3.4.1.3 Establish a National Risk Register and Regulations and/or Guidelines that promote continuous risk assessment and management across CIIs in Malawi 3.4.1.4 Establish Mandatory Equipment Specifications, Mandatory Guidelines, Regulations, Security Requirements, Procedures relating to the management of risks by CIIs 3.4.1.5 Create a National Vulnerability Register and Framework for regular vulnerability monitoring and disclosure for CII 3.4.1.6 Undertake continuous monitoring and regular testing to detect errors, vulnerabilities, and intrusions in CII 3.4.1.7 Promote and enhance regional and international cooperation in the protection of the critical information infrastructure (CII) 3.4.2 Specific Objective 2: Continuously monitor and manage cyber threats and risks to enhance incident response. Actions: 3.4.2.1 Expedite the establishment and operationalization of a national CERT with clear processes, defined roles and responsibilities 3.4.2.2 Continuously develop the capacity of staff at Malawi National CERT to address the fast changing technical requirements, and develop abilities to actively obtain information in cyberspace, about current cyber risks and threats 3.4.2.3 Develop a national incident reporting, information sharing and coordination mechanisms to address reporting of incidents and coordination in incident response 3.4.2.4 Create and continuously update cyber security incidents register, assess incidents, and suggest measures to resolve issues and mitigate threats and risks 3.4.2.5 Specify minimum and mandatory log/register requirements necessary for dependable cyber security incident analysis Page | 15

Select target paragraph3