Interested Parties and their Needs¶
Document Control¶
Document Information
| Document Name | Document Number | Implementation Date | Next Review Date | Policy Owner |
|---|---|---|---|---|
| Interested Parties and their Needs | CYS-IPATN-01/2025 | [YYYY-MM] | [YYYY-MM] | CISO |
Revision History
| Version | Name | Job Title | Date | Summary of Revision |
|---|---|---|---|---|
| 1 | Abdullah Alqhatani | CISO | [YYYY-MM] | 1st Release |
Document Approvals
| Name | Title | Date | Method |
|---|---|---|---|
| [FILL] | [FILL] | [YYYY-MM] | [FILL] |
Purpose¶
Masdr has identified the interested parties that are relevant to its ISMS and has determined their relevant requirements related to information security. These requirements are considered when establishing, implementing, maintaining, and continually improving the ISMS.
Interested parties include internal and external stakeholders that can affect, or be affected by, Masdr's ability to protect information and comply with applicable legal, regulatory, contractual, and business obligations.
Definitions¶
| Term | Definition |
|---|---|
| Policy Owner | The individual responsible for maintaining and updating this policy. |
| User | Any person who accesses or uses Masdr's systems, data, or networks. |
| ICT | Information and Communications Technology. |
| Information Security | Preservation of confidentiality, integrity, and availability of information. |
| Information Security Management System (ISMS) | Policies, procedures, guidelines, and associated resources and activities, collectively managed by an organization, in the pursuit of protecting its information assets. |
| Availability | Property of being accessible and usable on demand by an authorized entity. |
| Confidentiality | Property that information is not made available or disclosed to unauthorized individuals, entities, or processes. |
| Integrity | Property of accuracy and completeness. |
| Top management | Person or group of people who directs and controls an organization at the highest level |
Identification of Interested Parties¶
The following interested parties have been identified as relevant to Masdr's ISMS:
Internal Interested Parties¶
- Masdr Top Management
- Masdr Business Units, including Product, Engineering, and Operations Teams
- Masdr Employees
- Masdr Contractors and Temporary Staff
External Interested Parties¶
- Regulatory and Government Authorities
- Customers and End Users
- Business Partners and Third Parties
- Cloud Service Providers and Technology Vendors
- Data Subjects
- Shareholders and Investors
Needs and Expectations of Interested Parties¶
The table below summarizes the key interested parties and their relevant information security needs and expectations.
| Interested Party | Needs and Expectations Relevant to the ISMS |
|---|---|
| Top Management | Assurance that information security risks are identified, managed, and aligned with strategic objectives; compliance with applicable laws and regulations; protection of organizational reputation. |
| Employees and Contractors | Clear information security policies and procedures; secure access to systems and data; awareness and training on information security responsibilities. |
| Regulatory Authorities (NCA, NDMO, SDAIA, GOSI) | Compliance with applicable cybersecurity controls, data protection regulations, reporting obligations, and audit requirements; timely incident notification where required. |
| Customers and End Users | Protection of personal, financial, and health-related information; confidentiality, integrity, and availability of services; transparency in data handling and processing practices. |
| Business Partners and Third Parties | Secure information exchange; clearly defined security responsibilities; contractual assurance of compliance with information security and data protection requirements. |
| Cloud Service Providers and Technology Vendors | Clear definition of shared responsibility for information security; adherence to contractual security obligations; secure integration and service availability. |
| Data Subjects | Lawful, fair, and transparent processing of personal data; protection against unauthorized access, disclosure, or misuse of personal information; respect for data subject rights. |
| Shareholders/Investors | Confidence in governance, risk management, regulatory compliance, and long-term operational resilience. |
Determination of Relevant Requirements¶
Masdr determines which needs and expectations of interested parties become mandatory requirements for the ISMS through the following sources:
- Applicable laws, regulations, and national cybersecurity controls within the Kingdom of Saudi Arabia
- Regulatory directives issued by NCA, NDMO, SDAIA, and GOSI
- Contractual obligations with customers, partners, and service providers
- Internal policies, standards, and governance decisions
- Strategic business and operational objectives
These requirements are reflected in:
- The scope of the ISMS
- Information security policies and standards
- Risk assessment and treatment processes
- Supplier and third-party management practices
Review and Maintenance of Interested Parties¶
Masdr reviews its interested parties and their relevant requirements:
- At planned intervals
- Upon significant changes to regulatory legal, technological, or business conditions
- Following major incidents or changes affecting information security risk
Masdr will update interested parties and their requirements as part of its commitment to continually improve its ISMS.