Alqanoni

DataClassificationPolicy

Para. 1.4
Status unknownSaudi ArabiaRegulation

Issued by Saudi Data & AI Authority / NDMO

Data Classification Controls Based on the data classification levels, entities shall identify and implement appropriate data protection controls to ensure secure handling, processing, sharing and disposal of data. If data is not classified at the time of creation or receipt as per the classification criteria, it shall be treated as “Restricted” until correctly classified. The data that was not classified at the time of issuing these Policies shall be classified within a specific period of time according to an action plan to be prepared by the entity and approved by its head. Below are some Public examples of the controls that can be used when classifying data (refer to the data protection controls and guidelines published by the National Cybersecurity Authority). Data Classification controls include but are not limited to the following: Protective Marking !! Protective marking shall be applied to paper and electronic documents (including emails) as per each classification level. Access !! Access to data – logical and physical – shall be granted based on the principles of “Least Privilege” and “Need to Know.” !! Access shall be denied immediately upon the expiration or termination of the professional service of entity employees. Usage !! Classified data shall be used as per the requirements of the classification levels. For example, “Top Secret” data shall only be used within specified locations whether physical (e.g. offices) or virtual (e.g. using cryptography or special applications). Storage !! Data classified as “Top Secret,” “Secret” and “Restricted,” as well as mobile devices that process or store such data, shall not be left unattended. !! Unattended “Top Secret,” “Secret” and “Restricted” data shall be protected while being physically or electronically stored, using any of Public the encryption mechanisms approved by the National Cybersecurity Authority. Data Sharing !! Entities shall decide on the appropriate physical and digital means of secure data sharing that ensure minimization of potential risks and compliance with data sharing regulations. !! Entities shall agree on the data sharing mechanism, whether they will utilize existing sharing mediums, e.g. Government Service Bus, National Information Center Network, or Secured Government Network, or will set up a new direct connection, removable storage media, Wi-Fi, remote access, VPN, etc. Data Retention !! A schedule defining the retention period of all data shall be prepared. !! The retention period shall be defined based on the applicable business, contractual, regulatory and legal requirements. !! The retention schedule shall be reviewed periodically/annually or when there are changes in the relevant requirements. Disposal of Data !! All data shall be securely disposed of according to the data retention schedule upon the approval of the relevant Business Data Executive. !! Data which is classified as “Top Secret” or “Secret” and which is electronically controlled shall be disposed of by using the latest electronic media disposal methods. !! All paper-based data shall be disposed of using a cross-cut shredder. !! A detailed log of all disposed of data shall be maintained. Public Archiving !! Data shall be archived in secure storage locations, as recommended by the relevant Business Data Executive. !! Archived data shall be backed up. !! Archived data classified as “Top Secret” and “Secret” shall be protected using any of the encryption mechanisms approved by the National Cybersecurity Authority. !! A detailed list of users authorized to access archived data shall be prepared and documented. Declassification !! Data shall be declassified or downgraded upon the expiration of the classification period, or when protection is no longer required at the original classification level. !! In case data has been wrongly classified, a data user shall notify the Business Data Executive to determine the extent to which it is required to re-classify such data appropriately. !! Data declassification triggers shall be set when the initial classification levels are first applied and shall be captured in the data register. These triggers may include: o A specified period after data creation or receipt (e.g. two years after creation); o A specified period after taking the last action on data (e.g. six months from the date of the last use); o After the lapse of a specific date (e.g. to be reviewed on 1 January Public o After particular circumstances or events that have a direct impact on the data (e.g. a change of strategic priorities or a change of the employees of government entities). !! Declassification or downgrading of data, beyond the clear declassification triggers, shall require a sound understanding of both the sensitive data content and its context.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.