Sorry, you need to enable JavaScript to visit this website.
Skip to main content

Access Identity and Privilege Management Policy

1. General Requirements

  • Cybersecurity requirements for managing access identities and privileges at King Saud University (KSU) shall be defined, documented, and approved.
  • Cybersecurity requirements for managing access identities and privileges at King Saud University (KSU) shall be implemented.
  • The cybersecurity requirements for managing access identities and privileges at King Saud University (KSU) shall, at a minimum, cover the following:
    • User Authentication, based on user registration management and password management.
    • Multi-Factor Authentication (MFA) for remote access.
    • Management of user access permissions and privileges based on the principles of access control and authorization, including the Need-to-Know and Need-to-Use principles, the Principle of Least Privilege, and Segregation of Duties (SoD).
    • Privileged Access Management (PAM).
    • Annual review of access identities and privileges.
  • The implementation of cybersecurity requirements for managing access identities and privileges at King Saud University (KSU) shall be reviewed periodically.

2. Information Access Requirements

  • Access to information shall be controlled based on business and security requirements and the access control rules defined for each information system. These rules shall take into consideration the following:
    • Security requirements for the business application(s).
    • Specific business requirements for users to access information or perform operations, based on the “Need-to-Know” principle.
    • All access shall be denied by default unless explicitly authorized in accordance with the provisions of this policy.
    • Legal and/or contractual obligations to restrict and protect access to information systems.
  • Access by contractors, consultants, or third-party personnel to King Saud University’s business information assets shall be granted solely on the basis of a contractual agreement. Such agreement shall include, but not be limited to, the following:
    • Terms and conditions governing access.
    • Security responsibilities of contractors, consultants, or supplier personnel.
    • The contractors’, consultants’, or third-party personnel’s agreement to comply with King Saud University’s information security policies.
  • Access to networks and network services shall be authorized and monitored based on business and security requirements and the access control rules defined for each network. These rules shall take into consideration the following:
    • Security requirements for the network or network service(s).
    • Specific business requirements for users to access the network or network service, based on the “Need-to-Have” principle.
    • The user’s security classification and the security classification of the network.
    • Legal and/or contractual obligations to restrict or protect access to information assets.

3. User Account Management

  • King Saud University (KSU) shall establish a formal access control procedure that includes clear steps for requesting, creating, modifying, suspending, and revoking user accounts.
  • User identities shall be created in accordance with the legislative and regulatory requirements of King Saud University (KSU).
  • The granting of user access, changes to existing user access rights, and the removal of user access shall be authorized by the asset owner, taking into consideration the following:
    • Least Privilege (Need-to-Know principle).
    • Segregation of Duties.
    • Required level of access.
  • All King Saud University (KSU) users shall be uniquely identified through unique credentials that establish their identity. User credentials shall require at least one authentication factor, such as a password, token, or biometric device.
  • The system shall validate login credentials only after all input fields have been submitted. In the event of an error, the system shall not indicate which part of the information is correct or incorrect.
  • The Systems Administration shall uniquely identify and authenticate all users before granting them the appropriate level of access to the network/system.
  • Verification controls and access privileges shall be applied to all technical and information assets at King Saud University (KSU) through a centralized automated access control system, such as the Lightweight Directory Access Protocol (LDAP).
  • The use of shared accounts (generic accounts) to access King Saud University’s information and technical assets shall be prohibited.
  • All identity and access management systems shall be configured to transmit logs to a centralized logging and monitoring system, such as a Security Information and Event Management (SIEM) system, in accordance with approved policies.
  • Clear procedures for managing service accounts shall be documented, ensuring that such accounts are securely managed across applications and systems. Interactive human login shall also be disabled for service accounts.

4. Access Granting Rights

  • Access shall be granted based on a user request submitted through an approved form or system, with authorization from the user’s direct manager and the system owner, specifying the following:
    • System name.
    • Request type.
    • Access privileges and duration, where the access is temporary.
  • User access to King Saud University’s information and technical assets shall be granted in accordance with the user’s roles and responsibilities.
  • User login from multiple computers simultaneously (concurrent logins) shall be disabled.

5. Privileged Access Rights Management

  • Privileged access rights shall be verified to ensure that the requested privileged access is appropriate.
  • Details of users, including their identities, associated identifiers, and the access privileges to be granted, shall be documented.
  • Users shall be notified and required to acknowledge their understanding of their privileged access rights and the associated terms of use through relevant security awareness training.
  • Prior to granting privileged access rights to individuals, documented written approval from senior management shall be obtained in coordination with Risk Management and Information Security.
  • All users authorized to access King Saud University’s (KSU) information assets shall be identified and documented. The authorization process shall be tracked and recorded as follows:
    • Authorization date.
    • Identification of the purpose of the privileged access rights.
    • Authorized allocation of privileged access rights.
    • Privileged access rights shall be allocated on a need-to-use basis, based on the minimum requirements necessary for the user’s job role and on an event-by-event basis.
    • Privileged access rights shall be assigned to a user ID that is different from the ID used for normal or other activities.
    • Two-Factor Authentication (2FA) shall be used for privileged access.
    • A record of accounts with privileged access rights shall be maintained.
  • Default accounts shall be removed or renamed, particularly accounts with significant and sensitive privileges, such as the “root” account, “admin” account, and “unique system identifier” account.
  • The use of privileged access rights and any changes made to such rights shall be logged and reviewed regularly.
  • Normal activities shall not be performed using privileged user IDs.
  • The principles of Segregation of Duties and Least Privilege shall be followed when granting privileged access rights to users within King Saud University departments.

6. User Access Rights Review

  • Asset owners, in coordination with the Information Security Officer and relevant departments (such as Network, Data Center, and Electronic Services), shall review user access rights and privileges at least once a year.
  • When any misuse of privileged access rights is identified, the Information Security Officer shall recommend that the department manager restrict such privileges.
  • All failed and successful access attempts shall be logged, documented, and reviewed periodically.

7. Removal of Access Rights

  • Access rights (logical and/or physical) to information processing facilities and information shall be removed upon termination of employment, resignation, or termination of a contractual agreement. This may include, but is not limited to, the following:
    • Removal of all access rights associated with previous roles and duties, and establishment of appropriate access rights for new roles and duties.
    • Timely removal or reduction of access rights.
    • Removal or reduction of access rights prior to termination where the risks indicate that such action is appropriate, for example, when termination is initiated by King Saud University or when the access rights involve highly sensitive information or facilities.
    • Cancellation of all identification cards, such as magnetic cards, smart cards, and keys.
    • Changing shared access codes, such as lock combinations and safe combinations.
  • Human Resources Departments, in coordination with the Information User Manager, shall notify the Steering Committee or Risk Management and Information Security of transfers of information users or changes in job responsibilities, so that all necessary measures can be taken regarding the revocation or modification of access rights (logical and/or physical) to information assets.

8. Use of Secret Authentication Information

  • Users shall not enter passwords in email messages or other electronic communications.
  • Users shall not disclose their authentication information, including usernames and passwords, to other users. Accordingly, users shall be responsible for any activity associated with their access rights.
  • Users shall not capture, obtain, or otherwise acquire passwords, encryption keys, or any other access control mechanism that could enable unauthorized access.

9. Access Control to Application Systems

  • Controls shall be defined to regulate the output generated by application systems that process sensitive information, and such output shall be sent only to authorized terminals and locations.

10. Secure Logon for Operating Systems

  • The system shall define the maximum number of unsuccessful logon attempts permitted. The following shall also be taken into consideration:
    • All successful and unsuccessful logon attempts shall be logged.
    • A defined time period shall be enforced before additional logon attempts are permitted, or further attempts shall be denied unless specifically authorized.
    • Associated data communications shall be terminated.
    • An alert shall be sent to the system administrator when the maximum number of logon attempts is reached.
  • System administrators shall review all unsuccessful logon attempts on a monthly basis.
  • The system shall display a general warning notice stating that the computer may only be accessed by authorized users.
  • The logon process on any system shall display only limited information about the system and its intended use.
  • All King Saud University (KSU) system users shall ensure that endpoint protection software is installed on their computers before connecting to the KSU network. Only licensed software, including operating systems, obtained from sources approved by King Saud University shall be installed.

11. Session Time-Out Controls

  • During the logon process, systems shall define the minimum and maximum allowable time limits. If the maximum allowable time is exceeded, the session shall be terminated after 10 minutes.

12. Connection Time Control

  • Where feasible, all critical information systems shall have a defined time window for access and connection.

13. Utility Program Controls

  • Access to and use of system utility programs shall be restricted.
  • All unnecessary system utilities and programs shall be removed.

14. Protection of Software Source Code

  • King Saud University (KSU) shall ensure that all source code is centrally compiled, controlled, and maintained.
  • Access to software source code and configurations shall be documented and restricted to authorized personnel.

15. Network Security Controls

  • Insecure ports and protocols, such as File Transfer Protocol (FTP) and Telnet, shall be disabled.
  • All outbound traffic from the KSU Data Center (KSU DC) to the Internet shall be blocked, and access shall be permitted only for critical systems upon the administrator’s request.
  • Remote Desktop Protocol (RDP) and Secure Shell (SSH) ports shall be opened only for specified static IP addresses and designated servers.
  • RDP and SSH connections between servers located in different VLANs shall not be permitted.
  • Direct access from the VPN VLAN to the Data Center (DC) shall not be permitted. The administrator shall use their designated computer as a jump host between the VPN VLAN and the target server.

 

Last updated on : August 26, 2026 8:32am