تخطي إلى المحتوى الرئيسي

موقع حكومي رسمي تابع لحكومة المملكة العربية السعودية

روابط المواقع الالكترونية الرسمية السعودية تنتهي بـ .edu.sa

جميع روابط المواقع الرسمية التعليمية في المملكة العربية السعودية تنتهي بـ sch.sa أو edu.sa

المواقع الالكترونية الحكومية تستخدم بروتوكول HTTPS للتشفير و الأمان.

المواقع الالكترونية الآمنة في المملكة العربية السعودية تستخدم بروتوكول HTTPS للتشفير.

شعار هيئة الحكومة الرقمية

مسجل لدى هيئة الحكومة الرقمية برقم:

20260723112

Data Classification Policy

Data Management & Governance National Data Management Office (NDMO) Asset Confidentiality & Integrity

Data Classification Policy

Princess Nourah bint Abdulrahman University is dedicated to safeguarding the confidentiality, integrity, and availability (CIA) of its information assets. This policy establishes the statutory principles and tier-based categorization framework for institutional data in alignment with national regulatory standards, reinforcing accountability, transparency, and secure inter-agency data integration.

 

Approved Data Classification Levels

4 Standard Tiers
Tier 1 Top Secret Data whose compromise causes exceptionally grave harm to national interests or university operations.
Tier 2 Secret Sensitive data whose unauthorized disclosure causes substantial injury to public or institutional affairs.
Tier 3 Restricted Data intended for limited internal consumption, accessible exclusively to authorized internal personnel.
Tier 4 Public Unrestricted data available to the general public, governed by the University Open Data Policy.
 

Core Principles of Data Classification

7 Key Benchmarks
 

1. Open by Default

Data is presumed open in developmental spheres unless sensitivity warrants higher protection tiers, and presumed top secret unless nature warrants lower classifications.

 

2. Necessity & Proportionality

Data is classified commensurate with its intrinsic nature, business impact, and sensitivity, balancing operational utility against requisite confidentiality.

 

3. Timely Classification

Classification is performed synchronously upon data generation or receipt from external entities, executed rigorously within predefined timelines.

 

4. Highest Protection Standard

When aggregated datasets encompass records of varying sensitivity tiers, the entire composite dataset must inherit the highest classification standard.

 

5. Segregation of Duties

Clear operational separation across duties governing data classification, ingestion, modification, retrieval, and disposal, mitigating conflicting interests.

 

6. Need-to-Know Principle

Access and retrieval are restricted strictly to validated business necessity, confined to the minimum requisite number of authorized personnel.

 

7. Principle of Least Privilege

System entitlements and access rights are calibrated to the minimal privileges necessary to discharge assigned duties, subject to periodic access audits.


Was this page helpful?

0% of users said yes from 0 responses

Please tell us why*(You can select multiple options)

I am*

Last page update: KSA Time