Information Technology Governance Framework
Para. 3.1.2Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Information Technology Strategy Principle An IT strategy should be defined in alignment with the Member Organization's strategic objectives and in compliance with legal and regulatory requirements. Control Requirements 1. IT strategy should be defined, approved, maintained and executed. 2. IT strategic initiatives should be translated into defined roadmap considering the following: a. the initiatives should require closing the gaps between current and target environments; b. the initiatives should be integrated into a coherent IT strategy that aligns with the business strategy; c. the initiatives should address the external ecosystem (enterprise partners, suppliers, start-ups, etc.); and d. should include determining dependencies, overlaps, synergies and impacts among projects, and prioritization. 3. IT strategy should be aligned with: a. the Member Organization's overall business objectives; and b. legal and regulatory compliance requirements of the Member Organization. 4. IT strategy at minimum should address: a. the importance and benefits of IT for the Member Organization; b. the current business and IT environment, the future direction, and the initiatives required to migrate to the future state environment; and c. interdependencies of the critical information assets. 5. Member organization should identify IT strategic and emerging technology risks that may have impact on the achievement of overall organization wide strategic objectives. 6. Member organization should enhance skill sets and expertise (operational and technical) of the existing resources through providing periodic training on emerging technologies and if required to have the relevant resources on boarded in line with member organization direction towards digitalization. 7. IT strategy should be reviewed and updated periodically or upon material change in the Member Organizations operational environment, change in business strategy, objectives or amendment in laws & regulations. 3.1.3 Manage Enterprise Architecture Principle Enterprise architecture should be defined which outlines fundamental components of the business processes, data and supporting technology layers to ensure responsive and efficient delivery of Member organizations IT strategic objectives. Control Requirements 1. The enterprise architecture should be defined, approved and implemented. 2. The compliance with the enterprise architecture should be monitored. 3. The enterprise architecture should address the following, but not limited to: a. a strategic outline of organizations technology capabilities; b. outline the gaps between baseline and target architectures, taking both business and technical perspectives; and c. agility to meet changing business needs in an effective and efficient manner. 3.1.4 Information Technology Policy and Procedures Principle IT policy and procedures should be defined, approved, communicated and implemented to set member organizations commitment and objectives to IT and communicated to the relevant stakeholders. Control Requirements 1. IT policy and procedures should be defined, approved, communicated, and implemented. 2. IT policy and procedures should be reviewed periodically taking into consideration the evolving technology landscape. 3. IT Policy should be developed considering input from relevant member organizations policies (e.g. cyber security, finance, HR). 4. IT Policy should include: a. the Member Organization's overall IT objectives and scope; b. a statement of the board's intent, supporting the IT objectives; c. a definition of general and specific responsibilities for IT; and d. the reference to supporting IT (inter)national standards and process (where applicable).
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded