citizens use government online services with confidence: and trust that their sensitive
information is safe and, in turn, understand their responsibility to submit their sensitive
information online in a secure manner;
the Government shall set and adhere to the most appropriate cyber security standards, to
ensure that all branches of government understand and meet their obligations to secure
their networks, data and services; and
The Government’s critical assets, including those at the highest classification, are
protected from cyber-attacks.
The Government shall continue to move more of its services online so that the state can become
truly ‘digital by default’. The Government’s ministry of information stakeholders and CIRT-SL
shall ensure that all new digital services built or procured by government are also ‘secure by
default’. The Government’s networks are highly complex and in many cases still incorporate
legacy systems, as well as some commercially available software which is no longer supported
by the vendor. We will ensure that there are no unmanaged risks from legacy systems and
unsupported software.
We will improve government and wider public sector resilience to cyber-attack. This means
ensuring an accurate and up to date knowledge of all systems, data, and those who have access to
them. The likelihood and impact of a cyber-incident will be minimized by implementing best
practice as set out by the CIRT-SL. The Government will also ensure that it is able to respond
effectively to cyber incidents through a programme of incident exercises and regular testing of
government networks. We will invite Entrusted Administrations and local authorities to
participate in these exercises, as appropriate
Cyber security is not just about technology. Almost all successful cyber-attacks have a
contributing human factor. We will therefore continue to invest in our people, to ensure that
everyone who works in government has a sound awareness of cyber risk. We will develop
specific cyber expertise in areas where the risks are heightened and ensure that we have the right
processes in place to manage these risks effectively.
The CIRT-SL will develop/assemble world- leading cyber security guidance which will keep
pace with the threat and development of new technologies. We will take steps to make sure