3.4.3.1 Undertake a gap analysis to identify gaps in current ICT Security Legal and Regulatory Framework and develop requisite instruments to address Gaps including issues relating to privacy and data protection. 3.4.3.2 Develop and publish a cybersecurity policy and standards consisting of general and sector-specific cybersecurity controls that would be recognized as a national standard 3.4.3.3 Create a national programme to promote the adaptation and adoption of cyber standards across government institutions and CII in Malawi 3.4.4 Specific Objective 4: Stakeholder capacity building for law enforcement and judiciary to implement cybersecurity related laws Actions: 3.4.4.1 Identify needs and then provide training and education to develop the capacities of the law enforcement agencies, judiciary and the legal fraternity on how to interpret and enforce the policy, legal and regulatory frameworks on cybersecurity in Malawi 3.4.5 Specific objective 5: Enhance technical and procedural measures for implementing cybersecurity for CIIs 3.4.5.1 Establish mandatory and minimum technology and security requirements for CIIs 3.4.5.2 Develop a national government programme to deploy and manage government ICT infrastructure 3.4.5.3 Develop a national programme to enhance internet infrastructure development and resilience. 3.4.5.4 Develop National Contingency plans which identify emergency response asset priorities and standard operating procedures (SOPs) 3.4.5.5 Review and update the map of current emergency response assets 3.4.5.6 Ensure communication channels are deployed across emergency response functions, geographic areas of responsibility, public and private responders, and command authority. Page | 18

Select target paragraph3