and respond to threats, vulnerabilities, attacks, and damages to critical
information infrastructures;
Tactic Four: Build a capacity to produce and supply indigenous products and
services that are used to secure critical information infrastructures;
3. Developing secured information infrastructure products, services, communication
systems, reliable networks, and control systems technology;
Tactic One: Standards will be employed for ensuring the security of critical
information infrastructures, ICT products, and services ;
Tactic Two: Information and information infrastructure vulnerability
assessment, penetration testing, and security audits will be conducted, and
immediate remedial action will be taken at any time;
4. Enhancing the role of public and private institutions, and other concerned
stakeholders to provide special protection for critical information infrastructures;
Tactic One: By classifying critical information infrastructures persistently,
criteria for setting their roles and responsibilities will be prepared and
implemented;
Tactic Two: A 24/7 physical and virtual protection is provided for critical
information infrastructure and systems;
Tactic Three: The duties and responsibilities of all stakeholders will be
identified to provide special protection for critical information infrastructures;
2.8.
National and International Cooperation
2.8.1. National Coordination and Partnership
2.8.1.1.
Policy Statement
Cyber security attacks are so complex, unpredictable, dynamic, and borderless that cannot be
dealt with government or a limited number of institutions alone. Hence, establishing national
coordination and partnership to ensure cyber security, and also tackling cyber security threats
should be a shared responsibility of all stakeholders. In particular, the development of cyber
security products and services requires the active participation of the private sector. The
18