Business Continuity Management Framework
Para. 2.6Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
IT Disaster Recovery Plan (DRP) Principle The Member Organization should define, approve, implement and maintain a IT DRP for its critical activities and related technology infrastructure. Objective To ensure the Member Organization has IT DRP and up-to-date list of critical activities in place, in case of a disruptive incident Control considerations 1. An IT DRP to recover and restore technology services and infrastructure components (Data, systems, network, services and applications) should be defined, approved, implemented and maintained in alignment with business impact analysis. 2. The Member Organization should establish an alternative data center at an appropriate location. The location should be identified based on: a. A risk assessment to confirm that the location does not share the same risks of the main data center (e.g., geographical threat) b. Upon approval from SAMA 3. Data, system, network and application configurations, and capacities in the alternative data center should be commensurate to such configurations and capacities maintained in the main data center. 4. Member Organization should implement the same logical, physical, environmental and cyber security controls for the alternative data center as for the primary data center. 5. The Member Organization should define and implement a backup and recovery process. 6. The Member Organization should have offsite location for storing backups. 7. Formal contracts should be signed with third parties to ensure the continuity of outsourced services or delivery of replacing hardware or software within the agreed timelines in case of a disaster. Include guidelines to ensure that the contracts signed with external service providers are aligned with the BIA and RA outcomes. 8. The IT manager should be responsible to maintain and keep the disaster recovery plans and arrangements up to date with an overall accountability of integration within the BCM Program on the BCM Manager. 9. The compliance with the disaster recovery plan should be monitored. 10. The effectiveness of the IT DRP should be measured and should be evaluated on a yearly basis as minimum. 2.7 Cyber Resilience Principle The Member Organization should ensure that critical services, business functions and processes run on reliable and robust infrastructure and software. Objective To ensure each that the Member Organization's critical services, business functions and processes are available when required and resistant to disruptions. Control considerations 1. All changes to the infrastructure and software, which directly support the identified critical services, business functions and processes, should: a. Be subject to in-depth risk assessments to ensure the agreed business requirements regarding availability and recovery are met. b. Follow strict development, testing and change management procedures to avoid single point of failures or malfunctioning. 2. A periodic architectural review should be defined and approved to ensure the business requirements regarding availability and business continuity are being correctly addressed and implemented. Note. For more control considerations to improve the overall resilience, e.g., threat management , vulnerability management , please refer to the SAMA - Cyber Security Framework .
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded