MyMIS The ICT security process must cover various aspects in achieving a secure enviroment The ICT security process must cover all aspects of operation, including mechanisms used by hardware and software systems, networks, databases and other related systems and facilities. The goal is to achieve a secure working environment for employees and other persons working at or visiting the government’s facilities as well as to help establish processes to ensure the protection of information. ICT security processes should mirror management’s direction The ICT security process should mirror the management’s direction in relation to: (a) overall organisational policy; (b) organisational roles and responsibilities; (c) personnel; (d) government’s asset classification and control; (e) physical security; (f) system access controls; (g) network and computer management; (h) application development and maintenance; (i) business continuity; (j) compliance to standards as well as legal and statutory requirements; (k) classification and protection of information media; (l) employee awareness programmes; and (m) incident reporting and response. 1.2 This handbook provides guidelines on ICT security based on international standards Standards Framework This handbook provides essential guidelines to government employees on the ICT security process in the public sector. It is based mainly on two standards i.e. the MS ISO/IEC 13335 (Part 1 - 3) and the BS 7799 (Part 1 and 2). It also makes references to the Canadian Handbook on Information Technology Security, German IT Baseline Protection Manual and other related ISO standards. Various levels of details of standards can be viewed in the model depicted in Figure 1.1. In comparison to other standards and documents of ICT security management particularly to their level of detail, this handbook can be positioned along with the BS 7799, the Canadian MG-9 and the American National Institute of Science and Technology (NIST). This is warranted by the fact that this handbook is jurisdictional and specific to the Malaysian public sector. Description of model (Figure 1.1) In the model, the areas and level of details of these standards varies between each standard. Level 1, 2, 3 and 4 represent the Guidelines for the Management of IT Security (GMITS) or ISO/IEC 13335. It indicates the depth of knowledge required to understand the respective level. As an example, a Level 1 document needs no prior knowledge on ICT security management while a Level 2 document needs at least some understanding of the previous level. Level 1 to level 4 of the model The model progresses from Level 1 ‘Concepts and Models’ to Level 2 ‘Managing and Planning IT’, Level 3 ‘Techniques for the Management of IT’ before detailing ‘Selection of Safeguards, Management Guidance on Network and Guidelines for the Management of Trusted Third Parties’ in Level 4. Copyright MAMPU Chapter 1 - 2

Select target paragraph3