Acknowledgement
T
he Government of Malaysia is committed towards modernising its administrative machinery and
enhancing its service delivery mechanisms. The process of ensuring an efficient and effective
public sector is being driven by the enabling capabilities of information and communications technology
(ICT). The resultant widespread adoption of ICT systems by the public sector has meant that more
and more Government agencies are moving towards the paperless work environment where ICT
systems have become indispensable for the provision of Government services to citizens.
The expansion of ICT systems within the public sector has in turn led to a significant increase in
the number of public sector information repositories and other ICT-based installations and assets.
The security of these ICT installations and assets are exposed to the vulnerability of open and
networked electronic systems. As such agencies now face the additional responsibility of securing
ICT-based Government information and systems as well as ensuring that they are available to authorised
users.
The Malaysian Public Sector ICT Management Security Handbook (MyMIS) is intended as a reference
and guide for public sector personnel in managing security in all public sector ICT installations.
MyMIS serves to complement the ICT security measures taken earlier by the Government by way
of Pekeliling Am Bil. 3 Tahun 2000 entitled ‘Rangka Dasar Keselamatan Teknologi Maklumat dan
Komunikasi Kerajaan ’ (Government Information and Communications Technology Security Policy
Framework) and Surat Pekeliling Am Bil.1 Tahun 2001 entitled ‘Mekanisme Pelaporan Insiden Keselamatan
Teknologi Maklumat dan Komunikasi (ICT)’ (Information and Communications Technology (ICT) Security
Incident Reporting Mechanism).
While every effort has been made to address all possible ICT security situations in the handbook,
there will of course be instances during normal ICT operations where the incidents encountered may
not be sufficiently covered in this handbook. In the event of such cases, the best practice available
for the relevant situation should be followed.
Needless to say, the MyMIS handbook is the product of close collaboration between MAMPU and
various other Government agencies. Their contributions have certainly helped sustain the momentum
during periods of waning energy in the course of completing this handbook. MAMPU would therefore
like to place on record its appreciation to the following agencies:
• National Security Division, Prime Minister’s Department (Bahagian Keselamatan Negara, Jabatan
Perdana Menteri)
• Office of the Chief Government Security Officer, Prime Minister’s Department (Pejabat Ketua
Pegawai Keselamatan Kerajaan, Jabatan Perdana Menteri)
• Ministry of Energy, Communications and Multimedia (Kementerian Tenaga, Komunikasi dan
Multimedia)
•
•
•
•
•
Ministry of Defence (Kementerian Pertahanan)
National Institute of Public Administration (INTAN)
Universiti Teknologi Malaysia
Universiti Kebangsaan Malaysia
Universiti Putra Malaysia
• Universiti Malaya
• Bank Negara Malaysia
• GITN Sdn. Berhad
• MIMOS Berhad
• SIRIM Berhad
i