UNCLASSIFIED Group (NISAG) to advise the GoU on information security governance matters. The NISS further mandated the creation of a National Computer Emergency Response Team (CERT) under NITA-U. 3 Guiding Principles The guiding principles below influence actions and decisions within this policy. 3.1 Top Leadership Accountability The first principle is that the most senior person in the organisation must assume ultimate accountability for information security. Cabinet Ministers should ensure that MDALs report on their information risk position at least annually. 3.2 Collective Responsibility The principle requires all individuals to accept a collective duty to contribute to efforts to ensure that critical infrastructure assets and services obtain protection commensurate with their value, sensitive and criticality to their organisations. 3.3 Personal Accountability Individuals must understand and accept personal accountability for safeguarding the assets entrusted to them and expect to answer for and/or face sanctions for breaching security rules. 3.4 Risk Management/Proportionality Organisations must adapt security controls to their circumstances in particular their business needs, risk appetite, value and sensitivity of their information. 3.5 Secure/Assured Sharing This principle requires organisations to apply suitable security controls to enable the secure sharing of information regardless of its form and method of transfer. 3.6 Suitable, Trustworthy and Reliable Staff Organisations must only hire staff after verifying that their character and personal circumstances are such that they can be trusted with access to vital IT assets. 9

Select target paragraph3