Sorry, you need to enable JavaScript to visit this website.
Skip to main content

Email Security Policy

 

General Provisions

  • The cybersecurity requirements for protecting King Saud University’s email services shall be defined, implemented, documented, and formally approved.
  • Modern technologies shall be deployed to protect email services, analyze and filter email messages, and block suspicious messages, including spam emails and phishing emails.
  • Multi-Factor Authentication (MFA) shall be implemented, with the appropriate authentication factors, number of factors, and authentication technologies determined based on the results of an impact assessment of potential authentication failure or bypass. This requirement shall apply to remote access and access through the Webmail interface.
  • Email messages shall be archived and backed up periodically.
  • Advanced Persistent Threat (APT) protection mechanisms shall be implemented and securely managed to protect against threats that commonly employ previously unknown viruses and malware, including Zero-Day Malware.
  • King Saud University’s email domain shall be authenticated using appropriate mechanisms, such as the Sender Policy Framework (SPF), to prevent Email Spoofing. The authenticity of incoming email domains shall also be verified through Domain-based Message Authentication, Reporting, and Conformance (DMARC).
  • Emails sent outside King Saud University shall include an appropriate disclaimer notice in the email footer.
  • King Saud University reserves the right to disclose the contents of email messages upon obtaining the necessary authorization from the relevant authority and the Cybersecurity Department, in accordance with applicable procedures and regulations.
  • Individual email accounts shall be used exclusively by the person to whom the account has been assigned.
  • University-provided email accounts shall be used by King Saud University personnel. University email accounts shall not be used to register for websites or services unrelated to official work purposes or for personal use.
  • All King Saud University users shall use their university-provided email accounts and compose email content in accordance with the requirements set forth in the Acceptable Use Policy for Information Assets.
  • Email users shall not send, receive, or store any data or information classified as “Confidential” or “Highly Confidential”, in accordance with the University’s Data Classification Policy issued by the University Data Management Office, through email, whether such information is in the form of text, correspondence, documents, or attachments, either internally or with external entities.
  • All email messages shall comply with applicable standards of professional conduct, etiquette, and appropriate content. Content restrictions include, but are not limited to, the following:
  • King Saud University email shall not be used to send or receive data containing offensive, defamatory, or threatening material directed at others.
  • King Saud University email shall not be used to transmit data, messages, or images containing pornographic material, racial slurs, racist content, or any material that may reasonably be interpreted as harassment, insult, or offense to others.
  • Email accounts of employees whose employment has been terminated shall be disabled immediately and permanently deleted after six months.
  • Email accounts of faculty members who resign shall be disabled six months after their resignation.
  • Faculty members’ email accounts shall be retained indefinitely after retirement, with a maximum storage capacity of 2 GB.
  • Automatic or manual forwarding of King Saud University email messages to users’ personal email accounts, such as Gmail, Hotmail, or similar services, is strictly prohibited.
  • King Saud University’s cybersecurity requirements for protecting email services shall be reviewed periodically.
  • Key Performance Indicators (KPIs) shall be used to ensure the continuous improvement of the email management system.

Email Content Classification

In accordance with the relevant provisions of this Policy, the email content of the University’s employees and faculty members shall be classified as Restricted Data and shall be subject to the approved controls and requirements for protecting this category of data.

Email Security

  • All King Saud University email accounts shall be protected using strong and complex passwords in accordance with the University’s Password Policy.
  • King Saud University’s web-based email service shall be protected through Two-Factor Authentication (2FA), in addition to a strong password policy.
  • To maintain the security of King Saud University’s email system, access to the system shall be appropriately controlled. Users shall not provide their email usernames or passwords to any unauthorized individuals.
  • Users shall not open attachments received from unknown or untrusted sources. All email attachments, regardless of their source or content, shall be scanned for viruses and other malware before being opened or stored on any system.
  • Users shall not respond to emails or pop-up advertisements requesting personal or financial information.
  • Users shall forward suspected phishing emails to spam@ksu.edu.sa.
  • Appropriate technologies, such as Data Loss Prevention (DLP), shall be implemented to protect data against leakage through email, both within and outside King Saud University.
  • Owners of generic and shared email accounts (Generic Accounts) and their respective responsibilities shall be identified and documented.
  • The Open Mail Relay service shall be disabled.
  • The use of email services for Privileged Accounts is prohibited.
  • Communication between email servers and Email Gateways shall be encrypted to protect against Man-in-the-Middle (MitM) attacks.
  • Users shall perform a malware scan on all materials to be sent to other users through King Saud University’s email system before transmission.
  • Email attachments exceeding 35 MB shall be restricted. Non-work-related emails containing large file attachments, such as graphics and multimedia files, should not be sent through King Saud University’s email systems.
  • The maximum size of an individual incoming email message shall be 30 MB.
  • The maximum mailbox capacity for faculty members shall be 10 GB. Users shall receive a notification upon reaching 9 GB. Sending functionality shall be suspended when the storage limit is exceeded until the mailbox size is reduced, while incoming email reception shall remain available.
  • The maximum mailbox capacity for employees shall be 2 GB. Users shall receive a notification upon reaching 1.9 GB. Sending functionality shall be suspended when the storage limit is exceeded until the mailbox size is reduced, while incoming email reception shall remain available.
Last updated on : August 26, 2026 8:32am