3.4.1.3 Establish a National Risk Register and Regulations and/or Guidelines that promote
continuous risk assessment and management across CIIs in Malawi
3.4.1.4 Establish Mandatory Equipment Specifications, Mandatory Guidelines, Regulations,
Security Requirements, Procedures relating to the management of risks by CIIs
3.4.1.5 Create a National Vulnerability Register and Framework for regular vulnerability
monitoring and disclosure for CII
3.4.1.6 Undertake continuous monitoring and regular testing to detect errors, vulnerabilities,
and intrusions in CII
3.4.1.7 Promote and enhance regional and international cooperation in the protection of the
critical information infrastructure (CII)
3.4.2 Specific Objective 2: Continuously monitor and manage cyber threats and
risks to enhance incident response.
Actions:
3.4.2.1 Expedite the establishment and
operationalization of a national CERT with clear
processes, defined roles and responsibilities
3.4.2.2 Continuously develop the capacity of staff at Malawi National CERT to address the fast
changing technical requirements, and develop abilities to actively obtain information in
cyberspace, about current cyber risks and threats
3.4.2.3 Develop a national incident reporting, information sharing and coordination
mechanisms to address reporting of incidents and coordination in incident response
3.4.2.4 Create and continuously update cyber security incidents register, assess incidents, and
suggest measures to resolve issues and mitigate threats and risks
3.4.2.5 Specify minimum and mandatory log/register requirements necessary for dependable
cyber security incident analysis
Page | 15