Information Technology Governance Framework
Para. 3.3.4Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
IT Availability and Capacity Management Principle Service availability should be maintained to support member organizations business functions and to avoid disruption and slowness of systems performance through monitoring current system thresholds and prediction of future performance and capacity requirements. Control Requirements 1. The IT availability and capacity management process should be defined, approved and implemented. 2. The effectiveness of the IT availability and capacity management process should be monitored, measured and periodically evaluated. 3. IT availability and capacity plan should be developed, approved and periodically evaluated. 4. IT availability and capacity plan should be defined to address the following, but not limited to: a. existing capacity of systems and resources; b. alignment with the current and future business needs; c. high availability requirements (including disruption and slowness for customer channels); d. roles and responsibilities to maintain the plan; and e. identification of dependencies over service providers as part of capacity planning to address BCM requirements. 5. System performance thresholds should be defined and implemented. 6. System performance should be monitored considering the following, but not limited to: a. current and future business requirement; b. the agreed upon SLA with the business; c. critical IT infrastructures; d. disruption and slowness in the underlying system(s) supporting customer channels; and e. lessons learned from previous system performance issues. 7. Deviations from established capacity and performance baselines/thresholds should be identified, documented, followed-up, and reported to the management and ITSC. 3.3.5 Manage Data Center Principle Adequate physical controls are designed and implemented to protect IT facilities and equipment from damage and unauthorized access. Control Requirements 1. Physical and environmental controls for managing the data center should be defined, approved and implemented. 2. Physical and environmental controls should be monitored and periodically evaluated. 3. Necessary physical and environmental controls should be implemented such as but not limited to: a. access to the data center should be strictly controlled and provided on need to know basis; b. visitors entry to data center should be logged and escorted by an authorized person; c. smoke detectors; d. fire alarms; e. fire extinguishers; f. humidity control; g. temperature monitoring; and h. CCTV. 4. The outsourcing of data center should comply with the requirements published in SAMA circulars on the Rules of The Outsourcing and Cybersecurity Framework . 5. Member Organizations should ensure that appropriate control measures are built into contracts with the service providers to whom they plan to outsource data center such as but not limited to: a. have documented business case for outsourcing data center services; and b. nature and type of access to data center by the service provider.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded