National Information Assurance and Cyber Security Strategy (NIACSS) 2012 A nationwide policy should be developed, published and communicated to provide direction and support for information security per this strategy, relevant laws, regulations and international information security standards. The resulting information security standards and policies should be reviewed at planned intervals to accommodate for the rapid change of the cyberspace environment to ensure currency and effectiveness. Standards and policies should have a single owner for development, review and evaluation. At national and organizational level, officials and any other necessary party will be designated to help develop, promulgate, and review standards and policies. There should be defined management review procedures. Reviews should provide recommended improvements or changes needed according to law, and organizational and technical environments. The reviews should also consider feedback from interested parties, status of preventive and corrective actions, trends related to threats and vulnerabilities, reported incidents and actions taken to respond and recover from these incidents. . Information Security Policies should:  Assign and define information security classification levels required for the Government organizations.  Comply with Jordanian laws and adopted international standards.  Define organizational roles and responsibilities.  Define policy distribution, training, and implementation timelines.  Provide compliance and certification procedures, and approval authorities.  Provide procedures for corrective actions for non-compliance. 4.5. Legal and Regulatory Regime The need for empowering laws and regulations to support and enforce the implementation of the strategy is a must. A specialized committee should be formed with members from the Ministry of Information and Communications Technology and Ministry of Justice experts to further explore this area and provide recommendations. Page 11 of 20

Select target paragraph3