UNCLASSIFIED 2 ii. Uganda (1987), “The Security Organisations Act, 2005 – Sections 3”, The Government of Uganda, Entebbe, Uganda. iii. Uganda (2005a), "The Access to Information Act, 2005 – Section 5(1)", in The Uganda Gazette, The Government of Uganda, Entebbe, Uganda. iv. Uganda (2005b), The Uganda People's Defence Forces Act, 2005, The Government of Uganda, Entebbe, Uganda. v. Uganda (2006), The Police (Amendment) Act, 2006, The Government of Uganda, Entebbe, Uganda. vi. Uganda (2009a), "The National Information Technology Authority, Uganda Act, 2009 – Sections 5(b, (c), (d), (f), (g, (h), (n) and (r)", in The Uganda Gazette, The Government of Uganda, Entebbe, Uganda. vii. Uganda (2009b), “The National Security Council Act – Sections 2 and 3”, The Government of Uganda, Entebbe, Uganda. viii. Uganda (2010), "The Regulation of Interception of Communications Act, 2010", in The Uganda Gazette, The Government of Uganda, Entebbe, Uganda. ix. Uganda (2011a), "The Computer Misuse Act, 2011", in The Uganda Gazette, The Government of Uganda, Entebbe, Uganda. x. Uganda (2011b), "The Electronic Signatures Act, 2011 – Sections 2 and 21", in The Uganda Gazette, The Government of Uganda, Entebbe, Uganda. xi. Uganda (2011c), "The Electronic Transactions Act, 2011 – Section 23 (f)", in The Uganda Gazette, The Government of Uganda, Entebbe, Uganda. Policy Context The Government of Uganda (GoU) regards information security as an enabler of the efficient, effective, safe and secure delivery of public services. Information security also serves national security goals by protecting CII that operate and control the above-mentioned critical national sectors and their physical assets. 2.1 National Information Security Strategy The National Information Security Strategy (NISS) described the security risks of technological advance and the risk mitigation measures of such advancement. The NISS recommended the creation of the Directorate of Information Security (DIS) in accordance with the National Information Technology Authority, Uganda (NITA-U) Act, 2009. The DIS, which authored this policy, oversees and promotes information security governance, risk remediation planning and response. The NISS also recommended the creation of a National Information Security Advisory 8

Select target paragraph3