Reference Document: The National Cyber Security Agency
Release Date: February 2026
1. Purpose
The purpose of this policy is to define the cybersecurity requirements related to the use of user devices (Workstations), mobile devices (Mobile Devices), and Bring Your Own Device (BYOD) at Najran University, to reduce cyber risks to it and protect it from internal and external threats, through focusing on the core protection objectives which are: confidentiality, integrity, and availability of information.
This policy has been aligned with the controls and standards issued by the National Cyber Security Authority and the relevant regulatory and legislative requirements.
2. Scope of Work
This policy covers all user devices, mobile devices, and personal devices of employees at Najran University, and applies to all employees (staff and contractors) at Najran University.
General Terms
- Data and information stored on user devices, mobile devices, and personal devices (BYOD) must be protected according to their classification using appropriate security controls to restrict access to this information and prevent unauthorized personnel from accessing or viewing it.
Software for users’ devices, mobile devices, and personal devices (BYOD), including operating systems, software, and applications, must be updated and provided with the latest update packs and fixes in accordance with the approved Update and Patch Management Policy of Najran University.User devices, mobile devices, and personal devices (BYOD) must be configured and hardened in accordance with the approved technical security standards of Najran University.It is prohibited to grant employees significant and sensitive (Privileged Access) permissions on Najran University systems using mobile devices and personal devices (BYOD), and permissions must be granted according to the principle of least privilege and minimum rights.Default user accounts in operating systems and applications must be deleted or renamed.Clock synchronization must be centralized from a precise and reliable source for all user devices, mobile devices, and personal devices (BYOD).Users’ devices and mobile devices must be provided with a text message (Banner) to enable authorized use.It is necessary to use Data Leakage Prevention technology and employ data protection monitoring systems to ensure the protection of data on user devices and mobile devices.All media and storage devices belonging to users' devices and critical, sensitive mobile devices that have advanced privileges and access rights to sensitive systems must be fully encrypted (Full Disk Encryption) in accordance with the encryption standard adopted by Najran University.Must restrict the use of external storage media in accordance with approved procedures by Najran University, after obtaining prior approval from the Cyber Security Department.Mobile and personal devices (BYOD) must be centrally managed using a Mobile Device Management (MDM) system.Users’ devices, mobile devices, and personal (BYOD) devices equipped with outdated or expired software are not permitted to connect to the Najran University network, to prevent security threats arising from unpatched, obsolete software and lack of updates and fixes.Users’ devices, mobile devices, and personal devices (BYOD) that are not equipped with the latest security software must be prohibited from connecting to the Najran University network to avoid cyber risks leading to unauthorized access, malicious software entry, or data leakage. Security software includes antivirus and malware protection programs, host-based firewalls, and advanced intrusion detection/prevention systems on hosts.Deviations from acceptable user behavior must be identified, risk levels assessed, and appropriate mitigation measures developed and/or recommended to alleviate them.User devices and inactive mobile devices must be configured to display a password-protected session timeout screen if the device is not in use (Session Timeout) for 5 minutes.User devices and mobile device accounts must be centrally managed through the active directory server (Active Directory) of Shaqara Najran University domain or a central administrative system.Appropriate Group Policy must be implemented and applied to all user devices and mobile devices to ensure configuration settings, hardening, and compliance with Najran University’s regulatory and security controls, as well as the installation of necessary software configurations.Must perform regular backups of data stored on user devices and mobile devices, according to the approved backup policy at Najran University.It is necessary to provide and use technologies that enable the remote deletion of data stored on mobile devices and personal devices (BYOD) in the following cases:
- Loss or theft of a mobile device.
Termination or termination of the employment relationship between the user and Najran University.Expiration of usage and handover of the mobile device to the concerned administration at Najran University.
Remote systems and their associated information devices must be protected through:
- Implementing Secure Session Management, which includes session reliability (Authenticity), lockout functionality, and timeout settings.
Applying update and patch packages for remote work systems at least once a month.Review remote work systems security settings and conduct fortification once at least every year.Restriction of enabling features and services in remote work systems according to need, with an analysis of potential cybersecurity risks required if activation is necessary.
Awareness campaigns must be organized regarding safe mobile device and personal device (BYOD) usage, as well as user responsibilities towards them, in accordance with the approved Acceptable Use Policy of Najran University, and awareness sessions should be conducted for users with important and sensitive authorities.Appropriate procedures and standards must be developed regarding the security of user devices, mobile devices, and personal devices based on operational needs.A Key Performance Indicator (KPI) should be used to ensure continuous development and the proper, effective utilization of user device and mobile device and personal device protection requirements.4. Cybersecurity Requirements for User Device Security
- Users' devices must be assigned to technicians in technical roles with important and sensitive privileges, to be isolated in a private network for managing systems (Management Network) and not connected to any other network or service.
User device’s important and sensitive PAWs (Privileged Access Workstations) settings must be configured to send logs to the Prince of Narayman University central logging and monitoring system in accordance with the approved event logging and cybersecurity monitoring policy, while preventing users from changing these settings.Users’ devices must be physically secured within the buildings of Najran University and exit/entry operations, after obtaining the necessary approvals according to Najran University's approved physical security policy, shall be recorded.Users’ devices must be protected from viruses, malware, advanced and persistent threats, unknown attacks, and any other malicious attacks through endpoint protection software technologies.It is necessary to ensure the safety of user device data from tampering, loss, or damage, and to confirm its availability and recoverability.All necessary security controls must be applied when data is removed from user devices, particularly those connected to cloud services, in accordance with the University of Najran’s Data and Information Protection Policy.Update and patch packages for devices used to manage external, internet-connected sensitive systems should be managed at least once per month, and at least once every three months for devices used to manage internal sensitive systems, in accordance with the change management policy approved by Najran University.It is necessary to review the settings of the devices used to manage sensitive systems and protect them at least once every six months.5. Cybersecurity Requirements for Mobile Device Security
- Mobile devices should be restricted from accessing sensitive systems except for a temporary period only, after conducting a risk assessment and obtaining the necessary approvals from the Cyber Security Department.
Users who are not authorized must be restricted to unmonitored devices and/or lost and/or stolen devices.It is imperative to ensure the integrity of information stored on mobile devices.It is necessary to ensure that the operating system and installed applications on mobile devices are updated and configured appropriately before use (Device OS and Applications Security) in accordance with the approved technical standards of Najran University.All mobile devices must be updated with patches and security fixes at least once monthly.Data and information belonging to Najran University stored on mobile devices must be separated and encrypted.Cybersecurity Requirements for Personal Device Security (BYOD)
- In the event of employees using their personal devices for work purposes, this must be supported by documented agreements with employees and technical security controls to protect the data and information of Najran University.
Data and information specific to Najran University stored on personal devices (BYOD) must be segmented and encrypted.7. Roles and Responsibilities
- Policy Owner: Cybersecurity Management.
Review and Update of the Policy: Cyber Security Management.Implementation of Policy and Application: Digital Transformation Office, Knowledge Sources, Cyber Security Management.Measurement of Commitment to Policy: Cyber Security Management.8. Updates and Review
The Cybersecurity Management must review the policy at least annually, or in the event of changes to policies and procedures within King Saud University, or relevant legislative and regulatory requirements.
9. Commitment to Policy
- Cybersecurity Management must ensure that Najran University adheres to this policy periodically.
All employees of Najran University must comply with this policy.Any violation of this policy may result in disciplinary action against the offender according to the procedures followed at Najran University.