion detection devices). - Analyze these logs to detect abnormal activity and potential threats. - Maintain event logs within a secure archive and make them available for investigation when needed.
4-22. Threat Cybersecurity Incident Management Policy:
- Develop an incident response plan that ensures the detection, identification, and timely handling of cybersecurity incidents. - Comply with Royal Command Number 3714 dated 14/08/1438H in reporting and coordination mechanisms with relevant authorities.- Providing the technical and organizational measures to deal with the incident and secure affected systems.

4-23. Physical Security Policy:
- Protecting technological and informational assets from theft and sabotage through the implementation of physical protection measures (locks, surveillance cameras, security guards).
- Identifying sensitive areas (server rooms, network rooms) and imposing security measures for access to them.

4-24. Web Application Security Policy and Standards:
- Adopting web application security rules according to international standards (OWASP Top 10).
- Conducting periodic security audits of the University’s electronic applications to prevent common vulnerabilities (such as SQL injection, XSS).
- Applying immediate remediation mechanisms for applications when any weakness or regulatory error is detected.

4-25. Cybersecurity Resilience and Business Continuity Policy:
- Including business continuity requirements within the University’s cybersecurity strategy.
- Preparing plans for rapid recovery and ensuring the continuity of electronic services in case of disasters or incidents.
- Testing these plans periodically to verify their effectiveness in dealing with sudden disruptions.

4-26. Cybersecurity Policy Related to Third Parties and Cloud Computing:
- Assessing risks associated with using external service providers and outsourcing some technical services (Outsourcing & Managed Services).
- Verifying that external service providers comply with the University of Najran’s cybersecurity standards before signing contracts.
- Ensuring the existence of contracts that protect information confidentiality and define responsibilities when using cloud computing services.

4-27. Cybersecurity Policy Related to Cloud Hosting:
- Securing cloud hosting environments and hosting services used by the University.
- Applying security controls to ensure protection of data during its transmission and storage on cloud service providers.
- Continuously verifying that the service provider complies with relevant legislative and regulatory requirements.

4-28. Compliance with Evidence Collection (Cybersecurity Forensics and Evidence Collection):
- Cybersecurity Management has the right to access information and collect evidence necessary to investigate incidents.
- Evidence and digital assets are handled in accordance with legal and regulatory procedures that ensure the integrity of the digital supply chain of evidence.

5. Exceptions:
It is not permitted to violate any of the cybersecurity policies and controls without obtaining prior formal approval from the Cybersecurity Administration, unless it conflicts with any relevant legislative or regulatory requirements.

6. Roles and Responsibilities: Roles and responsibilities related to cybersecurity for university personnel:

# Responsibilities
1 Handling data and information according to its classification level.
2 Avoiding violation of any person’s or company’s rights, such as copyrights, patents, or other intellectual property, or similar laws and regulations.
3 Complying with cybersecurity policies and procedures.
4 Complying with user equipment cybersecurity requirements.
5 Complying with internet and email cybersecurity requirements.
6 Complying with software and protection system cybersecurity requirements.
7 Complying with system updates and instructions issued by the Cybersecurity Administration.
8 Utilizing all authorized assets for approved purposes only, in accordance with the regulations of Najran University.
9 Obtaining prior approval from relevant departments before hosting visitors in the university’s sensitive locations.
10 Reporting any cybersecurity-related incidents as soon as possible.
11 Complying with the Acceptable Use Policy of Information and Technical Assets.


7. Compliance:
1. The authorized competent person must ensure full compliance with cybersecurity policies and their application within their responsibilities.
2. The Cybersecurity Administration must review and update cybersecurity policies periodically to align with legislative and regulatory requirements.
3. All employees of Najran University must comply with this policy without exception.
4. In the event of any violation of these policies, the University’s administration may take appropriate disciplinary measures according to the internal regulations followed at Najran University.

This policy has been adopted by the Cybersecurity Administration of Najran University and is considered mandatory for all university personnel.