Information Security Policy¶
Document Control¶
Document Information
| Document Name | Document Number | Implementation Date | Next Review Date | Policy Owner |
|---|---|---|---|---|
| Information Security Policy | CYS-ISP-01/2025 | 2025-10 | 2026-10 | Cybersecurity GRC Consultant |
Revision History
| Version | Name | Job Title | Date | Summary of Revision |
|---|---|---|---|---|
| 1 | no-one | N/A | Cybersecurity GRC Consultant | 1st Release |
Document Approvals
| Name | Title | Date | Method |
|---|---|---|---|
| Abdullah Alqhatani | CISO | 2025-10 |
Purpose¶
Masdr is committed to protecting the confidentiality, integrity, and availability of all its information assets. Information security is a fundamental component of Masdr's operations and is essential to maintaining trust with users, partners, regulators, and other stakeholders.
This Information Security Policy establishes Masdr's overall direction and principles for information security and provides the foundation for the Information Security Management System (ISMS). The purpose of this policy is to:
- Define Masdr's commitment to information security
- Establish a high-level framework for managing information security risks
- Ensure compliance with applicable national, legal, regulatory, and contractual requirements
- Support the secure delivery of Masdr's products and services
Scope¶
This policy applies to:
- All information assets owned, processed, or managed by Masdr, regardless of format or location
- All Masdr personnel, including employees, contractors, temporary staff, and third parties
- All information systems, applications, infrastructure, and services, including cloud-based and third party environments
Compliance¶
Compliance with this policy is mandatory. Failure to comply with this policy may result in disciplinary action, up to and including termination of employment or contract, as well as potential legal consequences.
Definitions¶
| Term | Definition |
|---|---|
| Policy Owner | The individual responsible for maintaining and updating this policy. |
| User | Any person who accesses or uses Masdr's systems, data, or networks. |
| ICT | Information and Communications Technology. |
| Information Security | Preservation of confidentiality, integrity, and availability of information. |
| Information Security Management System (ISMS) | Policies, procedures, guidelines, and associated resources and activities, collectively managed by an organization, in the pursuit of protecting its information assets. |
| Availability | Property of being accessible and usable on demand by an authorized entity. |
| Confidentiality | Property that information is not made available or disclosed to unauthorized individuals, entities, or processes. |
| Integrity | Property of accuracy and completeness. |
| Top management | Person or group of people who directs and controls an organization at the highest level |
Roles and Responsibilities¶
| Role | Responsibility |
|---|---|
| Policy Owner | Ensure the policy is maintained, reviewed, and updated regularly. |
| All Employees | Understand and adhere to the requirements of this policy. |
| Managers | Communicate policy requirements to their teams and ensure compliance. |
Policy Statements¶
Information Security Objectives¶
Masdr establishes information security objectives that are consistent with its strategic direction and regulatory obligations.
The information security objectives of Masdr are to:
- Promote and ensure the secure, responsible, and controlled use, development, adoption, and access to Artificial Intelligence technologies
- Protect sensitive, personal, financial, and health-related information from unauthorized access, disclosure, alteration, or destruction
- Ensure the availability and resilience of information systems supporting Masdr's operations and services
- Mange information security risks through a structured risk assessment and treatment process
- Maintain compliance with applicable national decrees, laws, regulations, and national cybersecurity requirements within the Kingdom of Saudi Arabia
- Promote information security awareness and accountability throughout Masdr
- Continually improve the suitability, adequacy and effectiveness of Masdr's ISMS
| Objective | Key Result | Target | Owner | Timeline | Status |
|---|---|---|---|---|---|
Management Commitment¶
Masdr’s top management demonstrates leadership and commitment to the ISMS by:
- Establishing and approving this Information Security Policy
- Ensuring information security objectives are defined and aligned with business goals
- Providing adequate resources, including funding, personnel, and technology, to operate and improve the ISMS
- Assigning clear roles, responsibilities, and authorities for information security
- Supporting continual improvement of information security performance
- Promoting a culture of information security awareness and compliance
Information Security Policy Framework¶
Masdr maintains a structured framework of information and cyber security documentation to support this policy, which can be accessed through the policies portal. All personnel should apply information security in accordance with the Information Security Policy, topic-specific policies and procedures of Masdr.
This policy is supported by, and takes precedence over, all subordinate information security standards and procedures.
Information Security Responsibilities¶
Information security is a shared responsibility across Masdr. The table below outlines the key roles and their responsibilities related to the ISMS:
| Role | Responsibilities |
|---|---|
| Top Management | Provide strategic direction, oversight, and resources for the ISMS. |
| Information Security / ISMS Function | Develop, implement, maintain, and monitor the ISMS |
| Business Units Managers | Ensure their teams understand and comply with applicable information security requirements |
| Employees and Third Parties | Understand and follow information security policies, standards, and procedures, and promptly report any suspected or confirmed information security incidents, weaknesses, or non-conformities. |
Exceptions¶
Requests for exceptions to this policy must be submitted in writing to the Policy Owner. Exceptions will be reviewed on a case-by-case basis and must be formally approved before any deviation is permitted.
- All exceptions MUST be documented and approved by the
Policy OwnerandInformation Security. - Exceptions MUST include a defined expiration date.
- Compensating controls MUST be identified where applicable.
- All exceptions MUST be reviewed at least annually.