Annex 1: Documents referred to in the Policy
Government Information Security Policy
This model policy is aligned to the information
security standard ISO /IEC 17799. Government
organizations may modify and customize this policy
to suit their respective organizations' needs, and
thus create organizational information security
policies. The policy is available in the Re-engineering
government section in www.icta.lk.
ISO 8601
The International Standard for the representation of
dates and times. The standard describes a large
number of date/time formats. The document can
be purchased from the Sri Lanka Standards
Institution, Elvitigala Mawatha, Colombo 08.
ISO 10646
ISO/IEC 10646 was published in 1993. Its name is
“Universal Multiple-Octet Coded Character Set”. It
is a standardized coded character set with the
purpose to eventually include all characters used in
all the written languages in the world (and, in
addition, all mathematical and other symbols). The
current edition covers at least all major languages.
ISO / IEC 17799
The international Information Security standard,
ISO/IEC 17799, Second Edition, 2005, is
comprehensive in its coverage of security issues,
and establishes guidelines and general principles for
initiating, implementing, maintaining and improving
security management in an organization. The
standard was originally prepared by the British
Standards Institution (as BS 7799 Part 1) and was
later adopted by ISO (the International Organization
for Standardization and IEC (the International
Electro-technical Commission).The document can be
purchased from the Sri Lanka Standards Institution,
Elvitigala Mawatha, Colombo 08.
Section 15:
obligations, and of any security requirements.
Especially, relevant is section 15.1.3 Protection of
organizational records, wherein the following
controls are given;
Important records should be protected from loss,
destruction, and falsification in accordance with
22