Acknowledgement T he Government of Malaysia is committed towards modernising its administrative machinery and enhancing its service delivery mechanisms. The process of ensuring an efficient and effective public sector is being driven by the enabling capabilities of information and communications technology (ICT). The resultant widespread adoption of ICT systems by the public sector has meant that more and more Government agencies are moving towards the paperless work environment where ICT systems have become indispensable for the provision of Government services to citizens. The expansion of ICT systems within the public sector has in turn led to a significant increase in the number of public sector information repositories and other ICT-based installations and assets. The security of these ICT installations and assets are exposed to the vulnerability of open and networked electronic systems. As such agencies now face the additional responsibility of securing ICT-based Government information and systems as well as ensuring that they are available to authorised users. The Malaysian Public Sector ICT Management Security Handbook (MyMIS) is intended as a reference and guide for public sector personnel in managing security in all public sector ICT installations. MyMIS serves to complement the ICT security measures taken earlier by the Government by way of Pekeliling Am Bil. 3 Tahun 2000 entitled ‘Rangka Dasar Keselamatan Teknologi Maklumat dan Komunikasi Kerajaan ’ (Government Information and Communications Technology Security Policy Framework) and Surat Pekeliling Am Bil.1 Tahun 2001 entitled ‘Mekanisme Pelaporan Insiden Keselamatan Teknologi Maklumat dan Komunikasi (ICT)’ (Information and Communications Technology (ICT) Security Incident Reporting Mechanism). While every effort has been made to address all possible ICT security situations in the handbook, there will of course be instances during normal ICT operations where the incidents encountered may not be sufficiently covered in this handbook. In the event of such cases, the best practice available for the relevant situation should be followed. Needless to say, the MyMIS handbook is the product of close collaboration between MAMPU and various other Government agencies. Their contributions have certainly helped sustain the momentum during periods of waning energy in the course of completing this handbook. MAMPU would therefore like to place on record its appreciation to the following agencies: • National Security Division, Prime Minister’s Department (Bahagian Keselamatan Negara, Jabatan Perdana Menteri) • Office of the Chief Government Security Officer, Prime Minister’s Department (Pejabat Ketua Pegawai Keselamatan Kerajaan, Jabatan Perdana Menteri) • Ministry of Energy, Communications and Multimedia (Kementerian Tenaga, Komunikasi dan Multimedia) • • • • • Ministry of Defence (Kementerian Pertahanan) National Institute of Public Administration (INTAN) Universiti Teknologi Malaysia Universiti Kebangsaan Malaysia Universiti Putra Malaysia • Universiti Malaya • Bank Negara Malaysia • GITN Sdn. Berhad • MIMOS Berhad • SIRIM Berhad i

Select target paragraph3