Dimension 4 – Legal and Regulatory Frameworks D4-1: Cybersecurity Legal Frameworks ● ● ● D4-2: Legal Investigation ● ● ● ● Dimension 5 – Standards, Organisations and Technologies E Transactions and Cyber-Security Act in place Need to develop regulatory instruments relating to ICT Security Partial legislation regarding privacy Limited capacity for police and judiciary Law enforcement forces do possess some investigative capacity Lack formal collaboration mechanisms with law enforcement. Limited number of judges who have capacity to preside over cyber case D4-3: Responsible Reporting ● No formal and official responsible vulnerability disclosure framework exists D5-1: Adherence to Standards ● ● No information security standards Public Service ICT Standards available D5-2: National Infrastructure Resilience ● ● Low resilience of the internet services infrastructure Limited availability of technology to support e-commerce No formal approach has been established to address these issues. Minimal control of their technology infrastructure by Government Dependent on unreliable third party markets for cybersecurity related products ● ● ● D5-3: Cybersecurity Marketplace ● ● No cybersecurity related products or services from Malawi No cyber insurance 3.2. Key Strategic Issues Following the above analysis, the following emerge as key strategic areas for intervention: 1. Identifying and managing the critical information infrastructure of Malawi 2. Developing and enhancing cybersecurity-related capacity, infrastructure and regulatory frameworks. 3. Promoting awareness, information sharing and collaboration on cybersecurity. 4. Enable and continuously improve the safety of vulnerable groups1 in cyberspace, especially the safety of children. 5. Enhancing and coordinating the fight against all forms of cybercrime 6. Promoting the use of cyberspace to drive social and economic development 9

Select target paragraph3