Abstract
Saudi universities systems hold extensive data. These data are exposed to many threats that can impair their security level. In Saudi Arabia, universities use registration tools to interact with the databases. The vendors that provide those tools ensure that they are secure. However, the Information and Communication Technology (ICT) of the universities have a crucial role in providing a secure infrastructure. In this paper, we are interested in raising the awareness of the important controls an ICT has to consider to prevent attackers from affecting the database.