Cyber Resilience Fundamental Requirements (CRFR)
Para. 2.7Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Cyber Resilience 4 Appendices Appendix A: Glossary Term Description Access management Access management is the process of granting authorized users the right to use a service, while preventing access to non-authorized users. Audit Independent review and examination of records and activities to assess the adequacy of system controls, to ensure compliance with established policies and operational procedures. Source: NISTIR 7298r3 Glossary of Key Information Security Terms Availability Ensuring timely and reliable access to and use of information. Source: NISTIR 7298r3 Glossary of Key Information Security Terms Back-up Files, devices, data and procedures available for use in case of a failure or loss, or in case of deletion or suspension of their original copies. Business Continuity (BC) The capability of an organization to continue delivery of IT and business services at acceptable predefined levels following a disruptive incident. Source: ISO 22301:2012 Societal security -- Business continuity management systems Business Continuity Management (BCM) Holistic management process that identifies potential threats to an organization and the impacts to business operations those threats, if realized, might cause, and which provides a Fundamental Requirements for building organizational resilience with the capability of an effective response that safeguards the interests of its key stakeholders, reputation, brand and value creating activities. Source: ISO 22301:2012 - Business continuity management systems — Requirements Change management The controlled identification and implementation of required changes within a business or information systems. Cryptography The discipline that embodies the principles, means, and methods for the transformation of data in order to hide their semantic content, prevent their unauthorized use, or prevent their undetected modification. Source: NISTIR 7298r3 Glossary of Key Information Security Terms Cyber risk Risk of financial loss, operational disruption, or damage, from the failure of the digital technologies employed for informational and/or operational functions introduced to a manufacturing system via electronic means from the unauthorized access, use, disclosure, disruption, modification, or destruction of the manufacturing system Source: NISTIR 7298r3 Glossary of Key Information Security Terms Cyber security Cyber security is defined as the collection of tools, policies, security concepts, security safeguards, guidelines, risk management approaches, actions, training, best practices, assurance, and technologies that can be used to protect the Entities information assets against internal and external threats. Cyber Security event Any observable occurrence in an information system or network that has, or may potentially result in, unauthorized access, processing, corruption, modification, transfer or disclosure of data and / or Information or (b) a violation of an explicit or implemented Organization security policy. Cyber security governance A set of responsibilities and practices exercised by the Board of Directors with the goal of providing strategic direction for cyber security, ensuring that cyber security objectives are achieved, ascertaining that cyber risks are managed appropriately and verifying that the enterprise's resources are used responsibly. Cyber security incident An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. Source: NISTIR 7298r3 Glossary of Key Information Security Terms Cyber security incident management The monitoring and detection of security events on an information system and the execution of proper responses to those events. Cyber security policy A set of rules that governs all aspects of security-relevant system
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded