Page 3.6 3.7 3.8 3.9 Mass Storage Media 3 - 14 3.6.1 Protection of Information in Storage Media 3 - 14 3.6.2 Environmental Considerations 3 - 14 3.6.3 Disposal of Storage Media 3 - 15 3.6.4 Non-Current Storage Media 3 - 15 3.6.5 Intellectual Property Rights 3 - 15 3.6.6 Vendors, Contractors, External Service Providers, Third Party Access 3 - 15 Business Resumption 3 - 16 3.7.1 Risk Analysis 3 - 16 3.7.2 Disaster Recovery/Contingency Plan 3 - 16 Public Sector ICT Security Incident Handling 3 - 18 3.8.1 Causes of Security Incidents 3 - 19 3.8.2 Handling Security Incidents 3 - 19 3.8.3 Developing Security Incidents Handling Capability 3 - 19 3.8.4 Issues to Consider When Setting an Incident Handling Capability 3 - 21 Public Sector ICT Security Awareness, Training, Acculturation And Education 3.9.1 3.9.2 3 - 21 Benefits of Public Sector ICT Security Awareness, Training, Acculturation and Education 3 - 22 Public Sector ICT Security Awareness 3 - 23 3.9.2.1 Techniques 3 - 24 3.9.3 3 - 25 Public Sector ICT Security Training & Acculturation 3.9.3.1 General Users 3 - 25 3.9.3.2 Specialised or Advanced Skills Users 3 - 26 3.9.4 Public Sector ICT Security education 3 - 26 3.9.5 Implementation 3 - 26 3.9.5.1 Understand the Core Business of the Organisation 3 - 26 Identify Gaps in Public Sector ICT Security Knowledge 3 - 27 Align Skill Gaps to Support the Organisation’s Core Business 3 - 27 3.9.5.4 Identify Suitable Staffs 3 - 27 3.9.5.5 Allocate Financial Resources and Identify Training Location 3 - 27 Execute, Maintain and Evaluate Programme Effectiveness 3 - 28 3.9.5.2 3.9.5.3 3.9.5.6 viii

Select target paragraph3