Every Government Agency must adhere to the following:
1- Register the domain names of its websites in accordance with the regulations and rules issued by the Saudi Network Information Center at the Communications and Information Technology Commission.
2- Clearly display its name and logo on its websites, adopting the Arabic version of the main interface by default, and provide the following:
A- The administrative reference for non-independent government agencies.
B- Contact numbers, email, and any additional electronic means for communication with the services of the government agency, benefiting from the services of the government agency.
C- A notice of privacy protection, intellectual property rights, and a disclaimer stating that the agency bears no legal responsibility for the use of data or information published on its websites.
D- A user agreement that includes the consequences of misuse of information systems, resources, and electronic links related to the applicable regulations.
E- Highlight the activities and achievements in its field of work.
F- A recent copy of the information necessary for the services provided to beneficiaries.
G- Information about its social media accounts, if available.
3- Host its websites, information, and services, along with the required information systems and resources within the Kingdom, and do so either by itself, through other government agencies, or through hosting service providers licensed by the Communications and Information Technology Commission, ensuring that the hosting contract between the parties includes provisions to guarantee the confidentiality of information.
1- Each government entity must provide at least one general government email address.
2- Correspondence via the general or private government email is considered the property of the government entity, and the relevant authorities have the right to access such correspondence in the presence of a legal justification.
3- The use of the general or private government email is restricted to official correspondence related to work only, and the user is not permitted to send emails in their name when using the general government email. Additionally, the use of any personal email for official work-related correspondence is not allowed.
4- Each government entity must include a disclaimer regarding the contents of the general or private government email in its electronic messages.
5- Each government entity must host its email within the Kingdom either through itself, through other government entities, or through hosting service providers licensed by the Communications and Information Technology Commission. The hosting contract between the parties must include provisions to ensure the confidentiality of information, without prejudice to the regulations related to data classification, personal data protection, and any directives issued in this regard by the relevant authorities.
6- The user's government email address must be included on the business card issued by their entity - if available - and no personal email may be placed on it.
Every government entity must:
1- Adhere to what is issued by the relevant government entities in the field of cloud computing and emerging technologies, including policies, governance mechanisms, frameworks, standards, controls, and guidelines related to that.
2- Consider cloud computing and emerging technologies within its strategy.
1- Every government entity shall do the following:
A- Adhere to the regulations, rules, and instructions related to electronic official documents and information concerning its employees and clients when classifying or storing electronic official documents and information.
B- Ensure the lawful use of government information technology assets in a manner that does not conflict with the relevant regulations and rules, and not to use them for the following:
1) Any illegal act or purpose, or that conflicts with public morals and ethics.
2) Anything that leads to their waste, or the waste of the user's time.
3) Anything that adversely affects their performance, or that of other users.
4) Accessing other users' accounts without permission from the authorized owner.
2- Without prejudice to what is stated in subparagraph (B) of paragraph (1) of this item, the government entity may allow its authorized employees to use some government information technology assets for personal purposes, provided that it does not conflict with the regulations, rules, and policies of the entity.
Every government entity must adhere to the following:
1- What is issued by the National Cybersecurity Authority - in accordance with its competencies and missions - including policies, governance mechanisms, frameworks, standards, controls, and guidelines related to cybersecurity. This does not absolve the entity from taking the necessary measures to protect its cybersecurity in a manner that does not conflict with the competencies and missions of the Authority.
2- The use of electronic signatures and everything related to the authentication of data, documents, automated documents, and electronic correspondence in accordance with the Electronic Transactions Law, issued by Royal Decree No. (M/18) dated 8/3/1428 AH, in coordination with the National Center for Digital Certification, and in accordance with what is issued by the National Cybersecurity Authority to protect data in this regard.
Every government entity must adhere to the regulations set by the relevant authorities regarding its use of social media.
1- Every government agency must train the employees - authorized - on the use of information systems and resources and how to deal with them as needed, ensuring the success of information technology projects and compliance with related policies and regulations.
2- Every government agency must benefit from the shared national information systems and applications provided by the relevant central government agencies and the Government Electronic Transactions Program (Yesser), which are designated for use by government agencies, and avoid securing them individually.
3- Every government agency must attract national competencies and cadres, train them, and develop their capabilities in the field of information technology.
4- Every government agency must raise awareness among its members about the necessity of complying with all regulations and rules related to the controls for using information and communication technologies in government agencies.
5- The user must adhere to these controls, and the government agency must take the necessary measures to ensure their application to everyone authorized to use its information systems and resources, without prejudice to the regulations, rules, controls, and standards issued by other relevant entities.
6- Violating the provisions contained in these controls exposes the violator to accountability and the imposition of disciplinary and penal measures in accordance with the relevant regulations.
7- The Ministry of Communications and Information Technology, in coordination with the relevant entities, will review these controls every three (3) years from the date of their issuance.
8- These controls shall be effective from the date of their approval.
9- These controls replace the controls for using computers and information networks in government agencies, issued by Council of Ministers Resolution No. (81) dated 19/3/1430 AH.