National Information Assurance and Cyber Security Strategy (NIACSS)
2012
Government organizations and private sector need to develop their own
internal regulations consistent and compliant with national laws to cover
information security-related legal issues.
4.6.
National Encryption System
A National Encryption Centre (NEC) will be
established to manage, control, plan, monitor, and
enforce the national strategic encryption policies
A National
and later on produce indigenous national
Encryption
algorithms and keys. Government organizations
Centre should be
and involved parties will adhere to the encryption
established
standards, policies, or strategic guidelines
approved and or developed by the NEC. While
the private sector will have the flexibility to use
their own encryption solutions, these solutions
should never violate the approved standards, policies, or strategic guidelines.
Government organizations and private sector need to use encryption along
with other security measures to protect classified sensitive and critical
information assets. The following strategic needs list for Government
organizations will ensure investment in encryption today delivers strategic
value to national security efforts:
4.6.1 A national encryption policy will be developed, coordinated, and
placed in force.
4.6.2 Applicable international standards and best practices should be
considered for adoption for better encryption management.
4.6.3 Encryption should be applied to all data deemed sensitive or
classified.
4.6.4 Encryption should be considered where necessary when data is stored,
transmitted/disseminated and or processed.
4.6.5 Government organizations must ensure encryption is used in parallel
with other necessary security measures (defense-in-depth).
4.6.6 Government organizations must continually monitor or audit all
automated and manual actions and ensure procedures are in place to
guarantee the integrity and security of encryption capabilities and
associated logs.
Page 12 of 20