National Information Infrastructure Infrastructure (CNII) 1.3.2 Carry out a Cyber Security Audit on the management, operation and infrastructure to ensure CNII security and resilience 1.3.3 Assess and mitigate Cyber Security risks and threats on CNII and develop minimum security standards which operate and manage CNII Register of CNII Generate Cyber Security Audit MTC, MDJS report Risk Assessment report and MTC, MDJS minimum security standards. 1.4 Develop National 1.4.1 Perform Cyber Security risk assessment Cyber Security Risk assessment MTC, MDJS Cyber Contingency Plans and management report 1.4.2 Develop Standard Operating Procedures National Cyber Security MTC, MDJS (SOPs) Contingency plans of relevant CNIs Compiled Standard Operating Procedures 1.4.3 Develop coordination and response National Coordination MTC, MDJS framework Framework developed 1.5 Develop capability to 1.5.1. Identify processes, infrastructure and Identified systems, processes MTC, MDJS host national Cyber systems to be tested. and infrastructure Security drills/exercise 1.5.2 Establish a cyber exercise planning team Cyber exercise planning team MTC, MDJS formed 1.5.3 Conduct exercises / drills regular Cyber Security Regular exercises/drills 1.6 Establish a Cyber 1.6.1 Establish baseline security requirements Security Operation Centre 1.6.2 Establish incident reporting mechanism 19 | P a g e National Cybersecurity Strategy Cybersecurity MTC, MDJS Minimum security requirements Established and MDJS operational MDJS

Select target paragraph3