Triple S Arena…

DATA & SYSTEMS PROTECTION

Triple S Arena Data & Systems Protection Policy

Startime’s policy for protecting data, systems, and operational processes within Triple S Arena.

CYBERSECURITY POLICY

A Secure Framework for Digital Operations

1. Introduction

Startime is committed to implementing the highest cybersecurity standards to safeguard all data, systems, and operational processes within Triple S Arena. This commitment aligns with the requirements of the National Cybersecurity Authority (NCA) and internationally recognized frameworks.

This policy aims to ensure confidentiality, integrity, and availability of information, while providing a secure digital environment that supports Startime’s operational excellence and digital transformation objectives.

2. Scope

This policy applies to all Triple S Arena users, including employees, clients, partners, vendors, and contractors. It also covers all data stored or processed within the system, all connected infrastructure, and all access, modification, sharing, and workflow activities performed through the platform.

3. Data Protection & Privacy

Startime treats data as a critical organizational asset. All information is classified according to its sensitivity, including financial data, contractual records, operational files, and personal information related to employees, clients, and vendors.

The platform enforces strict privacy controls, including encryption of data in transit and at rest, restricted access based on user roles, and compliance with national privacy regulations. No data may be shared outside the system without formal authorization, and all operational records are maintained in a secure and controlled environment.

4. Identity & Access Management

Triple S Arena employs a robust Role-Based Access Control (RBAC) model to ensure that each user receives only the permission required for their role.

Multi-Factor Authentication is mandatory for all users, and access rights are reviewed regularly to prevent excessive or unauthorized access. All login, modification, deletion, and sharing activities are logged in a centralized audit trail.

Shared accounts are strictly prohibited, and any request for additional access must be formally approved.

5. Account & Session Security

Startime enforces strong password policies, periodic password renewal, automatic session timeout, and continuous monitoring of failed login attempts. Conditional access controls are applied based on device type and geographic location.

Any unusual activity triggers immediate protective measures to ensure account and system integrity.

6. System & Infrastructure Security

The platform uses industry-standard encryption technologies, including TLS 1.3 for data in transit and AES-256 for data at rest.

Systems undergo regular security updates, continuous vulnerability monitoring, and segmentation of sensitive environments. Backup and recovery procedures ensure business continuity in the event of a system failure or cyber incident.

7. Incident Response

Startime maintains a comprehensive Incident Response Plan that outlines procedures for reporting, analyzing, documenting, and resolving cybersecurity incidents.

In the event of a breach or attempted intrusion, the organization takes immediate action to contain the threat, restore operations, and coordinate with relevant authorities as required by Saudi regulations.

8. Awareness & Training

Startime provides ongoing cybersecurity training to all employees, reinforcing awareness of cyber threats and safe digital practices.

Periodic phishing simulations and security drills are conducted to ensure readiness and adherence to security protocols.

9. User Responsibilities

All users are responsible for protecting their login credentials, refraining from unauthorized data sharing, reporting unusual activity, and complying with all security and acceptable-use policies.

Any violation of these responsibilities is considered a breach of Startime’s cybersecurity standards.

10. Compliance & Review

Startime adheres fully to the cybersecurity controls mandated by the NCA, as well as international standards such as ISO 27001 and NIST CSF.

This policy is reviewed periodically to ensure alignment with evolving cybersecurity threats and regulatory requirements.