Procedures for Handling Cybersecurity Incidents in the Telecommunications, Information Technology, and Postal Sector

1. Introduction

In accordance with the Telecommunications System, its executive regulations, and the organization of the Communications and Information Technology Commission, which includes powers granted to the Communications and Information Technology Commission, including those related to protecting the public interest and the interests of users, as well as maintaining the confidentiality of communications and information security, and in pursuit of the Commission's goal to enhance the level of maturity in cybersecurity within the telecommunications, information technology, and postal sectors in the Kingdom, and to increase trust in service providers by taking all necessary measures, the Commission has prepared a document titled (Procedures for Dealing with Cybersecurity Incidents in the Telecommunications, Information Technology, and Postal Sectors); to emphasize the implementation of necessary procedures for the prevention and response to risks and security incidents related to cybersecurity.

2. Definitions

The words and phrases defined in the Communications System and its Executive Regulations, as well as other regulations of the Commission, shall have the same meaning when used in this document and its attached appendices, and the following words and expressions shall have the meanings associated with them unless the context requires otherwise:

The Commission: Communications and Information Technology Commission.

Service Provider: Provider of telecommunications, information technology, or postal services in the telecommunications and information technology and postal sector in the Kingdom of Saudi Arabia.

Response Entity: The entity providing cybersecurity incident response services.

Cybersecurity: The protection of networks, information technology systems, operational technology systems, and their components, including hardware and software, the services they provide, and the data they contain, from any unauthorized breach, disruption, modification, access, use, or exploitation. The concept of cybersecurity includes information security, electronic security, digital security, and similar terms.

Cybersecurity Incident: Any violation or event that has actually led to a breach, disruption, modification, access, use, or unauthorized exploitation of networks or information technology systems or operational technology systems or any of their components, including hardware and software, the services they provide, and the data they contain, including the leakage of personal or sensitive data.

Data Leakage: The declaration of data, or obtaining it, or enabling access to it without authorization or legal basis, whether intentionally or unintentionally.

Critical Incident: An incident with a high impact at the national level or at the sector level.

Initial Assessment of a Cybersecurity Incident: A rapid analysis process of the incident aimed at verifying the validity of the incident, determining its type and classifying it, collecting initial breach indicators, and an initial determination of the scope of impact from the incident.

Cybersecurity Incident Response: The process of dealing with the incident, within the expected time, in a systematic manner aimed at reducing the level of impact of the incident on the service provider to the lowest possible level while identifying and sharing breach indicators and detailed digital evidence, preparing and delivering reports and recommendations related to the incident.

3. General Provisions

1. All providers of telecommunications, information technology, and postal services in the Kingdom of Saudi Arabia are subject to the application of these procedures.

2. The service provider is responsible for taking all necessary measures to protect its informational assets and for periodically verifying its readiness to prevent cybersecurity incidents.

3. The service provider is responsible for responding to cybersecurity incidents when they occur.

4. The service provider must comply with all procedures outlined in this document and its annexes, and in the event of a violation, the violations will be addressed in accordance with the regulations of the authority, and the service provider shall not be exempt from liability in the event of contracting with other parties.

5. These procedures do not infringe upon any procedures included in a regulatory document issued by the authority or other relevant entities.

4. Procedures for Dealing with Cybersecurity Incidents:

4.1 Procedures for Handling Cybersecurity Incidents by the Service Provider:

The service provider must do the following:

1. Register with the authority and specify contact details by filling out the form outlined in the Appurtenance (A - Registration Form with the Authority), and update the information in case of any changes or modifications.

2. Notify the authority immediately upon the occurrence of a cybersecurity incident through the communication channels with the authority in cybersecurity incidents outlined in the Appurtenance (B - Communication Channels with the Authority in Cybersecurity Incidents), and then provide all necessary information about the incident to the authority's team and fill out the form in the Appurtenance (C - Cybersecurity Incident Reporting Form).

3. Designate a point of contact to respond to the authority's inquiries and provide all required information - if needed - throughout the response period to the cybersecurity incident.

4. Conduct an initial assessment of the cybersecurity incident and provide the authority with its results. The authority may request the service provider to redo the initial assessment of the cybersecurity incident if the information and risk analysis resulting from the incident are insufficient.

5. Provide the authority with a final report on the incident within a maximum period of 20 working days from the end of the response process, as outlined in the Appurtenance (D - Final Report on the Cybersecurity Incident).

6. Comply with the corrective procedures communicated to them by the authority within the specified timeframe.

7. Regarding the cybersecurity incident, the service provider is only allowed to communicate with the relevant parties.

8. If the authority assigns a response entity, the service provider must fully cooperate and facilitate the work and tasks of the authority and the assigned response entity, including allowing visits to the site of the cybersecurity incident and providing the necessary information and reports.

9. If necessary, and upon the authority's direction, the service provider shall, at their own expense, issue a clarifying statement regarding the cybersecurity incident.

10. If the incident affects other related parties, such as users of the service provider's services, the service provider must notify those parties and provide them - if necessary - with a brief report on the incident. The authority must be informed of this, including the details of the notification.

4.2 Procedures for Handling Cybersecurity Incidents by the Response Entity:

1. The response entity shall communicate with the service provider and request the required information, visit the incident site, and provide the authority and the service provider with periodic reports during the response period to cybersecurity incidents, and submit the final report as detailed in the Appurtenance (D - Final Report of the Cybersecurity Incident).

2. The response entity shall provide the authority and the service provider with periodic reports during the response service and the final report of the incident, as stated in the Appurtenance (D - Final Report of the Cybersecurity Incident). 

4.3 Procedures for Dealing with Cybersecurity Incidents by the Authority:

  • 1. The Authority may reassess the cybersecurity incident - if necessary - and classify it as a critical incident, which requires handling it as follows:

    • 1.1. The Authority - if necessary - may assign a response entity to respond to cybersecurity incidents and notify the service provider accordingly.

    • 1.2. The Authority shall appoint an internal team to follow up on the incident and organize communication between the service provider and the response entity.

2. The Authority – at its sole discretion – may share the results of preliminary or final reports, or part thereof, prepared by the service provider with relevant entities while maintaining the privacy and confidentiality of the information contained in those reports.

3. The Authority may conduct inspection and investigation at the site of the cybersecurity incident, in accordance with the Authority's regulations.

4. The Authority may request the service provider to implement corrective actions as a result of a cybersecurity incident, specifying the time frame required for their completion.

5. The Authority – at its sole discretion – may share lessons learned from the cybersecurity incident with other entities in the sector or outside it while preserving the privacy and information of the service provider.

6. The Authority – at its sole discretion – may issue a clarifying statement regarding the cybersecurity incident.

5. Annexes

5.1 Appendix (A): Registration Form with the Authority

5.2 Appendix (B): Communication Channels with the Authority in Cybersecurity Incidents

Next section title

Next section content