Alqanoni

Information Technology Governance Framework

Para. 3.1.7
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Internal IT Audit Principle IT Audit should be conducted in accordance with generally accepted auditing standards and relevant SAMA framework (s) to verify that the IT control design is adequately implemented and operating as intended. Control Requirements 1. IT audits should be performed independently and according to generally accepted auditing standards and relevant SAMA frameworks. 2. The Member Organizations should establish an audit cycle that determines the frequency of IT audits. 3. Member Organizations should develop formal IT audit plan addressing people, process and technology components. 4. IT audit plan should be approved by the Member Organization's audit committee. 5. The frequency of IT audit should be aligned with the criticality and risk of the IT system or process. 6. A follow-up process for IT audit observations should be established to track and monitor IT audit observations. 7. Member Organizations should ensure that the IT auditors have the requisite level of competencies and skills to effectively assess and evaluate the adequacy of IT policies, procedures, processes and controls implemented. 8. IT audit report, at a minimum, should: a. include the findings, recommendations, management's response with defined action plan, and responsible party and limitations in scope with respect to the IT audits; b. signed, dated and distributed according to the format defined; and c. submitted to the audit committee on periodical basis. 3.1.8 Staff Competence and Training Principle Staff of the Member Organizations should be equipped with the skills and required knowledge to operate the Member Organization's information assets in a controlled manner and provided with training regarding how to operate, address and apply IT relevant controls on Member Organization's information assets. Control Requirements 1. Member Organizations should identify and define critical roles within IT department (e.g. DBA, sysadmin, etc.) 2. Member Organizations should ensure adequate staffing for critical IT roles, such that critical IT roles are not handled by only one staff. 3. Member Organizations should identify the professional certifications required for staff responsible for critical IT roles. 4. Member Organizations should evaluate staffing requirements on periodic basis or upon major changes to the business, operational or IT environments to ensure that the IT function has sufficient resources. 5. Annual IT training plan should be developed by the Member Organizations. 6. Formal training should be conducted, as a minimum for: a. IT staff (existing and new); and b. Contractors (where applicable). 7. IT training plan should be reviewed periodically. 8. Specialist training should be provided to staff in the Member Organization's relevant functional area categories in line with their job descriptions, including: a. staff involved in performing critical IT roles; b. staff involved in developing and (technically) maintaining information assets; and c. staff involved in risk assessments. 3.1.9 Performance Management Principle Efficiency and effectiveness of IT processes and services of the Member Organizations should be continuously measured through key performance indicators (KPIs). Control Requirements 1. KPIs should be defined, approved and implemented to measure the execution of IT processes and system performance. 2. KPIs should be defined considering for the following, but not limited to: a. IT function and related processes; b. workforce competency and development; and c. compliance with regulatory regulations. 3. KPIs should be: a. communicated to the concerned IT Divisions/Units of the Member Organizations for implementation; b. supported by target value and thresholds; c. analyzed to identify the deviations against targets and initiate remedial actions; d. analyzed to identify trends in performance and compliance and take appropriate action; and e. monitored and periodically reported to the senior management and ITSC.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.