National Information Assurance and Cyber Security Strategy (NIACSS) 2012 Government organizations and private sector need to develop their own internal regulations consistent and compliant with national laws to cover information security-related legal issues. 4.6. National Encryption System A National Encryption Centre (NEC) will be established to manage, control, plan, monitor, and enforce the national strategic encryption policies A National and later on produce indigenous national Encryption algorithms and keys. Government organizations Centre should be and involved parties will adhere to the encryption established standards, policies, or strategic guidelines approved and or developed by the NEC. While the private sector will have the flexibility to use their own encryption solutions, these solutions should never violate the approved standards, policies, or strategic guidelines. Government organizations and private sector need to use encryption along with other security measures to protect classified sensitive and critical information assets. The following strategic needs list for Government organizations will ensure investment in encryption today delivers strategic value to national security efforts: 4.6.1 A national encryption policy will be developed, coordinated, and placed in force. 4.6.2 Applicable international standards and best practices should be considered for adoption for better encryption management. 4.6.3 Encryption should be applied to all data deemed sensitive or classified. 4.6.4 Encryption should be considered where necessary when data is stored, transmitted/disseminated and or processed. 4.6.5 Government organizations must ensure encryption is used in parallel with other necessary security measures (defense-in-depth). 4.6.6 Government organizations must continually monitor or audit all automated and manual actions and ensure procedures are in place to guarantee the integrity and security of encryption capabilities and associated logs. Page 12 of 20

Select target paragraph3