iii. For business continuity purpose, cybercrime incident occurring must be recorded, reviewed and resolved following an established incident management process as may be define in NIRP. iv. 6.4 All Cybercrime incidents must be documented and reported to ngCERT. Vulnerability Handling: i. Security assessment and audit shall be periodically required on critical national information infrastructure. It shall be carried out at a pre-defined interval and integrated into the National Incident Response Plan (NIRP). ii. There shall be provision for the documentation and archiving of all vulnerabilities and patches according to manufacturer’s specifications. A national record shall be kept for review. 6.5 i. Artifacts Handling: The policy requires the development of national guidelines on digital evidence handling which shall be incorporated into the NIRP. 6.6 Collaboration: i. ngCERT shall be saddled with advocacy to promote trust within the national cyberspace. ii. All collaboration with regional and international CERTs shall be coordinated by ngCERT as the National Point of Contact (POC). iii. All sectorial computer emergency response team (CERT) shall be promoted and supported by ngCERT. Technical support and expertise will be provided as when required. iv. A national trust level classification shall be established to cater for different tiers of sectorial CERT. 6.7   Sector-based CERT

Select target paragraph3