Restrictive cybersecurity policies
Penetration testing policy
1 - Policy Objective
This policy aims to provide cybersecurity requirements based on best practices and standards in assessing and testing the effectiveness of cybersecurity enhancement capabilities at Qassim University by simulating actual cyber attack techniques and methods, and to discover unknown security vulnerabilities that may lead to cyber breaches of the university by focusing on the core goals of protection: the confidentiality, integrity, and availability of information. This policy has been aligned with the controls of the National Cybersecurity Authority (NCA) and according to the international information security standard ISO27001. .
2 – Policy Scope
This policy covers all technical systems and their components, and all externally provided services (via the internet) and their technical components, including: infrastructure, websites, web applications, smartphone and tablet applications, email, and remote access to the university. This policy applies to all employees.