All links to official websites of government agencies in the Kingdom of Saudi Arabia end with .gov.sa
Secure websites in the Kingdom of Saudi Arabia use the HTTPS protocol for encryption.
These Controls aim to be Enhance the government entity's ability to proactively identify risks and threats, and to work to develop appropriate treatment plans to reduce the consequences of the availability and to work on develop appropriate treatment plans to reduce the consequences of the availability of the digital services through the compliance of government entities, suppliers and operators of digital government services to implement and maintain an effective Risk Management Program that provides the necessary capabilities to identify and reduce the consequences of potential and future risks.
Regarding Cabinet Resolution No. (418) dated 25/7/1442 AH, which approved the regulation of the Digital Government Authority (DGA), it stipulates that DGA is the competent authority for all matters related to digital government and serves as the national reference in this domain. Pursuant to its mandate, DGA shall “develop the technical standards for digital transformation models in government sectors and monitor compliance with them in coordination with the relevant authorities.”
In line with the aforementioned, DGA strives to enhance digital performance across government agency, improve the quality of services delivered, and elevate the end-user experience, all in alignment with the ambitious goals of Vision 2030.
DGA paves the way for government agency to deliver high-quality, efficient digital government services that drive investment returns, strengthen the value of the national economy, and enable the measurement of government agency’ performance and capabilities in the digital government domain.
From this perspective, DGA issued the fourth version of the “Controls of Risk Management and Business Continuity for Digital Government” in accordance with the regulations issued by the competent authorities. DGA remains responsible for regularly updating and reviewing this document to reflect evolving requirements.
These controls form part of the regulatory framework for digital government, which contributes to raising the maturity level of digital government services and strengthening agency’ ability and flexibility to identify risks and threats proactively. This is achieved through the establishment of a continuously improving risk management system and the development of business continuity plans. Such plans address response and recovery from service disruptions, aiming to minimize negative impacts and ensure the sustainability of digital government services. This objective is further reinforced by establishing and activating a business continuity management system, verifying its effectiveness, and pursuing continuous improvement.
In this version, DGA updated the controls related to the activation phase of the Business Continuity Management System, particularly those addressing the development of disaster recovery plans for information and communication technology. These updates enhance the readiness of government agency by providing and testing technical alternatives and solutions. Furthermore, the classification matrix for platforms, applications, and services was updated to serve as a comprehensive framework. Collectively, these efforts aim to ensure the reliability and continuity of digital government services across government agency.

The requirements and standards set forth herein shall apply to all government agency providing digital services and products, as well as to operators, regardless of their type, size, or nature. Their applicability shall be determined based on the agency’s operating environment, level of complexity, and number of geographical locations.
Refined: Pursuant to paragraph 9 of Article 4 of the Digital Government Authority Regulation—which stipulates that the Authority shall "develop the technical standards for digital transformation models in government sectors and follow up on compliance with them, in coordination with the relevant authorities", DGA shall assess and measure the extent to which government agency comply with these controls following the mechanism determined by the DGA.
For more information; Check the digital version.
39 Visitors Said Yes from 42
Suggestions and comments
For any inquiries or comments about the services or the current page, please fill in the required information.
Add Comment