The words and phrases defined in the Communications System and its Executive Regulations, as well as other regulations of the Commission, shall have the same meaning when used in this document and its attached appendices, and the following words and expressions shall have the meanings associated with them unless the context requires otherwise:
The Commission: Communications and Information Technology Commission.
Service Provider: Provider of telecommunications, information technology, or postal services in the telecommunications and information technology and postal sector in the Kingdom of Saudi Arabia.
Response Entity: The entity providing cybersecurity incident response services.
Cybersecurity: The protection of networks, information technology systems, operational technology systems, and their components, including hardware and software, the services they provide, and the data they contain, from any unauthorized breach, disruption, modification, access, use, or exploitation. The concept of cybersecurity includes information security, electronic security, digital security, and similar terms.
Cybersecurity Incident: Any violation or event that has actually led to a breach, disruption, modification, access, use, or unauthorized exploitation of networks or information technology systems or operational technology systems or any of their components, including hardware and software, the services they provide, and the data they contain, including the leakage of personal or sensitive data.
Data Leakage: The declaration of data, or obtaining it, or enabling access to it without authorization or legal basis, whether intentionally or unintentionally.
Critical Incident: An incident with a high impact at the national level or at the sector level.
Initial Assessment of a Cybersecurity Incident: A rapid analysis process of the incident aimed at verifying the validity of the incident, determining its type and classifying it, collecting initial breach indicators, and an initial determination of the scope of impact from the incident.
Cybersecurity Incident Response: The process of dealing with the incident, within the expected time, in a systematic manner aimed at reducing the level of impact of the incident on the service provider to the lowest possible level while identifying and sharing breach indicators and detailed digital evidence, preparing and delivering reports and recommendations related to the incident.