Cambodian ICT Masterplan 2020 First, in pursuing e-Government and public-sector informatization initiatives, a comprehensive framework act that sets out broad outlines and high-level principles should be introduced. This framework act must include key provisions on legal grounds for large-scale, long-term investments, coordination systems among government agencies concerned, policy development to bridge digital divide, informatization planning, progress monitoring and assessment, as well as effective IRM. Second, proactive campaigns and education programs designed to raise awareness of informatization initiatives as collective efforts of the government and citizens should be conducted. To this end, support for such programs and capacity-building activities for government officials and citizens needs to be guaranteed by law, especially in the early stage of informatization. Lastly, in parallel with the high-level principles laid down in the framework act, subsidiary legislations of each relevant government department should be drawn up either simultaneously or sequentially. The good examples of such subsidiary legislations include the Digital Signature Act, Electronic Commerce Act, Personal Information Protection Act, Citizen Registration Act, Customs Act, and Government Procurement Act. 6. Cyber Security 6.1 Introduction As ICT infrastructure policies are vitalized, information security becomes important issues in Cambodia as well as in the world. However, although Cambodia has tried to establish national cyber security base through CamCERT organization, there are some limitations such as lack of comprehensive cyber security system to ensure ICT service reliability, absence of relevant laws, regulations, policy, standard & norm, low level of knowledge and know-how skill on cyber security, and outdated infrastructure for cyber security (e.g. Information systems, ICT devices). To overcome these limitations and enhance the nationwide cyber security, it is needed to enhance cyber security system in Cambodia such as enactment completion of relevant legislations and establishment of government-wide leadership & organization. Moreover, it is necessary to expand cyber security activities through enhancing CERT system, protecting major infrastructure and distributing the standard. It is also crucial to build health culture for cyber security through making measures for unhealthy information distribution prevention, implementing illegal spam mail prevention system and executing awareness education & promotion for cyber security. 18

Select target paragraph3