Risk Management Policy
Reference Document: ISO31000
Version Number: 1.0
Release Date: May 2024
1. Introduction
The Digital Transformation Office and Knowledge Sources – affiliated with Najran University, is committed to implementing an integrated framework for risk management in accordance with ISO 31000:2018 standards, and in line with national cybersecurity policies and requirements of the Digital Government Authority and the Ministry of Education. This policy aims to enhance the Office’s ability to predict, analyze, and effectively address risks, which contributes to protecting resources and assets, ensuring business continuity, and supporting the University's strategic objectives.
2. Purpose
- Establish a methodological framework for risk management at all levels.
3. Application Scope
This policy applies to:- All departments and units affiliated with the Deanship.
- 4. General Principles
- Holistic Approach: Managing all types of risks (strategic, operational, technical, financial, legal, security).
5. Methodology
- Risk Identification: Identifying potential risks related to operations and services.
- Risk Name