UNCLASSIFIED 1.2.2 Critical Information Infrastructure (CII) The ITU regards Critical Information Infrastructure (CII) as the virtual element of critical infrastructure. The information and communication technologies (ICTs), that form CII, increasingly operate and control critical national sectors such as health, water, transport, communications, government, energy, food, finance and emergency services; their physical assets and the activities of personnel. 1.3 Policy Review Cycle NITA-U shall review this policy, at least annually, to help ensure that it maintains relevance to business needs, cyber threats and approaches for countering them. 1.4 Structure of National Information Security Policy The National Information Security Framework (NISF) comprises of five tiers or levels. This policy is at tier three. The policy presents a set of mandatory minimum-security requirements under four headings or parts, which are: 1.5  Security governance;  Information security;  Personnel security; and  Physical security Adaptation of Security Controls It is important to stress that the mandated minimum requirements contained in this policy define baseline security controls only. In reality, organisations would have to do more than merely apply the basic security controls. As a result, organisations must adapt the security controls provided for by this policy to their circumstances. Adaptation is inevitable because critical infrastructures reside in many sectors broadly grouped into health and safety, commerce and national security. Therefore, organisations acting through their Boards, must determine the additional security controls that they must apply to mitigate, to acceptable levels, the cyber threats relevant to their business activities. Boards must reach decisions on the level of security controls appropriate for their organisations by considering their own articulated Risk Appetite, business needs and the value, sensitivity and criticality of the information assets under consideration. 1.6 Applicable Legislation The following legislation underpins this national information security policy: i. Uganda (1964), “The Official Secrets Act, 1964 – Section 4(1)(d),” The Government of Uganda, Entebbe, Uganda. 7

Select target paragraph3