and this requires an appropriate and comprehensive cyber-security policy framework to ensure the security and resilience of national information systems and services. 1.4. CURRENT STATUS OF CYBER SECURITY Rwanda is aware that cyber security threats are posing a global danger to the integrity, security and privacy of information worldwide, and that in the twenty-first century every country shall have to protect its cyber-space in order to protect its citizens. Although there have been significant investments and government interventions to address cyber security challenges through various institutions, there is a need for a strong institutional framework to coordinate cyber security initiatives with an integrated approach as to fully realize cyber security strategic objectives. The absence of such an institutional framework has often led to inconsistency and duplication of efforts among stakeholders. In terms of Policy, Legal, and Regulatory Framework and Standards governing ICT, addresses issues related to ICT Services and Security. This includes ICT Policy and regulatory functions, consumer protection, matters of national interest and data security, regulation of electronic certification service providers, obligations of certification authorities (CAs), computer misuse, cyber-crime, and protection of personal information. The comprehensive ICT law under final review for enactment shall supersede several ICT related laws including “Law relating to electronic messages, electronic signatures and electronic transactions”. Even though the penal code and the current ICT bill outline provisions for cyber security, there are still gaps such as no legal basis and procedures for designating and managing the critical information infrastructures (CIIs) and no adopted national cyber security standard in Rwanda, resulting in inconsistency of security policies in each organization. In an effort to enhance the cyber security regulations, Several infrastructure and initiatives have been implemented in cyber security which include the establishment of an Internet Security Center (ISC) to monitor the status of Internet security, and the National Public Key Infrastructure (PKI) to provide confidentiality, integrity, authenticity and non-repudiation of e-Transactions, establishment of a National Computer Security and Incident Response Team (CSIRT), mandated with preventing and responding to cyber security incidents in public and private cyberspace. All the above would protect critical infrastructure such as the National Backbone (NBB), National Data Center (NDC), 4G LTE last mile networks, e-Government systems, Energy Infrastructure, Banking and Finance systems, etcetera. This infrastructure needs to be highly protected both logically and physically. 7

Select target paragraph3