and this requires an appropriate and comprehensive cyber-security policy framework to
ensure the security and resilience of national information systems and services.
1.4.
CURRENT STATUS OF CYBER SECURITY
Rwanda is aware that cyber security threats are posing a global danger to the integrity,
security and privacy of information worldwide, and that in the twenty-first century every
country shall have to protect its cyber-space in order to protect its citizens.
Although there have been significant investments and government interventions to address
cyber security challenges through various institutions, there is a need for a strong institutional
framework to coordinate cyber security initiatives with an integrated approach as to fully
realize cyber security strategic objectives. The absence of such an institutional framework has
often led to inconsistency and duplication of efforts among stakeholders.
In terms of Policy, Legal, and Regulatory Framework and Standards governing ICT,
addresses issues related to ICT Services and Security. This includes ICT Policy and
regulatory functions, consumer protection, matters of national interest and data security,
regulation of electronic certification service providers, obligations of certification authorities
(CAs), computer misuse, cyber-crime, and protection of personal information.
The comprehensive ICT law under final review for enactment shall supersede several ICT
related laws including “Law relating to electronic messages, electronic signatures and
electronic transactions”. Even though the penal code and the current ICT bill outline
provisions for cyber security, there are still gaps such as no legal basis and procedures for
designating and managing the critical information infrastructures (CIIs) and no adopted
national cyber security standard in Rwanda, resulting in inconsistency of security policies in
each organization. In an effort to enhance the cyber security regulations,
Several infrastructure and initiatives have been implemented in cyber security which include
the establishment of an Internet Security Center (ISC) to monitor the status of Internet
security, and the National Public Key Infrastructure (PKI) to provide confidentiality, integrity,
authenticity and non-repudiation of e-Transactions, establishment of a National Computer
Security and Incident Response Team (CSIRT), mandated with preventing and responding to
cyber security incidents in public and private cyberspace.
All the above would protect critical infrastructure such as the National Backbone (NBB),
National Data Center (NDC), 4G LTE last mile networks, e-Government systems, Energy
Infrastructure, Banking and Finance systems, etcetera. This infrastructure needs to be highly
protected both logically and physically.
7