• A risk-management based and technology neutral approach shall be adopted in performing assurance activities.   • Continuous improvement in the nation’s security posture shall be an objective underpinning assurance activities and recommendations. • All cyber security initiatives shall be assessed for conformity with relevant laws, harmonized frameworks, cost effectiveness and the ability to provide a secure and a safe cyberspace that contributes positively to the nation’s growth.   • A continuous monitoring approach shall be used to assess, security trends, threats and risks that face the nation’s cyberspace.   • Regular security audits shall be performed to determine the status of implemented cyber security controls and general security posture of the nation's cyberspace.   5.2.4 Critical Information Infrastructure Protection (CIIP)   i. It is the policy of the Government to develop national guidelines and criteria for profiling information infrastructure with a strategic intent of determining, identifying, and classifying critical national information infrastructure. ii. This policy will enable a mechanism for addressing vulnerability of nation’s Critical Information Infrastructure. iii. This policy seeks proactive security measures and controls throughout all government institutions towards addressing vulnerabilities and related security gaps within internal information systems, processes and users.   iv. Such measures should adapt to the national cybersecurity standards and guidelines as provided for in the National Cybersecurity Strategy.  

Select target paragraph3