Sorry, you need to enable JavaScript to visit this website.
Skip to main content

Encryption Policy

 

1. General Requirements

  • King Saud University must develop, document, and approve specific encryption procedures and standards based on business requirements and the cybersecurity risk assessment conducted by King Saud University. The applicable security level must be aligned with the National Encryption Standards issued by the National Cybersecurity Authority (NCA). These procedures must include approved encryption solutions and the technical and organizational restrictions applicable to them, methods of use, key generation, distribution, and recovery mechanisms, as well as key backup management and procedures for the secure destruction of encryption keys.
  • Data must be encrypted both in transit and at rest based on its classification, in accordance with King Saud University’s policies and procedures and the applicable legislative and regulatory requirements.
  • Up-to-date encryption methods, algorithms, keys, and cryptographic devices must be used in accordance with the requirements and guidelines issued by the National Cybersecurity Authority (NCA) in this regard.
  • All data of critical systems must be encrypted while in transit (Data-in-Transit).
  • All data of critical systems must be encrypted while at rest (Data-at-Rest) at the file level, database level, or at the level of specific columns within the database.
  • The roles and responsibilities related to the Key Management Infrastructure (KMI) within the Deanship of Electronic Transactions and Communications must be defined and documented, including, at a minimum, the following roles:
    • Keying Material Manager, who serves as the manager of the relevant cybersecurity function.
    • Key Custodians, who are responsible for protecting encryption keys.
    • Certification Authorities (CAs), which must be trusted and secure.
    • Registration Authorities (RAs), which must be trusted and secure.
  • Key Performance Indicators (KPIs) must be used to ensure the continuous improvement and proper and effective use of encryption.

 

Last updated on : August 26, 2026 8:32am