National Information Assurance and Cyber Security Strategy (NIACSS) 2012 4.4. Develop National Information Security Standards and Policies An authorized government entity, National Information Assurance and Security Agency (NIACSA) (Section 5), will develop and or customize nationwide cyberspace security overarching standards considering current The efforts of implementing nationwide overarching standards and policies will be assigned or managed by NIACSA (Section 5). NIACSA will also audit and evaluate the compliance with these standards and policies. NIACSA should have a flexible organizational structure in which development, review, evaluation and audit are assigned to responsible departments such that segregation of duties is maintained. international standards, policies, and best practices, such as encryption algorithms, encryption keys management, software development, physical and logical access control, and networks security. NIACSA will develop the Information Security Policy must be developed and enforced to meet optimum information security requirements for government organizations and private sector. necessary guidelines and training programs to guarantee that related entities can implement such standards and policies Individual government entities and private sector that have different security requirements will have the ability to develop their own security policies that do not contradict with the nationwide security policy. NIACSA, Government entities and private sector must co-operate to ensure that their policies augment, comply, and be consistent with the nationwide policies. Page 10 of 20

Select target paragraph3