Policy lifecycle

  1. Draft using the policy template (purpose, scope, roles, requirements, references).
  2. Review with the control owner and, for privacy items, the DPO.
  3. Approve via the four-eyes queue; record approver + date.
  4. Publish to the documents area (versioned; old versions superseded, not deleted).
  5. Review on the defined cycle (usually annual) or on material change.

Controls & assessment

Each control has an objective, an owner, and an assessment state

(Implemented / Partially / Not implemented / Not applicable). Assess with evidence, not opinion.

Framework familyWhat it drives
NCA ECC v2Saudi national baseline (binding)
ISO 27001:2022ISMS certification
NIST CSF 2.0Outcome-based programs
SOC 2Trust-services attestation
PCI-DSS v4Card data
PDPL / NDMOPrivacy & data governance

Evidence

Attach machine-generated evidence where possible (scan output, logs, screenshots with metadata).

Every artifact is hashed (SHA-256) and stored in the evidence repository with the control reference.

Gap analysis

When coverage is incomplete, open a gap with an owner and a remediation plan (action, cost,

deadline). Track to closure; re-assess after remediation.

Compliance is a byproduct of good controls, not a paperwork exercise. Evidence first.
← Administrator Guide  ·  All guidelines