DataClassificationPolicy
Para. 1.5Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
Data Classification Process
Step 1: Identify all data of the entity
The first step to be taken by an entity is to prepare an inventory of all
the data owned by such entity.
Step 2: Appoint Responsible of Performing data classification
Upon completion of a data inventory, the Entity shall assign the
responsibility for performing the classification to a particular person, usually
the Business Data Executive, who is an employee of the entity’s office and
who best understands the data and its value. This person shall be responsible
for making the initial classification. As there could be several Business Data
Executives within the Entity, there could be more than one classifier.
Step 3: Conduct impact assessment process
The Business Data Executive shall follow the steps required for an
assessment of the potential impact arising from:
!! The disclosure of or unauthorized access to such data;
!! Amendment and/or destruction of such data;
!! Lack of access to such data in a timely manner.
The impact assessment process shall be initiated with the application of
the ‘Open by Default’ principle (in the Development sector) unless its nature
Public
or sensitivity requires higher levels of classification and protection; and the
Top-Secret classification (in the political and security sectors) unless its
nature or sensitivity requires lower levels of classification.
Step 3.a: Identify the impact category
The first stage of the impact assessment process is to identify the main
and subcategory of the potential impact in any of the following main
categories:
!! National interest
!! Entity activities
!! Health or safety of individuals
!! Environmental resources.
Step 3.b: Identify the impact level
The second stage implies that the Business Data Executive must assign
to each potential impact a level of impact depending on the following:
!! The impact duration and the difficulty to control the damage;
!! The time to recover and repair the damage after its occurrence; and
!! The size of the impact (on a national or regional level, several entities,
single entity, multiple individuals, etc.)
These parameters define the four levels of impact:
!! High Impact: Access to or disclosure of such data shall cause
extremely grave or serious long-term damages that cannot be
recovered or rectified.
!! Medium Impact: Access to or disclosure of such data shall cause
grave or serious long-term damages that are difficult to control.
Public
!! Low Impact: Access to or disclosure of such data shall cause limited or
intermittent short-term damages that can be controlled.
!! No Impact: Access to or disclosure of such data is unlikely to cause
any long- or short-term damage.
All potential risks identified throughout the impact assessment process shall
be specific and evidence-based, in an attempt to limit the subjectivity of the
person classifying the data .
Based on the identified impacts and their levels, the Business Data Executive
shall determine the data classification level:
!! High Impact: data shall be classified as “Top Secret.”
!! Medium Impact: data shall be classified as “Secret”
!! Low Impact: further assessments need to be conducted (please refer to
Steps 4 and 5)
!! No Impact: data shall be classified as “Public”
A detailed description of the key considerations for each impact category and
level is outlined in Table 2 “Data Classification Impact Assessment Categories
and Levels”.
Steps 4 and 5 must be taken into consideration whenever the impact
level identified is Low.
Go to step 6 if data has been classified as “Top Secret”, “Secret” or
“Public.”
Public
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded