The following section details the Specific Objectives and Actions required to achieve the abovementioned Strategic Goals of the Strategy. 3.4 Specific Objectives and Actions I. Strategic Goal (i): Identify and manage the Critical Information Infrastructure of Malawi Protecting the information infrastructure of Malawi is of critical to the Government of Malawi, especially as successful cyber attacks on them will have severe impacts on the country. These impacts could include destabilization of Malawi’s economy and stability or reputational damages to individuals. Therefore, it is vital that Malawi prioritizes the cybersecurity of its critical information infrastructures (CIIs) which are key for the provision of essential services to Malawi by ensuring these CIIs are secure and resilient. The protection of Malawi’s information infrastructure including CIIs necessitates collaboration of all relevant stakeholders including public and private institutions that own or operate the information infrastructure which supports the well-functioning of the Malawian society. Consequently, the Government of Malawi will work with all relevant stakeholders to identify and understand the vulnerabilities and levels of cybersecurity of Malawi’s information infrastructure, especially CIIs. The Government will also work with relevant stakeholders to establish measures that will address current and future cyber threats and risks to the national information infrastructure, and drive improvements where necessary. 3.4.1 Specific Objective 1: Identify and protect the Critical Information Infrastructure of Malawi. Actions: 3.4.1.1 Establish a National CII Register 3.4.1.2 Develop a National CII Governance Framework which provides details on CII protection procedures and processes Page | 14

Select target paragraph3