Alqanoni

Information Technology Governance Framework

Para. 3.4.11
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Quality Assurance Principle The quality assurance process should be defined, approved, communicated and implemented to independently ascertain quality of the changes or development in the information assets in line with the business/user requirements prior moving them to the production environment. Control Requirements 1. The quality assurance process should be defined, approved, implemented and communicated by the Member Organizations. 2. The quality assurance process should be monitored and periodically evaluated. 3. The quality assurance process should address the following, but not limited to: a. clear roles and responsibilities for personnel carrying out quality assurance activities; b. minimum quality requirements sets by the Member Organizations including business and any other applicable regulatory requirements; and c. process for identification, maintenance and retirement of quality related records. 4. The quality assurance function/department should have independent existence and reporting with authority to provide objective evaluation. 5. All changes or development to information system should be assessed by the quality assurance team prior releasing to the production environment. 6. The quality assurance function should report the reviewed results to the relevant stakeholder(s) within the Member Organizations and initiate improvements where appropriate. Appendices Appendix A - How to Request an Update to the Framework Below the illustration of the process for requesting an update to the Framework. Detail information supported by pros and cons about the suggested update. The request should first be approved by CIO before submitting to IT steering committee. The request should be approved by Member Organization's IT steering committee. The request should be sent formally in writing to the manager 'General Department of Cyber Risk Control' via the Member Organization's CEO or managing director. 'General Department of Cyber Risk Control' will evaluate the request and informs the Member Organization. The current Framework remains applicable while the requested update is being considered, processed and if applicable is approved and processed. Appendix B - Framework Update Request Form Request to Update the IT Governance Framework A submission to the manager of SAMA MA General Department of Cyber Risk Control. The Saudi Arabia Monetary Authority (SAMA) will consider requests from a member organization (MO) to update its IT Governance Framework based on the information submitted using the form below. A separate form must be completed for each requested update. Please note that all required fields must be properly filled in before SAMA will begin the review process Requestor Information REQUESTOR'S SIGNATURE* x REQUESTOR'S POSITION* DATE* REQUESTOR'S NAME* MEMBER ORGANIZATION OF REQUESTOR* FRAMEWORK SECTION*: PURPOSE OF REQUESTED UPDATE (including detailed information on its pros and cons)*: PROPOSAL*: Approvals 1. MO'S CIO APPROVAL* DATE* 2. MO'S IT STEERING COMMITTEE APPROVAL* APPROVER'S POSITION* DATE* 3 SAMA DECISION SAMA APPROVAL DATE * Denotes required fields Appendix C - How to Request 2 Waiver from the Framework Below the illustration of the process for requesting a waiver from the Framework. Detail description about the reasons that the member organization could not meet the required control. Details description about the available or suggested compensating controls. The waiver request should first be approved by CIO before submitting to IT steering committee. The waiver request should approved by the members of Member Organization's IT steering committee. The waiver request should be signed by the CIO and relevant (business) owner. The waiver request should be formally issued in writing to the manager of 'General Department of Cyber Risk Control' via the Member Organization's CEO or managing director. ‘General Department of Cyber Risk Control' will evaluate the waiver request and informs the Member Organization. T

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.