Skip to content

Information Security Roles and Responsibilities

Document Control

Document Information
Document Name Document Number Implementation Date Next Review Date Policy Owner
Information Security Policy CYS-ISP-01/2025 2025-10 2026-10 Cybersecurity GRC Consultant
Revision History
Version Name Job Title Date Summary of Revision
1 no-one N/A Cybersecurity GRC Consultant 1st Release
Document Approvals
Name Title Date Method
Abdullah Alqhatani CISO 2025-10 Email

Purpose

Masdr is committed to protecting the confidentiality, integrity, and availability of all its information assets. Information security is a fundamental component of Masdr's operations and is essential to maintaining trust with users, partners, regulators, and other stakeholders.

This Information Security Policy establishes Masdr's overall direction and principles for information security and provides the foundation for the Information Security Management System (ISMS). The purpose of this policy is to:

  • Define Masdr's commitment to information security
  • Establish a high-level framework for managing information security risks
  • Ensure compliance with applicable national, legal, regulatory, and contractual requirements
  • Support the secure delivery of Masdr's products and services

Scope

This policy applies to:

  • All information assets owned, processed, or managed by Masdr, regardless of format or location
  • All Masdr personnel, including employees, contractors, temporary staff, and third parties
  • All information systems, applications, infrastructure, and services, including cloud-based and third party environments

Compliance

Compliance with this policy is mandatory. Failure to comply with this policy may result in disciplinary action, up to and including termination of employment or contract, as well as potential legal consequences.


Definitions

Term Definition
Policy Owner The individual responsible for maintaining and updating this policy.
User Any person who accesses or uses Masdr's systems, data, or networks.
ICT Information and Communications Technology.
Information Security Preservation of confidentiality, integrity, and availability of information.
Information Security Management System (ISMS) Policies, procedures, guidelines, and associated resources and activities, collectively managed by an organization, in the pursuit of protecting its information assets.
Availability Property of being accessible and usable on demand by an authorized entity.
Confidentiality Property that information is not made available or disclosed to unauthorized individuals, entities, or processes.
Integrity Property of accuracy and completeness.
Top management Person or group of people who directs and controls an organization at the highest level

Roles and Responsibilities

Role Responsibility
Policy Owner Ensure the policy is maintained, reviewed, and updated regularly.
All Employees Understand and adhere to the requirements of this policy.
Managers Communicate policy requirements to their teams and ensure compliance.

Policy Statements

Information Security Objectives

Management Commitment

Information Security Policy Framework

Masdr maintains a structured framework of information and cyber security documentation to support this policy, which can be accessed through the policies portal. All personnel should apply information security in accordance with the Information Security Policy, topic-specific policies and procedures of Masdr.

This policy is supported by, and takes precedence over, all subordinate information security standards and procedures.

Information Security Responsibilities

Information security is a shared responsibility across Masdr. The table below outlines the key roles and their responsibilities related to the ISMS:

Role Responsibilities
Top Management Provide strategic direction, oversight, and resources for the ISMS.
Information Security / ISMS Function Develop, implement, maintain, and monitor the ISMS
Business Units Managers Ensure their teams understand and comply with applicable information security requirements
Employees and Third Parties Understand and follow information security policies, standards, and procedures, and promptly report any suspected or confirmed information security incidents, weaknesses, or non-conformities.

Responsibility Assignment RACI

Organizational Chart



Exceptions

Requests for exceptions to this policy must be submitted in writing to the Policy Owner. Exceptions will be reviewed on a case-by-case basis and must be formally approved before any deviation is permitted.

  • All exceptions MUST be documented and approved by the Policy Owner and Information Security.
  • Exceptions MUST include a defined expiration date.
  • Compensating controls MUST be identified where applicable.
  • All exceptions MUST be reviewed at least annually.