MyMIS
ICT security management
safeguards
The ICT security management safeguard identify five (5) major elements
that should be considered by all public sector ministries, departments and
agencies to protect their ICT systems. These elements are the ICT security
policy, ICT security management programme, ICT security risk management,
planning and incorporation of ICT security into the ICT systems life cycle
and establishing ICT security assurance.
The handbook further explains some fundamental operational components
of ICT security that is best recognised by public sector employees.
Technical details of ICT
security
Technical security involves the use of safeguards incorporated into computer
and communications hardware and software, operations systems or applications
software and other related devices. This chapter explains the technical level
of ICT security in greater detail.
Legal implications
The last chapter of this handbook briefly explains legal matters with respect
to Malaysian law. It highlights Malaysian cyber laws and the various aspects
of criminal investigations.
The appendices of this handbook provide some samples of framework, plan,
checklist and forms useful in the ICT security management process.
1.4 Audience
Main objective is to
provide guidance to all
government employees
The main objective of this handbook is to provide guidance to employees
within government agencies on the essential components of ICT security.
It is intended to be the primary reference book used by all government
employees in safeguarding the government’s ICT assets.
The handbook is for ALL
government employees
Various categories of government employees will benefit from the handbook
as it covers a wide range of topics. Nevertheless this handbook is also
useful to anyone wishing to learn about the application of ICT security.
Organisation of the
content of the handbook
The handbook is presented in five (5) chapters that can be divided into three
(3) different levels; Essential, Intermediate and Advanced (Figure 1.2). The
Essential level, which comprises of Chapter 1, Chapter 2 and Chapter 5,
provides fundamental knowledge on ICT security and is suitable for chief
executives and managers in the public sector.
The Intermediate i.e. Chapter 3 is intended for general ICT users of the
public sector. The description and explanation will provide guidance to users
on the basic operational security safeguard to be implemented and maintained
by them.
The Advanced stage i.e. Chapter 4 is proposed for the more experienced
ICT administrators and managers. The descriptions on technical details of
ICT security should provide guidance and direction on steps that need to
be taken to ensure the confidentiality, integrity and availability of public sector
ICT systems.
Copyright MAMPU
Chapter 1 - 4