place a mechanism to ensure that National Critical Information Infrastructure (CII) is defined
and secure against various cyber threats.
In collaboration with the ICT Regulatory Authority, the concerned public institutions as well
as the private sector relevant to cyber security shall develop the CII Information Protection
law, CII regulations, compliance and compliance and protection plan. CII regulation shall
address, but shall not be limited to, CII procedures manuals, access control, business
continuity and contingency plan, physical and logical protection.
9) Establish Public-Private Collaboration Framework
Given the role that the private sector plays in the development and management of ICT
infrastructure and services, collaboration with the private sector is key in addressing security
and resilience. The Agency in charge of Cyber Security shall put in place a collaboration
framework that defines the roles and responsibilities of organizations managing critical
Information Infrastructure.
The GoR and Private Sector will meet regularly to discuss and review the security status of
CIIs and share cyber security related information.
POLICY AREA 5 – GOVERNMENT CYBER SECURITY ENHANCEMENT PROGRAM
Objective: To safeguard Government information and infrastructure systems against cyberattacks.
Measures:
10) Information Security Compliance
The Agency in charge of Cyber Security shall establish the Government Information Security
Certification (GISC) program based on Government Security Architecture (GSA) to enhance
Information Security Management System in public institutions. The agency in charge of
cyber security shall conduct an information security audit in public institutions based on GSA
requirements. Private institutions are also subject to a mandatory information security audit at
least once a year based on ISO 27001/27002 or GSA, in case required they shall seek support
from the agency in charge of cyber security.
11) Establish security levels for systems, applications and services,
The Agency in charge of Cyber Security shall define security levels of systems, applications
and services for GoR. More especially, e-Government services must adopt appropriate cyber
12