place a mechanism to ensure that National Critical Information Infrastructure (CII) is defined and secure against various cyber threats. In collaboration with the ICT Regulatory Authority, the concerned public institutions as well as the private sector relevant to cyber security shall develop the CII Information Protection law, CII regulations, compliance and compliance and protection plan. CII regulation shall address, but shall not be limited to, CII procedures manuals, access control, business continuity and contingency plan, physical and logical protection. 9) Establish Public-Private Collaboration Framework Given the role that the private sector plays in the development and management of ICT infrastructure and services, collaboration with the private sector is key in addressing security and resilience. The Agency in charge of Cyber Security shall put in place a collaboration framework that defines the roles and responsibilities of organizations managing critical Information Infrastructure. The GoR and Private Sector will meet regularly to discuss and review the security status of CIIs and share cyber security related information. POLICY AREA 5 – GOVERNMENT CYBER SECURITY ENHANCEMENT PROGRAM Objective: To safeguard Government information and infrastructure systems against cyberattacks. Measures: 10) Information Security Compliance The Agency in charge of Cyber Security shall establish the Government Information Security Certification (GISC) program based on Government Security Architecture (GSA) to enhance Information Security Management System in public institutions. The agency in charge of cyber security shall conduct an information security audit in public institutions based on GSA requirements. Private institutions are also subject to a mandatory information security audit at least once a year based on ISO 27001/27002 or GSA, in case required they shall seek support from the agency in charge of cyber security. 11) Establish security levels for systems, applications and services, The Agency in charge of Cyber Security shall define security levels of systems, applications and services for GoR. More especially, e-Government services must adopt appropriate cyber 12

Select target paragraph3