Chief Secretary to the Government T he Internet-driven global digital revolution and the explosive growth of computer networks and systems have resulted in the extensive use of information and communications technology (ICT) for gathering, maintaining and transmitting information and data. Electronic connectivity in the work place has meant that the security of ICT systems and the information residing in them can no longer be provided through conventional means. The increasing incidence of hacking, virus attacks and other forms of electronic trespass have necessitated the need for securing the new electronic work environment. The public sector is not insulated from the prevailing dangers of the digital world. For that matter, considering the scope of its functions, services and transactions as well as the complexities of its inter-relationships with all components of society, the public sector has to seriously address all concerns relating to ICT security. For the Malaysian public sector, ICT security is critical to the objective of implementing Electronic Government and expanding the use of ICT in the delivery of Government services as well as in enhancing the internal operations of public sector agencies. In this regard, the Government has already issued a broad policy guideline on the underlying principles of ICT security, the responsibility of safeguarding Government information and the need for awareness about threats to the integrity of information and ICT assets. In addition, guidelines on the mechanism for reporting ICT security incidents were also issued to assist agencies in handling ICT security incidents in the public sector. This Malaysian Public Sector Management of Information and Communications Technology Security Handbook (MyMIS) serves to complement the overall approach towards safeguarding ICT security in the public sector. It provides a comprehensive set of practical instructions to public sector agencies in managing and securing information and other ICT assets in their respective organisations. MyMIS will ensure that due attention is given to the entire range of activities related to the operations of a particular ICT-based facility, infrastructure, system or application. In this way, public sector agencies can be confident of the integrity, authenticity and availability of their services and outputs. As such, while satisfying the service requirements of customers at the individual level, public sector agencies can ensure privacy and confidentiality in all ICT-based transactions while safeguarding against any breach of national security. I am confident that MyMIS will prove to be an extremely useful source of reference for all public sector agencies in implementing an effective ICT security management paradigm in their respective organisations. While we understand that there cannot be a guarantee of absolute security within internetworked electronic work environments, adherence to guidelines as prescribed by MyMIS will go a long way in mitigating much of the risks that ICT-based systems are exposed to. Public sector agencies should therefore ensure that the relevant levels of management within their organisations are informed and understand the contents of the handbook which is meant to serve as the standard guide for all ICT security management decisions and tasks. Finally, I wish to congratulate MAMPU and all others involved in coming out with this handbook. T AN S RI SAMSUDIN OSMAN Chief Secretary to the Government, Malaysia January 2002 iii

Select target paragraph3