National Information Assurance and Cyber Security Strategy (NIACSS)
2012
Therefore, understanding the magnitude and potential impact of these risks
informs organizational prioritization against limited resources. Proper risk
assessment and management in Government organizations will contribute to
business continuity and mission success. Organizations should assess risk
both qualitatively and quantitatively by identifying threats and
vulnerabilities. The likelihood and impact of each risk should be evaluated
against organization missions and assets to identify security gaps. These
gaps then define the true nature of the potential risk faced by the
organization against which leaders must decide either to accept the risk, or
take action to minimize or reduce the potential threat.
As no system is risk-free, government organizations should maintain disaster
recovery plans that are products of effective risk management programs.
Successful disaster recovery plans ensure organizations are back in operation
in a short time period after incidents occur. Government organizations must
adapt to the following strategies, for responding to risks, where applicable:
mitigation, transference, acceptance, and avoidance.
4.2. National Computer Emergency Response Team (JOCERT)
Information systems are targets for cyber-attack due to: 1) revolutionary
growth
of
information
and
telecommunication
technologies
in
government organizations and big business
Government of Jordan
as well; 2) availability of Government Ewill establish a
services
through
the
E-Government
National Computer
program; 3) increasing internet penetration
Emergency Response
rate and e-commerce usage, and; 4) the
Team (JOCERT)
increasing number of connected systems and
networks.
Cyber-attacks increase the possibility of data disclosure, data manipulation,
data loss, and systems sabotage. These factors trigger the urgent need for a
National Computer Emergency Response Team (JOCERT). At its highest
level, the JOCERT helps the nation prepare for, prevent, respond to, and
recover from cyber incidents and attacks. The JOCERT, which will require
management and/or operational assets at national and organizational levels,
will enable Jordan to be better positioned to manage and respond to cyberPage 8 of 20