POLICY AREA 3 – CYBER SECURITY LEGAL AND REGULATORY FRAMEWORK Objective: To strengthen the existing legal and regulatory framework so as to comprehensively address cyber-crime and facilitate the criminalization of acts related to cyber-crime that are not addressed by any existing law, yet pose a potent threat to national security. Measures: 6) Enhance the legal and regulatory framework There is a need to enhance the current legal and regulatory framework to facilitate the enforcement of cyber security laws, investigation and prosecution of cyber-crime related activities. To this end, the GoR shall review the existing legal and regulatory framework to ensure that all applicable national legislations incorporate cyber security provisions that grant reasonable capacity to national law enforcement agencies, which are complementary to, and in harmony with, international laws, treaties and conventions. The GoR will also strengthen the legal and regulatory framework to prevent cyber security threats arising from harmful content disseminated in the national cyberspace. 7) Define Standards and Guidelines To ensure information security best practices with public and private institutions, the agency in charge of cyber security shall develop standards and guidelines to guide public and private sector players adopt consistent cyber security best practices and standards. POLICY AREA 4 – CRITICAL INFORMATION INFRASTRUCTURE PROTECTION (CIIP) Objective: To protect National Critical Information Infrastructure against cyber threats and related cyber-crimes to ensure its confidentiality, integrity and availability. Measures: 8) Protect National Critical Information Infrastructure The disruption of Critical Information Infrastructures (CIIs) has direct impact on business and society. Therefore, the Government institution in charge of cyber security shall put in 11

Select target paragraph3