Alqanoni

Information Technology Governance Framework

Para. 3.4.5
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Testing Principle All changes to information systems should be comprehensively tested on the test environment based on the defined and approved test cases to ensure that changes meets the business requirements as well as to identify defects or vulnerabilities before releasing changes to the production environment. Control Requirements 1. Test plan should be formally defined, approved and documented for the changes. 2. Test case should be defined, approved and documented for the changes. In addition, test case should address the following, but not limited to: a. test case name and unique ID; b. test case designed by and tested by; c. test case description with clear identification of negative and positive test cases; d. test priority; e. date of the test execution; f. data use to test the cases; g. status of the test case (i.e. pass or fail); h. expected outcome of the test case; and i. third party testing certification requirement, if applicable, i.e. MADA, Tanfeeth, etc. 3. At a minimum, the following types of testing should be considered as part of system change management. a. unit testing; b. system integration testing (SIT); c. stress testing (if applicable); d. security testing; and e. user acceptance testing (UAT). 4. All changes to information system should be thoroughly tested on a separate test environment in accordance with the approved test cases. 5. All changes should be formally tested and accepted by the concern business users. 6. Testing should include positive and negative test cases scenarios. 7. The results of UAT should be documented and maintained for future reference purposes. 8. The production data should not be utilized for system testing in the test environment. Only sanitized data should be used for testing purposes. 3.4.6 Change Security Requirements Principle Cyber security requirements should be defined and thoroughly tested for all changes in the information system in a testing environment in order to identify and mitigate security vulnerabilities therein prior introducing them into the production environment. Control Requirements 1. System change management process should consider SAMA Cyber Security Framework for defining, testing and implementing security requirements for any changes in the information assets. 3.4.7 Change Release Management Principle Change release management process should be defined to ensure that system changes are adequately planned and released to the production environment in a strictly controlled manner. Control Requirements 1. The release management process should be defined, approved, implemented and communicated. 2. The release management process should be monitored and periodically evaluated. 3. The release management process should address the following, but not limited to: a. change release strategy and approach; b. roles and responsibilities to carry out change releases; c. change release schedule and logistics; d. change roll-out and roll-back procedures; and e. data migration, where applicable. 4. The changes should be released in the corresponding system in disaster recovery site upon successful implementation of changes in the production environment at main site. 5. Change should be introduced as part of an agreed change window, exceptions has to have their own approval process and seldom allowed without compelling reasons.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.