This is an earlier version ofRegulations of Cybersecurity Operations in the Telecommunications, Information Technology, and Postal SectorSwitch to the new version

Regulations of Cybersecurity Operations in the Telecommunications, Information Technology, and Postal Sector

1. Introduction

 In accordance with the Telecommunications System, its executive regulations, and the organization of the Communications and Information Technology Commission, which includes powers related to protecting public interests and user interests, as well as maintaining the confidentiality of communications and information security, the Communications and Information Technology Commission has established a Cybersecurity Operations Center to achieve its strategic objectives in overseeing cybersecurity in the sector. This center aims to enhance cooperation among service providers in the telecommunications, information technology, and postal sectors, and to support efforts in preparedness and response to cybersecurity attacks in the sector. The center provides a range of services that include the exchange of information regarding threats, vulnerabilities, and cybersecurity incidents, monitoring and coordinating incident response efforts, and organizing incident response exercises and disaster recovery for cybersecurity. Therefore, these regulations have been issued to enable the center to perform its duties correctly and contribute to enhancing cybersecurity in the sector.

2. Definitions

3. Scope of Application of the Regulatory Document

This document: defines the roles and responsibilities of the Cybersecurity Operations Center and all providers of telecommunications, information technology, and postal services in the Kingdom, in a manner that serves the purpose of this document.

 

1-3 Obligation under the document

1-1-3 The application of these regulations is subject to all providers of telecommunications, information technology, and postal services in the Kingdom of Saudi Arabia.

2-1-3 The service provider must comply with all roles and responsibilities stated in this document and its annexes. In the event of a violation, the violations will be addressed in accordance with the Authority's regulations, and the service provider shall not be exempt from liability in the event of contracting with other parties.

3-1-3 This document does not exempt the service provider from the obligation to comply with any policies or procedures included in a regulatory document issued by the Authority or other relevant entities.

4. General Provisions

1-4 These regulations do not exempt the service provider from its responsibilities regarding its cybersecurity and taking all necessary measures to protect its informational assets, and periodically verifying its readiness to prevent cybersecurity incidents and respond to them if they occur.

2-4 The service provider must register with the Authority and specify contact information by filling out the form outlined in the Appurtenance (A - Registration Form with the Authority) or any other means that may be specified by the Center, and the information must be updated in case of any changes or modifications.

3-4 The Authority has the right to review the provisions of this document periodically and update them if necessary.

5. Cyber Information Sharing

The purpose of this article: is to organize the mechanism for the exchange and sharing of cybersecurity information between the Cybersecurity Operations Center and the providers of telecommunications, information technology, and postal services in the sector, and to define the roles and responsibilities that enable the Cybersecurity Operations Center to fulfill its duties in overseeing the response to cybersecurity threats and incidents, as well as detecting any potential targeting at the sector level. It also assists service providers in enhancing their state of readiness.

6. Proactive Information Sharing on Cyber Threats

The aim of this article:

 Is to organize the relationship for the exchange of proactive information regarding cyber threats between the Cybersecurity Operations Center and the providers of telecommunications, information technology, and postal services in the sector, and to define the responsibilities and duties among them, so that the proactive threat information exchange service at the Cybersecurity Operations Center is capable of providing proactive information about active cyber threats targeting the sector, thereby enhancing the readiness of service providers to confront cyber threats and increasing awareness of the cyber threat landscape in the sector.

Next section title

Next section content