Skip to content

Interested Parties and their Needs

Document Control

Document Information
Document Name Document Number Implementation Date Next Review Date Policy Owner
Interested Parties and their Needs CYS-IPATN-01/2025 [YYYY-MM] [YYYY-MM] CISO
Revision History
Version Name Job Title Date Summary of Revision
1 Abdullah Alqhatani CISO [YYYY-MM] 1st Release
Document Approvals
Name Title Date Method
[FILL] [FILL] [YYYY-MM] [FILL]

Purpose

Masdr has identified the interested parties that are relevant to its ISMS and has determined their relevant requirements related to information security. These requirements are considered when establishing, implementing, maintaining, and continually improving the ISMS.

Interested parties include internal and external stakeholders that can affect, or be affected by, Masdr's ability to protect information and comply with applicable legal, regulatory, contractual, and business obligations.


Definitions

Term Definition
Policy Owner The individual responsible for maintaining and updating this policy.
User Any person who accesses or uses Masdr's systems, data, or networks.
ICT Information and Communications Technology.
Information Security Preservation of confidentiality, integrity, and availability of information.
Information Security Management System (ISMS) Policies, procedures, guidelines, and associated resources and activities, collectively managed by an organization, in the pursuit of protecting its information assets.
Availability Property of being accessible and usable on demand by an authorized entity.
Confidentiality Property that information is not made available or disclosed to unauthorized individuals, entities, or processes.
Integrity Property of accuracy and completeness.
Top management Person or group of people who directs and controls an organization at the highest level

Identification of Interested Parties

The following interested parties have been identified as relevant to Masdr's ISMS:

Internal Interested Parties

  • Masdr Top Management
  • Masdr Business Units, including Product, Engineering, and Operations Teams
  • Masdr Employees
  • Masdr Contractors and Temporary Staff

External Interested Parties

  • Regulatory and Government Authorities
  • Customers and End Users
  • Business Partners and Third Parties
  • Cloud Service Providers and Technology Vendors
  • Data Subjects
  • Shareholders and Investors

Needs and Expectations of Interested Parties

The table below summarizes the key interested parties and their relevant information security needs and expectations.

Interested Party Needs and Expectations Relevant to the ISMS
Top Management Assurance that information security risks are identified, managed, and aligned with strategic objectives; compliance with applicable laws and regulations; protection of organizational reputation.
Employees and Contractors Clear information security policies and procedures; secure access to systems and data; awareness and training on information security responsibilities.
Regulatory Authorities (NCA, NDMO, SDAIA, GOSI) Compliance with applicable cybersecurity controls, data protection regulations, reporting obligations, and audit requirements; timely incident notification where required.
Customers and End Users Protection of personal, financial, and health-related information; confidentiality, integrity, and availability of services; transparency in data handling and processing practices.
Business Partners and Third Parties Secure information exchange; clearly defined security responsibilities; contractual assurance of compliance with information security and data protection requirements.
Cloud Service Providers and Technology Vendors Clear definition of shared responsibility for information security; adherence to contractual security obligations; secure integration and service availability.
Data Subjects Lawful, fair, and transparent processing of personal data; protection against unauthorized access, disclosure, or misuse of personal information; respect for data subject rights.
Shareholders/Investors Confidence in governance, risk management, regulatory compliance, and long-term operational resilience.

Determination of Relevant Requirements

Masdr determines which needs and expectations of interested parties become mandatory requirements for the ISMS through the following sources:

  • Applicable laws, regulations, and national cybersecurity controls within the Kingdom of Saudi Arabia
  • Regulatory directives issued by NCA, NDMO, SDAIA, and GOSI
  • Contractual obligations with customers, partners, and service providers
  • Internal policies, standards, and governance decisions
  • Strategic business and operational objectives

These requirements are reflected in:

  • The scope of the ISMS
  • Information security policies and standards
  • Risk assessment and treatment processes
  • Supplier and third-party management practices

Review and Maintenance of Interested Parties

Masdr reviews its interested parties and their relevant requirements:

  • At planned intervals
  • Upon significant changes to regulatory legal, technological, or business conditions
  • Following major incidents or changes affecting information security risk

Masdr will update interested parties and their requirements as part of its commitment to continually improve its ISMS.