•
A risk-management based and technology neutral approach shall be
adopted in performing assurance activities.
•
Continuous improvement in the nation’s security posture shall be an
objective underpinning assurance activities and recommendations.
•
All cyber security initiatives shall be assessed for conformity with
relevant laws, harmonized frameworks, cost effectiveness and the
ability to provide a secure and a safe cyberspace that contributes
positively to the nation’s growth.
•
A continuous monitoring approach shall be used to assess, security
trends, threats and risks that face the nation’s cyberspace.
•
Regular security audits shall be performed to determine the status of
implemented cyber security controls and general security posture of
the nation's cyberspace.
5.2.4 Critical Information Infrastructure Protection (CIIP)
i.
It is the policy of the Government to develop national guidelines and
criteria for profiling information infrastructure with a strategic intent of
determining, identifying, and classifying critical national information
infrastructure.
ii.
This policy will enable a mechanism for addressing vulnerability of nation’s
Critical Information Infrastructure.
iii.
This policy seeks proactive security measures and controls throughout all
government institutions towards addressing vulnerabilities and related
security gaps within internal information systems, processes and users.
iv.
Such measures should adapt to the national cybersecurity standards and
guidelines as provided for in the National Cybersecurity Strategy.