procedures, as relevant for their job function, roles, responsibilities and skills.
SA 4.
Employees should be trained to recognize social engineering attempts on them and not disclose
any information that could violate the Agency’s security policies, such as during social gatherings,
public events and training events.
SA 5.
Contents of the security training and awareness are reviewed and updated regularly to reflect
new trends, new threats, and changes to the Agency’s information technology infrastructure or
applicable laws and regulations.
SA 6.
New employees are provided information security awareness training as part of the employee
induction process and refresher training must be conducted on periodic basis.
SA 7.
Training is followed up with an assessment, to ascertain the effectiveness of the programme,
including maintaining of records of attendance of security awareness programmes.
SA 8.
Indirect media such as posters, intranet, email, etc. may be used effectively to support the
awareness programme.
8. Incident Management [IM]
8.1. Policy Objective
An information security incident is an event that impacts on the confidentiality, integrity or availability of an information
system or network, through an act that contravenes prescribed security policy and or applicable laws or regulations.
For the purposes of this policy, an incident is defined as a violation or imminent threat of violation of computer security
policies, acceptable use policies, or standard security practices.
This policy intends to provide a reference for the Agency’s management, administration and other technical and
operational staff to facilitate the development of information security incident management capability, and to be used
for preparation for, detection of and response to information security incidents.
8.2. Policy & Baseline Controls
To meet the requirement of this Policy, Agencies MUST:
IM 1.
*Appoint a person to own and manage the Incident Management programme, including a
point of contact for all information security communications.
IM 2.
Establish an information security incident response capability, based on the [IAP-NAT-DCLS] which
is capable of making a periodic risk assessment (from threat, vulnerability and asset value) of data,
processes, systems and networks in accordance with this Information Assurance Manual.
IM 3.
*Define procedures to detect, evaluate and respond to incidents.
IM 4.
Define procedures to report, manage and recover from information security incidents, internally,
with Q-CERT and with other Agencies.
IM 5.
*Create awareness amongst its staff to report incidents.
IM 6.
Categorise and prioritize all incidents according to the incident criticality classification provided in
Appendix C.
IM 7.
Co-ordinate with Q-CERT to create a repository of incidents in the Agency.
IM 8.
*Report all Criticality Level 1 incidents to Q-CERT within one (1) hour of identification.
IM 9.
The Incident Management coordinator is responsible for developing and executing an annual
Security Assurance Plan. This may include activities such as penetration testing, audit of security
procedures, and incident scenario testing.
9. Business Continuity Management [BC]
9.1. Policy Objective
This document provides Agencies guidance in the development and implementation of a comprehensive Business
Continuity (BC) plan to enable organizations to recover, operate and deliver essential business processes and services
23
NATIONAL INFORMATION ASSURANCE MANUAL