Alqanoni

Information Technology Governance Framework

Para. 1.8
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Review, Updates and Maintenance SAMA will review the Framework periodically to determine the Framework's effectiveness, including the effectiveness of the Framework to address emerging IT threats and risks. If applicable, SAMA will update the Framework based on the outcome of the review. If a Member Organization considers that an update to the framework is required, the Member Organization should formally submit the requested update to SAMA. SAMA will review the requested update, and when applicable, the Framework will be adjusted on the next updated version. The Member Organization will remain responsible to be compliant with the framework pending the next version update. Please refer to ' Appendix A - How to request an Update to the Framework ' for the process of requesting an update to the Framework. Version control will be implemented for maintaining the framework. Whenever any changes are made, the preceding version shall be retired and the new version shall be published and communicated to all Member Organizations. For the convenience of the Member Organizations, changes to the framework shall be clearly indicated. 1.9 Reading Guide The Framework is structured as follows. Chapter 2 elaborates on the structure of the Framework, and provides instructions on how to apply the Framework. Chapter 3 presents the actual framework, including the IT domains and subdomains, principles, objectives and Control Requirements. 2. Framework Structure and Features 2.1 Structure The Framework is structured around four main domains, namely: Information Technology Governance and Leadership. Information Technology Risk Management. Information Technology Operations Management. System Change Management. For each domain, several subdomains are defined. A subdomain focusses on a specific IT governance topic. Per subdomain, the Framework states a principle and Control Requirements. A Principle summarizes the main set of required IT controls related to the subdomain. The Control Requirements reflects the mandated IT controls that should be considered. The framework should be implemented in view of principles mentioned in per subdomains along with its associated Control Requirements. Control Requirements have been uniquely numbered according to the following numbering system throughout the Framework: Figure 2 - Control requirements numbering system The figure below illustrates the overall structure of the Framework and indicates the IT Governance Framework domains and subdomains, including a reference to the applicable section of the Framework. Figure 3 - Information Technology Governance Framework 2.2 Principle-Based The framework is principle based, also referred to as risk based. This means that it prescribes key IT governance principles and objectives to be embedded and achieved by the Member Organizations. The list of mandated Control Requirements provides additional direction and should be considered by the Member Organizations in achieving the objectives. When a certain control requirement cannot be tailored or implemented, the Member Organizations should consider applying compensating controls, pursuing an internal risk acceptance and requesting a formal waiver from SAMA. Please refer to Appendix D for details for the - How to request Waiver from the Framework - process . 2.3 Self-Assessment, Review and Audit The implementation of the framework at the Member Organizations will be subject to a periodic self-assessment. The self-assessment will be performed by the Member Organizations based on a questionnaire. The self-assessments will be reviewed and audited by Saudi Central Bank to determine the level of compliance with the framework and the IT maturity level of the Member Organizations. Please refer to ‘ 2.4 Information Technology Governance Maturity Model ' for more details about the information technology governance maturity model.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.