1- General Provisions
1-1 Procedures for managing the relationship between <Entity Name> and external parties must be documented, approved, and implemented before, during, and after the contractual relationship ends.
1-2 A cybersecurity risk assessment must be conducted on external parties and the services provided, including but not limited to reviewing external parties’ projects within <Entity Name> and reviewing cybersecurity event logs related to the external party’s services (if available) before, during, and periodically throughout the relationship in accordance with the cybersecurity risk management policy approved by <Entity Name>. The cybersecurity risk assessment procedures must include identifying the necessary protective controls to be applied for effective management of the identified cybersecurity risks.
1-3 Security screening (Screening or Vetting) must be conducted for outsourcing companies and managed services providers that support or operate sensitive systems.
1-4 Contracts and agreements with external parties must include <Entity Name>’s cybersecurity requirements and clauses obligating external parties to comply with <Entity Name>’s cybersecurity policies and relevant legislative and regulatory requirements.
1-5 Cybersecurity responsibilities, non-disclosure clauses, and secure deletion provisions must be included in contracts for external parties’ employees handling <Entity Name>’s data (covering during and after the termination/ending of the employment relationship with <Entity Name>).
1-6 It must be ensured that the external party manages its own cybersecurity risks.
1-7 External parties must grant <Entity Name> the necessary authorizations to conduct tests verifying the external parties’ compliance with <Entity Name>’s cybersecurity requirements and provide required reports upon request.
1-8 Key Performance Indicators (KPIs) must be used to ensure continuous improvement and proper, effective use of cybersecurity requirements related to external parties.
2- Cybersecurity Requirements for IT Outsourcing or Managed Services Provided by External Parties
2-1 To obtain IT outsourcing or managed services, the external party must be carefully selected, and at minimum the following must be verified:
2-1-1 Conduct a cybersecurity risk assessment and ensure controls are in place to manage those risks before signing contracts or agreements or when relevant legislative and regulatory requirements change.
2-1-2 Managed cybersecurity operations centers for operation and monitoring that use remote access methods must be located entirely within the Kingdom.
2-1-3 Outsourcing services on sensitive systems must be provided by national companies and entities, in accordance with relevant legislative and regulatory requirements.
2-1-4 Outsourcing and managed services handling classified data must be provided by national companies and entities, in accordance with relevant legislative and regulatory requirements.
3- Cybersecurity Requirements Related to External Parties’ Employees
3-1 Security screening (Screening or Vetting) must be conducted for outsourcing companies, outsourcing service employees, and managed services employees working on sensitive systems or who have access privileges to classified data.
3-2 It must be ensured that external parties’ employees expected to have direct or indirect access to <Entity Name>’s assets sign a confidentiality protection pledge before entering into the employment relationship, according to the approved format at <Entity Name>.
3-3 It must be ensured that external party employees are aware of <Entity Name>’s cybersecurity requirements and comply with them.
4- Cybersecurity Requirements Related to Documentation and Access Controls
4-1 External parties must develop approved procedures for granting and revoking access rights to all information and technical systems that process, transfer, or store <Entity Name>’s information, in line with cybersecurity requirements and <Entity Name>’s cybersecurity control objectives.
4-2 Access by external parties’ employees to <Entity Name>’s information and its processing must be restricted securely, and access activities must be continuously monitored.
4-3 Password controls must be applied to all users with access privileges to <Entity Name>’s information in accordance with cybersecurity requirements and <Entity Name>’s cybersecurity control objectives.
4-4 Access rights and privileges must be revoked immediately upon termination/ending of services of any external party employee who has access to <Entity Name>’s information or information and technical assets, or upon a change in their job role that no longer requires continued access.
4-5 External parties must periodically review access rights in accordance with the identity and access management policy approved by <Entity Name>.
4-6 All audit logs must be stored securely, maintained, and made available upon <Entity Name>’s request and in accordance with relevant legislative and regulatory requirements.
5- Cybersecurity Requirements Related to Change Management
5-1 External parties must follow the formal and appropriate change management process according to <Entity Name>’s policies and procedures.
5-2 Changes made to <Entity Name>’s information and technical assets must be reviewed and tested before implementation in the production environment.
5-3 Relevant parties within <Entity Name> must be notified of planned major changes as well as changes made to <Entity Name>’s information and technical assets.
6- Cybersecurity Incident Management and Business Continuity Requirements
6-1 Contracts and agreements with external parties must include requirements related to reporting cybersecurity incidents and notifying <Entity Name> in the event the external party experiences a cybersecurity incident.
6-2 Procedures for communication between the external party and <Entity Name> in the event of a cybersecurity incident or vulnerability reporting must be identified and documented, and these procedures must be reviewed and updated periodically.
6-3 An appropriate business continuity plan must be established to avoid unavailability of services provided to <Entity Name> in accordance with <Entity Name>’s business continuity and disaster recovery plan requirements.
7- Data and Information Protection Requirements
7-1 Data and information of <Entity Name> present in all systems and processed or stored by external parties must be classified according to the data and information classification policy approved by <Entity Name>.
7-2 External parties must process, store, and dispose of <Entity Name>’s data and information in accordance with the data and information protection policy and standards approved by <Entity Name>.
7-3 Contracts and agreements with external parties must include the ability to securely delete the entity’s data held by the external party upon termination/ending of the contractual relationship, with evidence provided.
7-4 External parties must apply appropriate encryption controls to protect data and information according to their classification at <Entity Name> and ensure confidentiality, integrity, and availability in accordance with the encryption standard approved by <Entity Name>.
7-5 External parties must perform regular backups of <Entity Name>’s data and information in accordance with <Entity Name>’s backup management policy.
7-6 Data and information of <Entity Name> present in sensitive systems and personal data processed by external parties must not be processed, stored, or used in test environments except after applying strict controls to protect such data, such as Data Masking, Data Scrambling, or Data Anonymization techniques, and after obtaining necessary approvals from relevant departments at <Entity Name> to ensure data protection and privacy in accordance with the guidelines and requirements of the National Data Management Office.
7-7 Data and information of <Entity Name> present in sensitive systems and processed or stored by external parties must not be transferred outside the production environment.
8- Auditing
8-1 <Entity Name> must conduct audits of related operations and systems whenever necessary or appropriate.
8-2 All external party employees must fully cooperate with <Entity Name>’s event log review and audit activities, including executed audits.