3.4.3.1 Undertake a gap analysis to identify gaps in current ICT Security Legal and Regulatory
Framework and develop requisite instruments to address Gaps including issues relating
to privacy and data protection.
3.4.3.2 Develop and publish a cybersecurity policy and standards consisting of general and
sector-specific cybersecurity controls that would be recognized as a national standard
3.4.3.3 Create a national programme to promote the adaptation and adoption of cyber
standards across government institutions and CII in Malawi
3.4.4 Specific Objective 4: Stakeholder capacity building for law enforcement and
judiciary to implement cybersecurity related laws
Actions:
3.4.4.1 Identify needs and then provide training and education to develop the capacities of the
law enforcement agencies, judiciary and the legal fraternity on how to interpret and
enforce the policy, legal and regulatory frameworks on cybersecurity in Malawi
3.4.5 Specific objective 5: Enhance technical and procedural measures for
implementing cybersecurity for CIIs
3.4.5.1 Establish mandatory and minimum technology and security requirements for CIIs
3.4.5.2 Develop a national government programme to deploy and manage government ICT
infrastructure
3.4.5.3 Develop a national programme to enhance internet infrastructure development and
resilience.
3.4.5.4 Develop National Contingency plans which identify emergency response asset priorities
and standard operating procedures (SOPs)
3.4.5.5 Review and update the map of current emergency response assets
3.4.5.6 Ensure communication channels are deployed across emergency response functions,
geographic areas of responsibility, public and private responders, and command
authority.
Page | 18