1. Systems Implementation and Governance
The implementation, operation, and continuous enhancement of organizational information systems constitute one of the key processes within the Information and Communication Technology (ICT) Management. The principal responsibilities of this unit include:
· Planning, researching, and identifying the latest developments in information and communication systems and technologies, aligning them with operational requirements, and implementing appropriate solutions to enhance the Company's information and communication capabilities, including the development of decision-support systems for management.
· Leading, directing, and planning the design, development, implementation, and maintenance of information systems to provide and support required business applications and information technology services in software and information management domains for all departments, business units, and affiliated subsidiary companies.
· Supervising the preparation, development, and maintenance of documentation, regulations, and standards related to all information systems within the Company, with a focus on systems integration and knowledge management, as well as organizing and maintaining such resources to ensure reliable system development, operation, and dissemination of organizational knowledge across the Company.
· Overseeing the assessment and preparation of information systems development plans in accordance with ICT and corporate strategies; managing, supervising, and controlling the preparation of Requests for Proposal (RFPs), business requirements, and tender documentation for ICT projects; and conducting technical, commercial, and qualitative evaluations of bidders through the Tender Committee process.
· Establishing system-wide coordination and standardization across all Company information systems by considering system architectures, foundational software platforms, databases, and operational procedures.
· Collaborating with other ICT divisions and corporate departments in assessing, forecasting, and developing short-term and long-term plans to address the Company's future information systems requirements.
· Designing and implementing essential programs and projects aimed at improving the performance of information and communication systems, including process optimization, enhancement of information security and data protection, and improvement of IT service quality.
· Applying recognized standards and industry best practices throughout the development and testing lifecycle of information systems.
· Monitoring system performance, resolving operational issues, and providing technical solutions and user support to ensure the continued efficiency, reliability, and productivity of information systems.
· Enhancing information systems capabilities through migration to modern technologies, adoption of innovative tools and methodologies, and continuous improvement of ICT infrastructure.
· Conducting training programs to educate employees on the effective use of newly implemented information systems and the optimal utilization of information technology tools and practices.
· Evaluating the performance and outcomes of information and communication systems development and implementation projects, and preparing reports and recommendations aimed at improving operational effectiveness and increasing organizational productivity.
2. Network Infrastructure and Support
The principal responsibilities of the Network Infrastructure and Support Unit include:
· Designing and implementing network infrastructure for users at the National Iranian Oil Refining and Distribution Company's headquarters.
· Designing, managing, and monitoring communication networks connecting subsidiary companies with the Ministry of Petroleum and other affiliated entities within the Ministry.
· Designing, developing, and continuously upgrading data center infrastructure in accordance with evolving information technology requirements and industry best practices.
· Utilizing state-of-the-art technologies for uninterruptible power supply (UPS) systems, environmental control and cooling systems, as well as fire detection and suppression systems within the data center environment.
· Performing routine network administration, infrastructure maintenance, monitoring, and support activities to ensure the reliability, availability, and security of ICT services.
3. Information Systems, Information Security and Cybersecurity
In recent years, senior management has increasingly recognized the strategic importance of Information Technology (IT) management. In an era where information technology has become an integral component of organizations of all sizes and sectors, aligning IT initiatives with business objectives, optimizing technology investments, and maximizing value creation through IT have emerged as key challenges, particularly in the domain of digital and online services. Addressing these challenges effectively requires a controlled and governed environment supported by active oversight from executive management.
Business operations are highly dependent on information technology. Any disruption to IT services, security incidents, or non-compliance with external regulations and requirements can significantly impact organizational performance, resulting in both tangible losses, such as financial costs, and intangible losses, including reduced customer confidence and reputational damage. Sustainable success in today's competitive environment depends on effective governance, management, and security of information technology services. Consequently, organizations must place greater emphasis on strengthening cybersecurity, enhancing IT service performance, and establishing robust governance frameworks.
Recognizing the critical role of information security, the Information Systems and Information Security Office within the Information and Communication Technology (ICT) Management of the National Iranian Oil Refining and Distribution Company (NIORDC) is responsible for addressing evolving and sophisticated cyber threats through the selection and implementation of appropriate security solutions, with priority given to indigenous technologies and products. This process begins with identifying critical assets, assessing potential threats, defining security requirements and principles, and implementing suitable safeguards to protect organizational information and systems.
Implemented and Ongoing Initiatives
Information Security Management System (ISMS)
Risk Management: Risk management is a structured process through which risks are identified, analyzed, assessed, and treated. Appropriate mitigation measures are implemented to reduce risks to an acceptable level while ensuring the continuity and security of business operations.
Roles and Responsibilities: Roles and responsibilities are assigned according to organizational positions and business functions. Appropriate levels of authority, access privileges, and information resource permissions are defined and managed in accordance with job responsibilities and security requirements.
Information Security Documentation: Comprehensive documentation is essential for the effective implementation of information security controls. Security policies, standards, procedures, and operational guidelines are formally documented to ensure consistency, compliance, and continuous improvement.
Penetration Testing:
Systems Security Validation: The Information Systems and Information Security Office utilizes advanced technical methodologies and specialized assessment tools to evaluate the security posture of organizational information assets and systems. Through security audits and penetration testing conducted in accordance with recognized standards and best practices, classified information assets, information systems, and network infrastructures are assessed to determine residual risk levels and verify the effectiveness of implemented security controls.
Security Operations Center (SOC)
Information Security Monitoring: Information security is a continuous process that requires ongoing monitoring and vigilance. Vulnerabilities may arise from weaknesses in system design, implementation, maintenance, change management activities, or evolving cyber-attack techniques and technologies. Continuous monitoring enables the identification of emerging vulnerabilities and helps maintain a resilient security posture against both known and unknown threats.
As part of its monitoring activities, the Information Systems and Information Security Office oversees the performance and security of information systems and technology resources while conducting vulnerability management activities, including vulnerability identification, assessment, analysis, and remediation. In addition, the office manages change-related security risks by monitoring system modifications, identifying disruptions, weaknesses, and potential security gaps, and ensuring timely corrective actions.
Cybersecurity Incident Management: Cybersecurity incidents can have significant adverse effects on business operations, potentially resulting in financial losses, information disclosure, service disruptions, and reputational damage. To strengthen organizational cyber resilience and ensure effective response capabilities, the Information Systems and Information Security Office is developing and implementing a comprehensive Cybersecurity Incident Response Program through the establishment of a Computer Security Incident Response Team (CSIRT).
4. ICT Studies, Planning and Architecture
One of the core Information and Communication Technology (ICT) management processes is the “ICT Strategy Planning and Development Process”. This process is recognized as a key and fundamental discipline within internationally recognized ICT frameworks such as ITIL, COBIT, and IT4IT, and is typically incorporated as a major function within ICT organizational structures.
The responsibilities of this function include:
- Planning for the implementation and compliance with all applicable corporate directives and ensuring that existing methods and procedures conform to relevant regulations, policies, and standards.
- Planning for the review and update of the Company's ICT Strategic Plan and assessing the status of activities carried out in alignment with the plan.
- Planning to establish consistency, coherence, and integration across all ICT-related activities, operations, and processes within the National Iranian Oil Refining and Distribution Company (NIORDC) and its subsidiaries.
- Monitoring and controlling project schedules and preparing progress reports for ongoing ICT projects.
- Overseeing the development of ICT methodologies, procedures, and standards across all functional domains.
- Planning and conducting studies to identify emerging ICT capabilities, technologies, and applications, and proposing appropriate solutions for the development and delivery of innovative services.
- Supervising the preparation and development of RFP (Request for Proposal) and RFQ (Request for Quotation) documents for all ICT projects.
- Monitoring technological developments, evaluating and selecting emerging technologies, and planning for the adoption of technological advancements to improve business and operational performance.
- Designing, developing, and periodically reviewing ICT objectives, strategies, and plans based on the Company's vision and corporate policies across NIORDC and its subsidiaries, while overseeing the implementation of approved projects and reporting outcomes.
- Taking the necessary actions to communicate and disseminate approved ICT objectives, strategies, and policies to all relevant organizational units.
- Developing the Company's ICT and e-Government implementation programs, pursuing their approval, and reporting progress to relevant authorities.
- Developing and maintaining ICT performance indicators, including KRIs (Key Risk Indicators), KPIs (Key Performance Indicators), and PIs (Performance Indicators).
- Designing, developing, and improving ICT-related business processes; establishing and enhancing process management, quality assurance, and performance optimization procedures, guidelines, and templates for business processes and information systems.
- Implementing, maintaining, and updating strategic ICT initiatives and frameworks, including COBIT, ITIL, and the ICT Master Plan.
- Developing, maintaining, and obtaining approval for the ICT Reference Architecture and Enterprise Architecture of the Company.
- Facilitating inter-organizational coordination and integration in the development and deployment of e-Government infrastructures and public digital services.
- Managing, monitoring, and overseeing the implementation of the One-Stop Electronic Service Portal across NIORDC headquarters and subsidiary companies.
- Preparing, compiling, and submitting periodic and ad hoc reports on ICT and e-Government performance indicators to competent internal and external authorities in coordination with subsidiary companies.
- Designing and developing mechanisms, procedures, and governance structures for the implementation of e-Government initiatives, including the establishment and management of related working groups.
- Overseeing the continuous improvement of the effectiveness and efficiency of ICT processes and practices across headquarters and subsidiary companies to accelerate and facilitate service delivery to employees and citizens.
- Designing ICT-related training programs, pursuing their approval and implementation, and contributing to the enhancement of organizational culture regarding the effective use of information technology.
- Planning, managing, and controlling ICT budgets and resources.
- Providing technical advisory and support services to managers and employees on ICT-related matters and guiding them in the effective use of information systems and digital tools to enhance performance and productivity.
- Planning studies and assessments of the information architecture of all organizational units based on existing business processes, and proposing improvements or, where necessary, business process reengineering initiatives to enhance responsiveness and alignment with current and future stakeholder needs.