National Information Assurance and Cyber Security Strategy (NIACSS)
2012
4.4.
Develop National Information Security Standards and Policies
An authorized government entity, National Information Assurance and
Security Agency (NIACSA) (Section 5), will develop and or customize
nationwide cyberspace security overarching standards considering current
The efforts of implementing nationwide overarching standards and
policies will be assigned or managed by NIACSA (Section 5).
NIACSA will also audit and evaluate the compliance with these
standards and policies. NIACSA should have a flexible organizational
structure in which development, review, evaluation and audit are
assigned to responsible departments such that segregation of duties is
maintained.
international standards, policies, and best practices, such as encryption
algorithms, encryption keys management, software development, physical
and logical access control, and networks security. NIACSA will develop the
Information Security Policy must be developed and enforced to meet
optimum information security requirements for government
organizations and private sector.
necessary guidelines and training programs to guarantee that related entities
can implement such standards and policies
Individual government entities and private sector that have different security
requirements will have the ability to develop their own security policies that
do not contradict with the nationwide security policy. NIACSA, Government
entities and private sector must co-operate to ensure that their policies
augment, comply, and be consistent with the nationwide policies.
Page 10 of 20