“incident handling” means a systematic approach to effectively manage and respond to security incidents or disruptions in information technology systems or infrastructure; “information system” means a system for generating, sending, receiving, storing, displaying or otherwise processing data and electronic messages, including internet; “owner” in relation to critical information infrastructure includes a person who operates or exercises control of the critical information infrastructure; “proactive services” means a systematic approach of identifying potential cybersecurity issues or needs before they become significant problems for individuals or organizations; “reactive services” means a response to, and mitigation of, cybersecurity incidents that have already occurred; “sectoral CERT” means a specialized group or organization that is responsible for handling and responding to cybersecurity incidents within a specific sector or industry; and “vulnerability” means a weakness, susceptibility or flaw of an information and communication technology product or service that can be exploited by a cyber threat. Objectives of this Act 3. – (1) The objectives of this Act are to set up a responsive information and communication technology legal framework that shall ensure the security of information and information communication and technology infrastructure. 8

Select target paragraph3