b) Through the ISSD of MCIT enforce the adaptation of ISO 2700 series and other
International standards for Information Security Management System (ISMS),
information assurance, Information Systems and IT infrastructure audits, Vulnerability
assessment, Risk management of the critical information infrastructures (CII),
Business continuity, ensure Application security through Software Development Life
Cycle (SDLC) and best practices and Penetration testing of IT infrastructures.
c) Enforce data classification of all governmental entities in order to ensure data
confidentiality and apply access controls (Physical, Technical and Administrative) to
ensure accountability.
d) Periodically conduct risk assessment and security standard compliance of the critical
information infrastructures (CII).
3. Establishing a regulatory framework
a) MCIT will work together with the Ministry of Justice (MoJ) to develop legal
framework and conduct for addressing cybersecurity issues
b) Develop the Cyber Law of Afghanistan and Child Online Protection policy with
support and cooperation’s of US-DOC, CLDP, European Commission, UNCITRAL
and International Multilateral Partnership Against Cyber Threats (IMPACT)
c) Develop legal framework for private Certification Authority (CA) and secure
electronic transaction system for business and financial institutes
d) Develop legal framework and policies to assure secure mobile computing, cloud
computing, mobile governance and internet governance
e) Develop regulatory framework for auditing and certifying IT infrastructures for the
sack of cyber security within the government and for those Solution providers (SPs)
who are providing IT services to the government
f) Organize awareness campaign for all regulatory frameworks and periodically update
the regulatory frameworks with the evolving technological advancements.
4. Enhance AFCERT capabilities
a) AFCERT as the focal point will act as first responder to any cyber incident or
computer crime investigations within the government and private sector
b) Coordinate crime scene investigation report with law enforcement for further
processes
c) Provide cyber related awareness to all government and nongovernment agencies
through its Network Operation Center (NOC), workshops, seminars, email, magazines
and newsletters
d) Extend its operation hours to 24/7 service availability within the timeframe of two
years
e) Assist provinces in establishing the provincial CERTs
f) Keep strong engagement and coordination with regional CERTs in order to fight
against cyber crimes
Information
Systems
Security
Directorate
-‐
MCIT