Alqanoni

DataClassificationPolicy

Para. 1.5
Status unknownSaudi ArabiaRegulation

Issued by Saudi Data & AI Authority / NDMO

Data Classification Process Step 1: Identify all data of the entity The first step to be taken by an entity is to prepare an inventory of all the data owned by such entity. Step 2: Appoint Responsible of Performing data classification Upon completion of a data inventory, the Entity shall assign the responsibility for performing the classification to a particular person, usually the Business Data Executive, who is an employee of the entity’s office and who best understands the data and its value. This person shall be responsible for making the initial classification. As there could be several Business Data Executives within the Entity, there could be more than one classifier. Step 3: Conduct impact assessment process The Business Data Executive shall follow the steps required for an assessment of the potential impact arising from: !! The disclosure of or unauthorized access to such data; !! Amendment and/or destruction of such data; !! Lack of access to such data in a timely manner. The impact assessment process shall be initiated with the application of the ‘Open by Default’ principle (in the Development sector) unless its nature Public or sensitivity requires higher levels of classification and protection; and the Top-Secret classification (in the political and security sectors) unless its nature or sensitivity requires lower levels of classification. Step 3.a: Identify the impact category The first stage of the impact assessment process is to identify the main and subcategory of the potential impact in any of the following main categories: !! National interest !! Entity activities !! Health or safety of individuals !! Environmental resources. Step 3.b: Identify the impact level The second stage implies that the Business Data Executive must assign to each potential impact a level of impact depending on the following: !! The impact duration and the difficulty to control the damage; !! The time to recover and repair the damage after its occurrence; and !! The size of the impact (on a national or regional level, several entities, single entity, multiple individuals, etc.) These parameters define the four levels of impact: !! High Impact: Access to or disclosure of such data shall cause extremely grave or serious long-term damages that cannot be recovered or rectified. !! Medium Impact: Access to or disclosure of such data shall cause grave or serious long-term damages that are difficult to control. Public !! Low Impact: Access to or disclosure of such data shall cause limited or intermittent short-term damages that can be controlled. !! No Impact: Access to or disclosure of such data is unlikely to cause any long- or short-term damage. All potential risks identified throughout the impact assessment process shall be specific and evidence-based, in an attempt to limit the subjectivity of the person classifying the data . Based on the identified impacts and their levels, the Business Data Executive shall determine the data classification level: !! High Impact: data shall be classified as “Top Secret.” !! Medium Impact: data shall be classified as “Secret” !! Low Impact: further assessments need to be conducted (please refer to Steps 4 and 5) !! No Impact: data shall be classified as “Public” A detailed description of the key considerations for each impact category and level is outlined in Table 2 “Data Classification Impact Assessment Categories and Levels”. Steps 4 and 5 must be taken into consideration whenever the impact level identified is Low. Go to step 6 if data has been classified as “Top Secret”, “Secret” or “Public.” Public

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.