National
Information Infrastructure
Infrastructure (CNII)
1.3.2 Carry out a Cyber Security Audit on the
management, operation and
infrastructure to ensure CNII security
and resilience
1.3.3 Assess and mitigate Cyber Security
risks and threats on CNII and develop
minimum security standards
which operate and manage CNII
Register of CNII
Generate Cyber Security Audit MTC, MDJS
report
Risk Assessment report and MTC, MDJS
minimum security standards.
1.4
Develop
National 1.4.1 Perform Cyber Security risk assessment Cyber Security Risk assessment MTC, MDJS
Cyber Contingency Plans and management
report
1.4.2 Develop Standard Operating Procedures National
Cyber
Security MTC, MDJS
(SOPs)
Contingency plans of relevant
CNIs
Compiled Standard Operating
Procedures
1.4.3 Develop coordination and response National
Coordination MTC, MDJS
framework
Framework developed
1.5 Develop capability to 1.5.1. Identify processes, infrastructure and Identified systems, processes MTC, MDJS
host
national
Cyber systems to be tested.
and infrastructure
Security drills/exercise
1.5.2 Establish a cyber exercise planning team Cyber exercise planning team MTC, MDJS
formed
1.5.3
Conduct
exercises / drills
regular
Cyber
Security Regular
exercises/drills
1.6 Establish a Cyber 1.6.1 Establish baseline security requirements
Security
Operation
Centre
1.6.2 Establish incident reporting mechanism
19 | P a g e
National Cybersecurity Strategy
Cybersecurity MTC, MDJS
Minimum security requirements
Established
and
MDJS
operational MDJS