1- The objective of the policy
This policy aims to provide cybersecurity requirements based on best practices and standards related to documenting cybersecurity requirements and the university's commitment to them, in order to reduce cybersecurity risks and protect against internal and external threats. This is achieved by focusing on the primary objectives of protection, which are: information confidentiality, integrity, and availability, in accordance with the controls of the National Cybersecurity Authority (NCA) and the international information security standard ISO 27001.
2 – Scope of the Policy
This policy applies to all information technology projects, including university employees, employees of temporary staffing agencies, vendors, partners, contractor personnel, and functional units, regardless of geographic location. The Cybersecurity Department is responsible for resolving any issues arising from the implementation of this policy. This policy serves as the primary driver for all cybersecurity policies, procedures, and standards across various topics, as well as an input for internal processes such as human resources, supplier management, project management, change management, and others.
3 – Elements of the Policy
- Cybersecurity management must establish cybersecurity standards and document its policies and programs, based on the results of the risk assessment, in a manner that ensures the dissemination and adherence to cybersecurity requirements, in accordance with the university's organizational business requirements and relevant legislative and regulatory requirements. They must also be approved by the authorized authority and disseminated to the relevant university employees and stakeholders.
- The Cybersecurity Department must develop and implement cybersecurity policies, programs, and standards, including, but not limited to, the following:.
- The Cybersecurity Department is authorized to access information and gather the necessary evidence to ensure compliance with relevant legislative and regulatory requirements pertaining to cybersecurity.