MyMIS
Chapter 2
MANAGEMENT SAFEGUARDS
Senior management
commitment
The main objective of this chapter is to highlight the major elements that
should be considered by all government ministries, federal departments,
statutory bodies, state secretaries and local authorities in their efforts to
safeguard their respective ICT systems. Of utmost importance is senior
management commitment towards acknowledging and addressing security
issues.
5 major elements
The five (5) major elements of management safeguards are:
(a) Public Sector ICT Security Policy;
(b) Public Sector ICT Security Programme Management;
(c) Public Sector ICT Security Risk Management;
(d) Incorporating Public Sector ICT Security into ICT System’s Life Cycle;
and
(e) Public Sector ICT Security Assurance.
2.1
Public Sector ICT Security Policy
ICT Security Policy must
ensure the government’s
information is secured
The government acknowledges its obligation to ensure appropriate security
for all ICT assets under its ownership. This is best implemented by having
a written ICT Security Policy that serve to assist in identifying at the very
outset what needs to be protected. The document will also inform department
members what activities are allowed or what activities are disallowed. The
policy should define common rules to be abided by everyone within
the organisation. The policy so formulated should address the need for a
total enforcement of controls and measures to safeguard government ICT
assets.
Policy needs to be
balanced between rigid
and loose information
control
The tremendous increase in ICT dependency and usage especially with the
advent of the Internet, exposes government information to a much larger
audience and with that a potential threat that government information being
compromised. This is especially worrying on classified government information
and if left unchecked, can cause serious integrity issues to the government.
At the same time, there need to be a balance between rigid information
control that limits service delivery on one hand against a loose information
control that would compromise security or severely affect the interest of the
public service or the nation.
It is in realising the absolute importance of the provision of ICT security, the
ICT Security Policy be drafted based on concrete ICT principles, best practices,
responsibilities towards securing information, threats and incremental steps
towards upgrading information security.
Copyright MAMPU
Chapter 2 - 1