UNCLASSIFIED
1.2.2
Critical Information Infrastructure (CII)
The ITU regards Critical Information Infrastructure (CII) as the virtual element of
critical infrastructure. The information and communication technologies (ICTs),
that form CII, increasingly operate and control critical national sectors such as
health, water, transport, communications, government, energy, food, finance and
emergency services; their physical assets and the activities of personnel.
1.3
Policy Review Cycle
NITA-U shall review this policy, at least annually, to help ensure that it maintains
relevance to business needs, cyber threats and approaches for countering them.
1.4
Structure of National Information Security Policy
The National Information Security Framework (NISF) comprises of five tiers or
levels. This policy is at tier three. The policy presents a set of mandatory
minimum-security requirements under four headings or parts, which are:
1.5
Security governance;
Information security;
Personnel security; and
Physical security
Adaptation of Security Controls
It is important to stress that the mandated minimum requirements contained in
this policy define baseline security controls only. In reality, organisations would
have to do more than merely apply the basic security controls. As a result,
organisations must adapt the security controls provided for by this policy to their
circumstances. Adaptation is inevitable because critical infrastructures reside in
many sectors broadly grouped into health and safety, commerce and national
security. Therefore, organisations acting through their Boards, must determine
the additional security controls that they must apply to mitigate, to acceptable
levels, the cyber threats relevant to their business activities. Boards must reach
decisions on the level of security controls appropriate for their organisations by
considering their own articulated Risk Appetite, business needs and the value,
sensitivity and criticality of the information assets under consideration.
1.6
Applicable Legislation
The following legislation underpins this national information security policy:
i.
Uganda (1964), “The Official Secrets Act, 1964 – Section 4(1)(d),” The
Government of Uganda, Entebbe, Uganda.
7