الإطار التنظيمي للأمن السيبراني لمؤسسة النقد العربي السعودي

ساري

آخر تحديث إخلاء المسؤولية

المعلومات الأساسية

نوع الوثيقة
تنظيم/هيكلة
القطاعات
تقنية المعلومات والأمن السيبراني، المالية والضرائب

النطاق

يسري هذا الإطار التنظيمي على جميع المؤسسات المالية الخاضعة لرقابة مؤسسة النقد العربي السعودي، وتشمل: البنوك، وشركات التأمين وإعادة التأمين، وشركات التمويل، ومكاتب الائتمان، وبنية السوق المالية. ويطبق على أصول المعلومات الإلكترونية والمادية والبنية التحتية التقنية.

الإلزامات

تلتزم المؤسسات الأعضاء الخاضعة لرقابة مؤسسة النقد العربي السعودي بتبني الإطار التنظيمي وتنفيذ مبادئه وأهدافه واعتباراته الرقابية. ويشمل ذلك تحقيق مستوى نضج لا يقل عن المستوى الثالث، وإجراء تقييم ذاتي دوري، والامتثال لجميع المجالات الرقابية الأربعة (القيادة والحوكمة، إدارة المخاطر والامتثال، العمليات والتقنية، طرف ثالث). وفي حال تعذر تطبيق ضابط معين، يجب اللجوء إلى ضوابط تعويضية أو طلب إعفاء رسمي من مؤسسة النقد.

ملخص الأحكام

يُعد الإطار التنظيمي للأمن السيبراني الصادر عن مؤسسة النقد العربي السعودي وثيقة الزامية تهدف إلى حماية أصول المعلومات والخدمات الإلكترونية في القطاع المالي. ويشتمل على أربعة مجالات رئيسية هي: قيادة وحوكمة الأمن السيبراني، وإدارة مخاطر الأمن السيبراني والامتثال، وعمليات وتقنية الأمن السيبراني، وأمن الطرف الثالث. ويحدد لكل مجال فرعي مبدأ وهدفاً واعتبارات رقابية مرقمة. ويعتمد الإطار نموذج نضج يضم ستة مستويات، على أن تلتزم المؤسسات الأعضاء بتحقيق المستوى الثالث على الأقل. كما ينص على إجراء تقييم ذاتي دوري ومراجعة من قبل مؤسسة النقد، ويوفر آليات لطلب تحديث الإطار أو الإعفاء من بعض أحكامه بعد موافقة رسمية.

محتويات النظام36 قسمًا

Introduction to the Framework

1 Introduction

1.1 Introduction to the Framework

The current digital society has high expectations of flawless customer experience, continuous availability of services and effective protection of sensitive data. Information assets and online services are now strategically important to all public and private organizations, as well as to broader society. These services are vital to the creation of a vibrant digital economy. They are also becoming systemically important to the economy and to broader national security. All of which underlines the need to safeguard sensitive data and

Responsibilities and Reading Guide

1.2 Definition of Cyber Security

Cyber security is defined as the collection of tools, policies, security concepts, security safeguards, guidelines, risk management approaches, actions, training, best practices, assurance, and technologies that can be used to protect the member organization's information assets against internal and external threats.

The general security objectives comprise the following:

- Confidentiality – Information assets are accessible only to those authorized to have access (i.e., protected from unauthorized disclosure or (un)intended leakage of sensitive data).

Framework Structure and Features

2.1 Structure

The Framework is structured around four main domains, namely:

- Cyber Security Leadership and Governance. - Cyber Security Risk Management and Compliance. - Cyber Security Operations and Technology. - Third Party Cyber Security.

For each domain, several subdomains are defined. A subdomain focuses on a specific cyber security topic. Per subdomain, the Framework states a principle, objective and control considerations.

- A principle summarizes the main set of required cyber security controls related to the subdomain. - The objective describes the purpose of the principle

سجّل مجاناً لعرض النص كاملاً

٣٣ قسماً إضافياً بانتظارك — افتح حسابك المجاني واعرض المصدر

الإطار التنظيمي للأمن السيبراني لمؤسسة النقد العربي السعودي — ملخصه ومواده | ريحان