National Information Assurance and Cyber Security Strategy (NIACSS) 2012 4. NATIONAL INFORMATION SECURITY PRIORITIES To achieve the National Strategic Objectives listed above (Section 3), Government of Jordan organizes its NIACSS across nine major national interdependent priorities, each priority demanding collaboration across Government, and with international partners, the private sector, and the citizenry. Taken as a whole, these priorities form the action lines of the NIACSS Implementation Roadmap. The nine priorities (not sorted in order of importance) are: 1) Risk Management Program 2) National Computer Emergency Response Team (JOCERT) 3) Security Awareness and Capacity Building Program 4) National Information Security Standards and Policies 5) Legal and Regulatory Regime 6) National Encryption System 7) International Information Security Cooperation Program 8) Securing National Information Systems/Networks 9) Critical National Infrastructure Protection (CNIP) Program 4.1. Risk Management Program A Nation-Wide Risk Management Program will establish the needed framework for high level impact risk management on the national level. It will not address individual risks, for government entities and private sector, with little or no impact on the national level. Government organizations and private sector must address and manage their own risks. They must develop their own risk management programs or plans that are inline with the Nation-Wide Risk Management Program. Government organizations and private sector will develop and maintain risk management programs that are inline with the nation-wide risk management program. In cyberspace, risks can never be reduced to zero and there is no 100% secure system. Page 7 of 20

Select target paragraph3