Restrictive cybersecurity policies
Network Security Management Policy
The objective of the policy:
This policy aims to provide cybersecurity requirements based on best practices and standards related to the university's network security to minimize cyber risks and protect it from internal and external threats by focusing on the core objectives of protection, namely: information confidentiality, integrity, and availability. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all university technical networks, including wireless networks, and covers all university affiliates.
Access Management Policy
The objective of the policy:
This policy aims to define cybersecurity requirements to ensure the protection of informational and technological assets at the university from cybersecurity risks through:
- Maintaining the information asset register that documents all information assets in the university.
- Asset owners and administrators clarification.
- Verification of confidentiality, integrity, and availability classifications for information assets.
In compliance with the National Cybersecurity Authority (NCA) guidelines and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all of the university's information assets (such as physical assets, data, business applications, software, and technical assets), and to all personnel (employees and contractors) at the university.
Penetration testing policy
Policy objective:
This policy aims to provide cybersecurity requirements based on best practices and standards for assessing and testing the effectiveness of cybersecurity enhancement capabilities at Qassim University. This is achieved by simulating actual cyberattack techniques and methods, and by discovering unknown security vulnerabilities that could lead to a cyber breach of the university, with a focus on the core objectives of protection: confidentiality, integrity, and availability of information. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the global information security standard ISO 27001.
Policy scope:
This policy covers all systems and their technical components, as well as all externally provided services (via the internet) and their technical components, including: infrastructure, websites, web applications, smartphone and tablet applications, email, and remote access to the university. This policy applies to all personnel.
Vulnerability Management Policy
The objective of the policy:
This policy aims to define the cybersecurity requirements related to ensuring the timely detection and effective remediation of technical vulnerabilities in order to prevent or reduce the likelihood of these vulnerabilities being exploited by cyberattacks, as well as to minimize the potential impacts on the university, protect it against internal and external threats, and implement the provisions set forth by the National Cybersecurity Authority (NCA) controls and in accordance with the international information security standard. ISO27001.
Policy scope:
This policy applies to all IT and technical projects, including university employees, temporary staffing agency employees, vendors, partners, contractor employees, and functional units, regardless of geographic location. The Cybersecurity Department is responsible for resolving any issues arising from the implementation of this policy.
Update and Patch Management Policy
The objective of the policy:
This policy aims to provide cybersecurity requirements based on best practices and standards related to the management of updates and patches for systems, applications, databases, network devices, and information processing devices to reduce cybersecurity risks resulting from internal and external threats, focus on the confidentiality and integrity of information within the university, and in application of the provisions of the National Cybersecurity Authority (NCA) controls and in accordance with the international information security standard. ISO 27001.
Policy scope:
This policy applies to all university technical assets, including all components of cloud technical systems (CTS), sensitive systems, operational systems, remote work systems, and technical assets related to social media accounts. The policy also includes the Cybersecurity Department and the Information Technology Department at the university, in addition to any other departments or teams responsible for managing, maintaining, or securing technical assets.
Cybersecurity Incident and Threat Management Policy
The objective of the policy:
This policy aims to establish an integrated framework for managing cybersecurity incidents and threats at the university, ensuring the rapid detection of incidents, effective response to them, minimizing their impact on operations as well as technical and informational assets, and smoothly restoring operational activities. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard. ISO 27001.
Policy scope:
This policy applies to all university systems, networks, and digital infrastructure, as well as all employees, users, and contractors who interact with these assets. The policy covers all types of cyber incidents, such as malicious attacks, data breaches, or unauthorized access attempts, and includes all personnel (employees and contractors).
Event Log Management and Cybersecurity Monitoring Policy
The objective of the policy:
This policy aims to regulate the management of event logs and the monitoring of technical activities within the university, to ensure the effective collection and analysis of security event logs, and to enhance the capability to detect and respond to cyber threats. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all technical, informational, event log management, and cybersecurity monitoring systems of the university, including servers, databases, applications, networks, and protection systems. It also covers cloud systems, sensitive systems, and social media accounts, and includes all personnel (employees and contractors).
Password Management Policy
The objective of the policy:
This policy aims to define the cybersecurity requirements related to password management on the university's information and technical assets in order to protect them from cybersecurity risks and internal and external threats by focusing on the primary objectives of protection, which are: confidentiality, integrity, and availability of information, in application of the National Cybersecurity Authority (NCA) controls and in accordance with the international information security standard. ISO 27001.
Policy scope:
This policy applies to all IT and technical projects, including university personnel, temporary employment agency staff, suppliers, partners, contractor employees, and functional units, regardless of geographical location. The Cybersecurity Department is responsible for resolving any issues arising from the implementation of this policy.
Cybersecurity Risk Management Policy
The objective of the policy:
The cybersecurity risk management policy aims to reduce the impact of negative risks on the university. This policy includes reviewing and assessing potential risks, identifying, classifying, and conducting a comprehensive analysis of risks, and implementing proposed controls to mitigate them. It also aims to provide a comprehensive and systematic system for handling risks, ensuring the continuity of the university's operations, protecting its interests and assets, enhancing opportunities for success and growth in the presence of risks, and applying the provisions of the National Cybersecurity Authority (NCA) controls in accordance with the international information security standard. ISO 27001.
Policy scope:
This policy applies to all IT and technical projects, including university employees, temporary staffing agency employees, vendors, partners, contractor employees, and functional units, regardless of geographic location. The Cybersecurity Department is responsible for resolving any issues arising from the implementation of this policy.
Identity and Access Management Policy
The objective of the policy:
This policy aims to define the cybersecurity requirements related to the management of access identities and privileges on the university's information and technological assets in order to protect them from cybersecurity risks as well as internal and external threats by focusing on the core protection objectives, namely: confidentiality, integrity, and availability of information, and in implementation of the provisions of the National Cybersecurity Authority (NCA) controls and in accordance with the international information security standard ISO27001.
Policy scope:
This policy applies to all IT and technical projects, including university employees, temporary staffing agency employees, vendors, partners, contractor employees, and functional units, regardless of geographic location. The Cybersecurity Department is responsible for resolving any issues arising from the implementation of this policy.
Acceptable Use Policy
The objective of the policy:
This policy aims to define the acceptable use of all university information technology assets, such as hardware, software, networks, information, and communication systems that are operated, in implementation of the National Cybersecurity Authority (NCA) controls and in accordance with the international information security standard. ISO27001.
Policy scope:
This policy applies to all IT and technical projects, including university employees, temporary staffing agency employees, vendors, partners, contractor employees, and functional units, regardless of geographic location. The Cybersecurity Department is responsible for resolving any issues arising from the implementation of this policy.
Security Settings and Hardening Policy
The objective of the policy:
This policy aims to provide cybersecurity requirements based on best practices and standards related to the protection, hardening, and configuration control of the university's information, technical assets, and applications to resist cyber attacks by focusing on the core objectives of protection: confidentiality, integrity, and availability of information. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all University information assets, technologies, and applications, and includes all personnel (employees and contractors).
Cybersecurity Compliance Policy
The objective of the policy:
This policy aims to provide an approach to be followed to ensure compliance with the university's cybersecurity policies, standards, procedures, and guidelines, to ensure that the cybersecurity program complies with relevant legislative and regulatory requirements to reduce cybersecurity risks resulting from internal and external threats, to focus on the confidentiality and integrity of information within the university, and in application of the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all technical and informational assets of the university and to all entities that own or use this information or technology. It also applies to all university employees, whether directly, indirectly, through a branch, or any entity performing work on behalf of the university that involves the use of information owned by the university. The Cybersecurity Department is responsible for resolving any issues arising from the application of this policy.
Physical and Environmental Cybersecurity Policy
The objective of the policy:
This policy aims to protect the physical infrastructure of university facilities from security risks and to ensure the safety of information and systems. It also seeks to provide a secure environment that supports academic and administrative operations and prevents physical threats. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all university facilities and physical systems, including data centers, servers, technical rooms, and offices. It includes all individuals who have access to these facilities, whether they are employees, contractors, or visitors.
Cloud computing and hosting cybersecurity policy
The objective of the policy:
This policy aims to provide a framework that defines the necessary security controls to protect the university's data and information while using cloud computing and hosting services. It also aims to enhance security and privacy; this policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all data stored, processed, or transmitted via cloud computing services, as well as hosted systems and applications and the devices used to access them, and includes all personnel (employees and contractors).
Cybersecurity policy regarding human resources
The objective of the policy:
This policy aims to provide cybersecurity requirements based on best practices and standards to ensure that cybersecurity risks and requirements related to university personnel (employees and contractors) are effectively addressed before, during, and upon the conclusion/termination of their employment, in implementation of the National Cybersecurity Authority (NCA) controls and in accordance with the international information security standard. ISO 27001.
Policy scope:
This policy applies to employees, contractors, consultants, temporary staff, and other workers at the university, including all third-party personnel who use IT resources, regardless of geographical location. The Cybersecurity Department is responsible for resolving any issues arising from the application of this policy.
Cybersecurity policy within change management
The objective of the policy:
This policy aims to ensure that changes to the university's technical systems, applications, and infrastructure are implemented in a secure and orderly manner, in compliance with the requirements of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all IT and technical projects, including university employees, temporary staffing agency employees, vendors, partners, contractor employees, and functional units, regardless of geographic location. The Cybersecurity Department is responsible for resolving any issues arising from the implementation of this policy.
Cybersecurity policy within project management
The objective of the policy:
This policy aims to protect digital assets and project-related information at the university, and to ensure the confidentiality, integrity, and availability of this information. The policy also seeks to enhance readiness to face cyber threats and to support business continuity safely and effectively. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all projects managed within the university, including the systems, applications, networks, and technical infrastructure used in their management, as well as to all personnel (employees and contractors).
Encryption and Key Management Policy
The objective of the policy:
This policy aims to protect the confidentiality, integrity, and availability of sensitive information within the university. Through the implementation of encryption technologies compliant with international and national standards, ensuring the secure management of cryptographic keys, preventing unauthorized access to data in transit or at rest, in application of the provisions stipulated by the National Cybersecurity Authority (NCA) controls, and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy covers all the university's electronic information assets and applies to all university personnel, including entities that deal with it and external parties.
Malware Protection Policy
The objective of the policy:
This policy aims to ensure the protection of university systems and data from malware to enhance information security and infrastructure integrity. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all university-affiliated systems, devices, and networks, and all users who interact with them on campus or remotely.
Backup and Restore Policy
The objective of the policy:
This policy aims to define cybersecurity requirements regarding the periodic creation and testing of backups for information and software. It also contributes to enabling business continuity in the event of incidents such as natural disasters, human errors, or cyber attacks, in application of the requirements of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to informational and technical assets such as: university systems, data, and information, and to all personnel (employees and contractors).
Mobile Device Security Policy
The objective of the policy:
This policy aims to define the cybersecurity requirements for user workstations, mobile devices, and employee personal devices (Bring Your Own Device “BYOD”) at the university, in order to reduce cyber threats associated with the use of these devices and maintain the integrity, confidentiality, and availability of information. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all devices used by university employees, including mobile and personal devices. This policy also applies to all employees (staff and contractors) at the university.
Email Security Policy
The objective of the policy:
This policy aims to provide clear guidelines for protecting email from cyber risks as well as internal and external threats at the university, such as phishing, malware, and information theft, in order to ensure the protection of university information and its employees from email-related threats. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all university employees, contractors, and any other party with access to the university's email systems. This policy covers all devices used to access email, including personal computers, laptops, and smart devices, whether university-owned or personal.
Server Security Policy
The objective of the policy:
This policy aims to ensure the protection of servers used at the university from cyber threats. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all university servers and includes all personnel (employees and contractors).
Supplier and Third-Party Relationship Security Policy
The objective of the policy:
This policy aims to protect informational and technical assets, and to ensure effective and secure management of the university's relationships with external parties, with a focus on their compliance with cybersecurity requirements. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all external parties that access, interact with, or provide services to the University's information and technical assets, including contracted companies, and it also applies to all personnel (employees and contractors) to ensure their compliance with cybersecurity requirements.
Database Security Policy
The objective of the policy:
This policy aims to provide cybersecurity requirements based on best practices and standards related to protecting the university's databases and ensuring secure access to them, in order to reduce cybersecurity risks resulting from internal and external threats, focus on the confidentiality and integrity of information within the university, and in application of the National Cybersecurity Authority (NCA) controls and in accordance with the ISO 27001 international information security standard.
Policy scope:
This policy applies to all database systems and all individuals who configure and manage databases at the university. The Cybersecurity Department is responsible for resolving any issues arising from the application of this policy.
Application Development Policy
The objective of the policy:
This policy aims to provide cybersecurity requirements based on best practices and standards related to the development and protection of the university's internal and external web applications, in order to reduce cybersecurity risks resulting from internal and external threats and to focus on the confidentiality and integrity of information within the university. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all internal and external web applications of the university, and includes all personnel (employees and contractors).
Data Protection Policy
The objective of the policy:
This policy aims to establish a comprehensive framework for protecting university data from cyber risks resulting from internal and external threats, by defining and implementing the necessary cybersecurity requirements. This policy serves to enhance the main protection objectives, which are the confidentiality of information, the integrity of information systems, and their availability. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all university facilities, information and technical assets, equipment, and devices, and includes all university personnel.
Web Application Protection Policy
The objective of the policy:
This policy aims to protect web applications from cyber threats and potential security risks by defining cybersecurity requirements related to their protection. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all university web applications and to all of its employees, whether they are staff or contractors.
Cybersecurity Review and Audit Policy
The objective of the policy:
This policy aims to define cybersecurity requirements based on best practices and standards for reviewing and auditing the university's cybersecurity controls, ensuring their implementation, and confirming that they operate in accordance with the university's regulatory policies and procedures, relevant national legislative and regulatory requirements, and international requirements formally approved for the university. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope:
This policy applies to all technical systems, networks, databases, and servers used at the university, as well as their associated applications and services, and includes all personnel (employees and contractors).