MyMIS ICT security management safeguards The ICT security management safeguard identify five (5) major elements that should be considered by all public sector ministries, departments and agencies to protect their ICT systems. These elements are the ICT security policy, ICT security management programme, ICT security risk management, planning and incorporation of ICT security into the ICT systems life cycle and establishing ICT security assurance. The handbook further explains some fundamental operational components of ICT security that is best recognised by public sector employees. Technical details of ICT security Technical security involves the use of safeguards incorporated into computer and communications hardware and software, operations systems or applications software and other related devices. This chapter explains the technical level of ICT security in greater detail. Legal implications The last chapter of this handbook briefly explains legal matters with respect to Malaysian law. It highlights Malaysian cyber laws and the various aspects of criminal investigations. The appendices of this handbook provide some samples of framework, plan, checklist and forms useful in the ICT security management process. 1.4 Audience Main objective is to provide guidance to all government employees The main objective of this handbook is to provide guidance to employees within government agencies on the essential components of ICT security. It is intended to be the primary reference book used by all government employees in safeguarding the government’s ICT assets. The handbook is for ALL government employees Various categories of government employees will benefit from the handbook as it covers a wide range of topics. Nevertheless this handbook is also useful to anyone wishing to learn about the application of ICT security. Organisation of the content of the handbook The handbook is presented in five (5) chapters that can be divided into three (3) different levels; Essential, Intermediate and Advanced (Figure 1.2). The Essential level, which comprises of Chapter 1, Chapter 2 and Chapter 5, provides fundamental knowledge on ICT security and is suitable for chief executives and managers in the public sector. The Intermediate i.e. Chapter 3 is intended for general ICT users of the public sector. The description and explanation will provide guidance to users on the basic operational security safeguard to be implemented and maintained by them. The Advanced stage i.e. Chapter 4 is proposed for the more experienced ICT administrators and managers. The descriptions on technical details of ICT security should provide guidance and direction on steps that need to be taken to ensure the confidentiality, integrity and availability of public sector ICT systems. Copyright MAMPU Chapter 1 - 4

Select target paragraph3