MyMIS Chapter 2 MANAGEMENT SAFEGUARDS Senior management commitment The main objective of this chapter is to highlight the major elements that should be considered by all government ministries, federal departments, statutory bodies, state secretaries and local authorities in their efforts to safeguard their respective ICT systems. Of utmost importance is senior management commitment towards acknowledging and addressing security issues. 5 major elements The five (5) major elements of management safeguards are: (a) Public Sector ICT Security Policy; (b) Public Sector ICT Security Programme Management; (c) Public Sector ICT Security Risk Management; (d) Incorporating Public Sector ICT Security into ICT System’s Life Cycle; and (e) Public Sector ICT Security Assurance. 2.1 Public Sector ICT Security Policy ICT Security Policy must ensure the government’s information is secured The government acknowledges its obligation to ensure appropriate security for all ICT assets under its ownership. This is best implemented by having a written ICT Security Policy that serve to assist in identifying at the very outset what needs to be protected. The document will also inform department members what activities are allowed or what activities are disallowed. The policy should define common rules to be abided by everyone within the organisation. The policy so formulated should address the need for a total enforcement of controls and measures to safeguard government ICT assets. Policy needs to be balanced between rigid and loose information control The tremendous increase in ICT dependency and usage especially with the advent of the Internet, exposes government information to a much larger audience and with that a potential threat that government information being compromised. This is especially worrying on classified government information and if left unchecked, can cause serious integrity issues to the government. At the same time, there need to be a balance between rigid information control that limits service delivery on one hand against a loose information control that would compromise security or severely affect the interest of the public service or the nation. It is in realising the absolute importance of the provision of ICT security, the ICT Security Policy be drafted based on concrete ICT principles, best practices, responsibilities towards securing information, threats and incremental steps towards upgrading information security. Copyright MAMPU Chapter 2 - 1

Select target paragraph3