No. 39475 85
STAATSKOERANT, 4 DESEMBER 2015
NATIONAL CYBERSECURITY POLICY FRAMEWORK FOR SOUTH AFRICA
who monitor, (e.g. the Auditor General), to ensure that solutions are implemented in
accordance with certification conditions and legislation.
e)
Establishing a body that will centrally coordinate the required national verification
functions.
8.
8.1
NCII Protection
The NCPF recognises the need to provide a mechanism to ensure that South Africa's
critical information infrastructure is protected and secured against cyber related crimes. It is
also noted that a more secured critical information infrastructure will help to achieve the
continued provision of essential services and support national security, economic prosperity
and social well-being of the Republic. The policy framework recognises that a significant
proportion of SA's national critical information infrastructure (NCII) is privately owned or
operated on a commercial basis.
8.2
The NCPF therefore seeks to ensure that appropriate steps are taken to ascertain that all
National Critical Information Infrastructure (NCII) are identified and properly protected from
a variety of threats. For continued availability of the critical information infrastructure, the
NCPF thus promotes the development of a National Critical Information Infrastructure
(NCII) Strategy that will address the identification and protection of NCII by:
a)
Developing National Critical Information Infrastructure regulations, relating, inter alia, to:
i.
Information Classification and Information Security Policy and Procedures;
ii.
Third Party Access to NCII;
iii.
Access to and authentication on NCII;
iv.
Storage and archiving of critical databases;
v.
vi.
b)
Incident management and business continuity; and
Physical and technical protection of all NCII.
Facilitate an effective business - government partnership relating to the implementation
of the Gil Protection Plan. To this end, the private sector, State Owned Enterprises
(SOE's), and other government agencies and institutions such as the State Information
Technology Agency (SIT A) will play a critical role in ensuring the implementation of NCII
protection plan.
20
This gazette is also available free online at www.gpwonline.co.za