Reference Document: ISO31000

Version Number: 1.0

Release Date: May 2024

 

1. Introduction

The Digital Transformation Office and Knowledge Sources – affiliated with Najran University, is committed to implementing an integrated framework for risk management in accordance with ISO 31000:2018 standards, and in line with national cybersecurity policies and requirements of the Digital Government Authority and the Ministry of Education. This policy aims to enhance the Office’s ability to predict, analyze, and effectively address risks, which contributes to protecting resources and assets, ensuring business continuity, and supporting the University's strategic objectives.

2. Purpose

  • Establish a methodological framework for risk management at all levels.
Enable decision-makers to manage risks within an accepted risk tolerance level.Guaranteeing the linkage between risks and the University’s strategic and operational objectives.
  • Support for Business Continuity and Integration with the ISO 22301 Business Continuity Management System.
  • 3. Application Scope

    This policy applies to:
    • All departments and units affiliated with the Deanship.
  • Technical Systems, Digital Services, Infrastructure, Data, Human Resources, Suppliers.
  • Operations and Projects and Digital Initiatives.
    • 4. General Principles
    • Holistic Approach: Managing all types of risks (strategic, operational, technical, financial, legal, security).
  • Integration: Linking risks with business continuity plans and digital governance.
  • Participation: Involve all employees and stakeholders in identifying and evaluating risks.
  • Transparency: Documenting all stages of risk management in the approved Risk Register.
  • Compliance: Adherence to national regulations (Royal Decrees – Council of Ministers’ Resolutions – Agency Policies – Ministry of Education Requirements).
  • Continuous Improvement: Reviewing and updating policies and procedures periodically.
  • 5. Methodology

    1. Risk Identification: Identifying potential risks related to operations and services.
  • Risk Analysis: Assessment (Probability x Impact) using the approved Risk Matrix.
  • Risk Assessment: Identify the level of risk (Low – Medium – High – Critical).
  • Risk Management: Selecting one of the methods (Avoidance – Reduction – Transfer – Acceptance).
  • Follow-up and Review: Monitoring the risk status and measures taken periodically.
  • Documentation: Recording data in the risk register, including:
    • Risk Name
    ReasonsThe consequencesObjectives Related
  • Evaluation Level Before / After Processing
  • Responsible Owner
  • Preventive/Treatment Procedures
  • Status (Implemented – Proposed – Open – Archived)
  •