UNCLASSIFIED
2
ii.
Uganda (1987), “The Security Organisations Act, 2005 – Sections 3”, The
Government of Uganda, Entebbe, Uganda.
iii.
Uganda (2005a), "The Access to Information Act, 2005 – Section 5(1)", in
The Uganda Gazette, The Government of Uganda, Entebbe, Uganda.
iv.
Uganda (2005b), The Uganda People's Defence Forces Act, 2005, The
Government of Uganda, Entebbe, Uganda.
v.
Uganda (2006), The Police (Amendment) Act, 2006, The Government of
Uganda, Entebbe, Uganda.
vi.
Uganda (2009a), "The National Information Technology Authority,
Uganda Act, 2009 – Sections 5(b, (c), (d), (f), (g, (h), (n) and (r)", in The
Uganda Gazette, The Government of Uganda, Entebbe, Uganda.
vii.
Uganda (2009b), “The National Security Council Act – Sections 2 and 3”,
The Government of Uganda, Entebbe, Uganda.
viii.
Uganda (2010), "The Regulation of Interception of Communications Act,
2010", in The Uganda Gazette, The Government of Uganda, Entebbe,
Uganda.
ix.
Uganda (2011a), "The Computer Misuse Act, 2011", in The Uganda
Gazette, The Government of Uganda, Entebbe, Uganda.
x.
Uganda (2011b), "The Electronic Signatures Act, 2011 – Sections 2 and
21", in The Uganda Gazette, The Government of Uganda, Entebbe,
Uganda.
xi.
Uganda (2011c), "The Electronic Transactions Act, 2011 – Section 23
(f)", in The Uganda Gazette, The Government of Uganda, Entebbe,
Uganda.
Policy Context
The Government of Uganda (GoU) regards information security as an enabler of
the efficient, effective, safe and secure delivery of public services. Information
security also serves national security goals by protecting CII that operate and
control the above-mentioned critical national sectors and their physical assets.
2.1
National Information Security Strategy
The National Information Security Strategy (NISS) described the security risks of
technological advance and the risk mitigation measures of such advancement.
The NISS recommended the creation of the Directorate of Information Security
(DIS) in accordance with the National Information Technology Authority, Uganda
(NITA-U) Act, 2009. The DIS, which authored this policy, oversees and promotes
information security governance, risk remediation planning and response. The
NISS also recommended the creation of a National Information Security Advisory
8