Identity and Access Management Policy
Access Control and Identity Management Policy
Document Category: Restricted
Version: 2.0
Date: 11/02/2025
Reference: The National Cyber Security Agency
Disclaimer:
This model was developed by the National Cyber Security Agency as an illustrative example that can be used as a reference guide for business operations, with customization and modification by the competent authorities at Najran University for legal and regulatory requirements related to it. This model must be approved by the head of the entity or by the person authorized to delegate it. The Agency highlights that it is not responsible for the use of this model as is, and that it is nothing more than an illustrative example.
Table of Contents:
- Purpose
- General Items
-
1. Purpose:
To identify cybersecurity requirements related to user and access management on the information and technical assets of Najran University, to protect them from cyber threats and internal and external threats, through focusing on the primary protection objectives: confidentiality, integrity, and availability. This policy is aligned with the controls and standards issued by the National Cybersecurity Authority and the relevant regulatory and legislative requirements.
2. Scope of Work:
This policy applies to all information and technical assets of Najran University, and to all employees (staff and contractors) in the university.
3. Policy Items:
3.1 General Items:
- 1-1. Access granting, modification, cancellation, and monitoring procedures must be documented and approved for Najran University’s information and technical assets.
- Need-to-Know and Need-to-Use principle
3.2 Access Granting Permissions:
- 2-1-1. Access permission must be granted based on user request through an approved form from the relevant administration (direct manager or system owner) in the Cybersecurity Management System, including the system name, request type, permission, and validity period (if temporary).
3.3 Important and Sensitive Access Permissions Requirements:
- 2-2-1. System Manager authorities (Sys ID) must be assigned based on job functions, taking into account the principle of segregation of duties.
3.4 Granting Remote Access Permissions:
- 2-3-1. Remote access privileges to information and technical assets must be granted after obtaining prior approval from the Cybersecurity Management and restricted access using Multi-Factor Authentication (MFA) through secure and approved channels.
3.5 Revoking and Changing Access Permissions:
- 2-4-1. Upon transfer or termination of the user relationship with Najran University, or changes to their duties, the Human Resources Department must notify the Information Technology Department to disable or modify user accounts and their privileges as soon as possible and with the maximum possible automation.
3.6 Reviewing User Identities and Permissions:
- 2-5-1. User IDs and their usages on sensitive systems must be reviewed at least annually.
3.7 Password Management:
- 2-6-1. A secure password policy with high standards must be applied to all accounts within Najran University, in accordance with the Identity and Access Management Policy and relevant legislation and regulatory requirements.
3.8 Password Protection:
- 2-7-1. All passwords for information and technical assets must be stored and transferred using encryption technology in accordance with the encryption policy approved by Najran University.
4. The Roles and Responsibilities:
- Cybersecurity Director: Policy Owner.
5. Update and Review:
The Cybersecurity Management must review this policy annually or when changes occur in policies or regulatory procedures or related legal and regulatory requirements for Najran University.
6. Policy Compliance:
- Cybersecurity Management must periodically verify the compliance of all employees at Najran University with this policy.