Sorry, you need to enable JavaScript to visit this website.
Skip to main content

Systems and Information Processing Devices Protection Policy

 

1. General Requirements

  • King Saud University (KSU) shall identify, provide, and verify the reliability of modern and advanced protection technologies and mechanisms.
  • Protection technologies and mechanisms shall be implemented to protect user devices, mobile devices, and servers against malware and shall be securely managed.
  • Protection technologies and mechanisms shall be capable of detecting and removing all known types of malware, including viruses, Trojan horses, worms, spyware, adware, and rootkits.
  • Prior to selecting protection technologies and mechanisms, their compatibility with the operating systems used by the University, such as Windows, UNIX, Linux, macOS, and other operating systems, shall be verified.
  • If an update to protection technologies causes adverse effects on systems or business requirements, the protection technologies shall support rollback to the previous version.
  • The authority to disable, uninstall, or modify the configuration of anti-malware protection technologies shall be strictly restricted to authorized security system administrators.
  • The use of storage media devices, such as USB drives and CDs, shall be strictly restricted across all KSU information and technology assets.
  • Security updates and patches for the University's social media applications shall be applied at least once every month.
  • The security configuration and hardening of KSU social media accounts and their associated technology assets shall be reviewed at least once every year.
  • Default configurations of social media accounts and technology assets shall be reviewed and hardened, including the removal or modification of hard-coded passwords, pre-configured login credentials, and default lockout settings.
  • The activation of features and services in social media accounts shall be restricted based on business and operational needs. Any requirement to activate such features or services shall be subject to an assessment of the potential cybersecurity risks.
  • Security updates and patches shall be applied to systems used to process data from the time they are released, in accordance with the timeframe specified for each level at KSU.
  • The security configuration and hardening of systems used to process data shall be reviewed in accordance with the timeframe specified for each level at KSU.
  • Default configurations, such as hard-coded passwords and default backgrounds, of technology assets used to process data shall be reviewed and hardened.
  • All KSU users shall use standard applications and software products approved and licensed by KSU. All University users shall comply with the following requirements when installing any application or software product on their devices, including, but not limited to, servers:
    • Users shall not install any unauthorized software, application, script, or executable code on their devices.
    • Users shall install only software that has been approved and licensed by KSU.
    • Software obtained from external sources shall not be installed without prior approval from the relevant authorized department.
  • Controls shall be implemented over software installation on operating systems. To minimize the risk of operating system disruption, the following controls shall be observed:
    • Operational software libraries shall be updated only upon obtaining appropriate authorization from the relevant department.
    • Operating systems shall contain only authorized executable code.
    • Executable code shall not be executed on operating systems until evidence of successful testing and user acceptance has been obtained, and the corresponding source-code libraries have been updated.
    • An audit trail shall be maintained for all updates to operational software libraries and executable code.
    • Previous versions of software shall be retained as a contingency measure.
  • The authorized personnel responsible for vulnerability management shall ensure the following:
    • Security scanning tools shall be used on a defined and scheduled basis to identify vulnerabilities that could potentially be exploited by individuals conducting unauthorized scans using similar tools.
    • Multiple scanning tools employing different techniques shall be used to identify the maximum possible number of vulnerabilities.
    • Internet-facing and intranet-connected assets shall be scanned.
    • The asset owner shall be notified and shall acknowledge and accept the potential impact of the scanning activity on the target environment before the scan is initiated.
    • Third-party sources of technical vulnerability information, such as security alerts, system patches, workarounds, and antivirus updates, shall be monitored to determine their relevance to KSU, particularly where vulnerabilities are reported by third-party sources.
    • Vulnerability management responsibilities shall include comparing each identified vulnerability against the University's asset inventory to determine whether any KSU information technology resources are exposed or vulnerable.
    • When a vendor releases a security patch to address a security-related control or vulnerability, the release of such a patch shall be considered an implicit notification of the existence of a security vulnerability, and appropriate risk mitigation measures shall be taken.
    • All identified vulnerabilities affecting authorized devices connected to the KSU network, as well as operating systems and applications with known security vulnerabilities, shall be addressed in a timely manner to remediate known vulnerabilities.
    • If a vulnerability affecting a network-connected device cannot be remediated, the vulnerability shall be mitigated through an approved and acceptable compensating security control.

2. Cybersecurity Requirements for Protecting Critical and Sensitive Systems and Information Processing Devices

  • KSU shall allow only a defined whitelist of executable files, applications, and software to operate on servers hosting sensitive systems.
  • Servers hosting sensitive systems at KSU shall be protected using endpoint protection technologies approved by KSU.
  • Security updates and patches shall be applied at least once a month to external sensitive systems connected to the Internet and at least once every three months to internal sensitive systems, in accordance with KSU-approved change management procedures.
  • KSU shall allocate dedicated workstations for personnel performing technical functions with critical and sensitive privileges. Such workstations shall be isolated within a dedicated Management Network and shall not be connected to any other network or service, such as email or the Internet.
  • Any non-console administrative access over the network to technical components of sensitive systems shall be encrypted using secure encryption algorithms and protocols.
  • The security configuration and hardening of KSU sensitive systems shall be reviewed at least once every six months.
  • Default configurations shall be reviewed and modified to ensure that hard-coded, backdoor, and default passwords are not present.
  • Sensitive logs and files of the University's systems shall be protected against unauthorized access, tampering, alteration, or unlawful deletion.

3. Cybersecurity Requirements for Protecting Remote Work Systems and Devices

  • King Saud University (KSU) shall apply security updates and patches to remote work systems at least once a month.
  • The security configuration and hardening of remote work systems shall be reviewed at least once a year.
  • The default configurations of the technology assets supporting remote work systems shall be reviewed and hardened, including the presence of hard-coded passwords and default configurations.
  • Secure session management shall be implemented, including session authenticity, lockout, and timeout.
  • The General Directorate of Cybersecurity at King Saud University shall restrict the activation of features and services in remote work systems based on business needs. Where activation is required, the potential cybersecurity risks shall be assessed.

4. Configuration of Anti-Malware Protection Technologies and Mechanisms

  • Protection technologies and mechanisms shall be configured in accordance with the University's approved technical security standards, taking into consideration the vendor's guidelines and recommendations.
  • Antivirus software on email servers shall be configured to scan all incoming and outgoing email messages.
  • Third-party personnel shall not be permitted to connect to the University's wired or wireless network unless their antivirus software is up to date and the appropriate security settings have been configured.
  • The availability of anti-malware protection servers shall be ensured. The backup environment for anti-malware protection servers supporting non-critical and non-sensitive operations shall also be appropriately configured and maintained.
  • Access to websites and other Internet resources known to host malware shall be blocked using Web Content Filtering mechanisms.
  • Clock synchronization shall be centrally managed using an accurate and trusted time source for all anti-malware protection technologies and mechanisms.
  • Anti-malware protection technologies shall be configured to perform analysis and verification of suspicious content within isolated environments, such as sandboxes.
  • Periodic scans shall be performed on user devices and servers to verify that they are free from malware.
  • Anti-malware protection technologies shall be automatically updated whenever new versions or updates are made available by the vendor, taking into consideration the University's patch and update management policy.
  • Email and Internet browsing protection technologies against Advanced Persistent Threats (APT) shall be provided, implemented, and securely managed. Such technologies shall address threats involving previously unknown malware, including Zero-Day Malware.
  • Protection technologies shall be configured to allow only a defined whitelist of executable files, applications, and software to operate on servers hosting sensitive systems (CSCC-2-3-1-1).
  • Servers hosting sensitive systems shall be protected using endpoint protection technologies approved by the University (CSCC-2-3-1-2).
  • Periodic reports on the status of anti-malware protection shall be prepared, indicating the number of devices and servers connected to the protection technologies and their current status, such as updated, outdated, disconnected, or otherwise unavailable. These reports shall be submitted to the relevant cybersecurity department.
  • Anti-malware protection technologies shall be centrally managed and continuously monitored.

5. Computer Configuration Requirements for Laboratory Facilities

  • All devices connected to the University's network shall be joined to the secure domain, particularly devices running operating systems approved by the University.
  • Support technicians responsible for laboratory facilities shall be granted the minimum level of administrative privileges required to perform their duties.
  • All servers and software used in laboratory facilities shall be hosted within the University's data center.
  • The ports required for the operation of designated applications between servers and devices shall be securely opened in accordance with the University's information security policies.

6. Information Systems Audit Considerations

  • Audit requirements and activities covering the verification of operating systems shall be carefully planned and performed periodically, at least annually, in coordination with the information asset owners, in order to minimize the risk of disruption to business operations.
  • Where system audits require access to systems or data, or involve the use of software tools and utilities, such audits shall be conducted with the knowledge, cooperation, and approval of the information asset owners. Appropriate precautions shall be taken to protect system information and data from damage, corruption, or disruption resulting from the audit activities or audit tools.
  • Periodically, and at least annually, one or more information security audits of King Saud University's information systems shall be conducted by an appropriately qualified and independent external audit firm.

 

Last updated on : August 26, 2026 8:32am