National Information Assurance and Cyber Security Strategy (NIACSS)
2012
A nationwide policy should be developed, published and communicated to
provide direction and support for information security per this strategy,
relevant laws, regulations and international information security standards.
The resulting information security standards and policies should be reviewed
at planned intervals to accommodate for the rapid change of the cyberspace
environment to ensure currency and effectiveness. Standards and policies
should have a single owner for development, review and evaluation. At
national and organizational level, officials and any other necessary party will
be designated to help develop, promulgate, and review standards and
policies. There should be defined management review procedures. Reviews
should provide recommended improvements or changes needed according to
law, and organizational and technical environments. The reviews should also
consider feedback from interested parties, status of preventive and corrective
actions, trends related to threats and vulnerabilities, reported incidents and
actions taken to respond and recover from these incidents. .
Information Security Policies should:
Assign and define information security classification levels required for
the Government organizations.
Comply with Jordanian laws and adopted international standards.
Define organizational roles and responsibilities.
Define policy distribution, training, and implementation timelines.
Provide compliance and certification procedures, and approval
authorities.
Provide procedures for corrective actions for non-compliance.
4.5.
Legal and Regulatory Regime
The need for empowering laws and regulations to support and enforce the
implementation of the strategy is a must. A specialized committee should be
formed with members from the Ministry of Information and
Communications Technology and Ministry of Justice experts to further
explore this area and provide recommendations.
Page 11 of 20