Information Technology Governance Framework
Para. 3.3Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Operations Management IT Operations Management can be defined as the function responsible for continues management and maintenance of the Members Organization's IT applications and infrastructure to ensure delivery of the agreed level of IT services to the business. Thus, IT operations risk factors should be addressed by the Member Organizations through effective management and control. 3.3.1 Manage Assets Principle Asset Management process should be established to provide visibility of the Member Organization's information assets by maintaining an accurate and up-to-date inventory. Control Requirements 1. The asset management process should be defined, approved, implemented and communicated. 2. The effectiveness of the asset management process should be monitored, measured and periodically evaluated. 3. The asset management process should include but not limited to: a. asset onboarding; b. asset identification, classification, labeling and handling; c. asset disposal; and d. asset decommissioning. 4. Asset register should provide with the level of details, including (but not limited): a. asset name; b. asset owner; c. asset custodian; asset criticality; d. asset physical location; e. asset logical location (network zone); f. asset identified as direct in-scope of PCI; g. asset identified as indirect in-scope of PCI; h. availability or backup information; i. service contract or license information; j. technical contacts (OS, Application, Database and Network); k. primary and secondary processes supported by the asset; l. acceptable downtime aligned with BCM - Business Impact Analysis where applicable; m. financial impact per hour in the event of downtime; n. vendor engagement contract number; o. vendor point of contact details; p. vendor SLA details; and q. vendor classification details. 5. Asset register should be maintained and updated on yearly basis, or whenever any asset introduced or removed from inventory. 6. Member organizations should: a. define criteria for the identification of critical assets; b. identify, maintain and periodically update comprehensive list of critical assets; c. proactively monitor performance of critical assets; and d. ensure adequate resilience measures in place for critical assets to maintain availability of the required critical services. 7. Asset owner should be responsible for, but not limited to: a. classification and labeling of asset; b. defining and reviewing access rights, restrictions, and taking into account applicable access control policies of the Member Organizations; c. authorizing changes related to assets; and d. ensure alignment with cyber security controls. 8. Assets should be disposed of in a controlled and secure manner upon completion of its useful life and when other relevant obligations are met. 3.3.2 Interdependencies Principle Interdependencies for critical information assets should be identified and managed through governance model to ensure availability of business operations. Control Requirements 1. Member Organizations should define and implement robust governance model in light of their interdependencies with relevant stakeholders (e.g. service providers, government institutions, etc.) 2. Member Organizations should identify its critical information assets interdependencies. 3. As part of the (BCP) testing, the Member Organizations should take into consideration the interdependencies of critical information assets scenarios within its infrastructure. Note: For more Control Requirements to improve the overall resilience, please refer to the SAMA - BCM Framework .
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded