UNCLASSIFIED
Group (NISAG) to advise the GoU on information security governance matters.
The NISS further mandated the creation of a National Computer Emergency
Response Team (CERT) under NITA-U.
3
Guiding Principles
The guiding principles below influence actions and decisions within this policy.
3.1
Top Leadership Accountability
The first principle is that the most senior person in the organisation must assume
ultimate accountability for information security. Cabinet Ministers should ensure
that MDALs report on their information risk position at least annually.
3.2
Collective Responsibility
The principle requires all individuals to accept a collective duty to contribute to
efforts to ensure that critical infrastructure assets and services obtain protection
commensurate with their value, sensitive and criticality to their organisations.
3.3
Personal Accountability
Individuals must understand and accept personal accountability for safeguarding
the assets entrusted to them and expect to answer for and/or face sanctions for
breaching security rules.
3.4
Risk Management/Proportionality
Organisations must adapt security controls to their circumstances in particular
their business needs, risk appetite, value and sensitivity of their information.
3.5
Secure/Assured Sharing
This principle requires organisations to apply suitable security controls to enable
the secure sharing of information regardless of its form and method of transfer.
3.6
Suitable, Trustworthy and Reliable Staff
Organisations must only hire staff after verifying that their character and personal
circumstances are such that they can be trusted with access to vital IT assets.
9