5. Information Security within Government 5.1. Government Engagement Objective: Recommended Control 1: Security personnel are aware of and use information security services offered within the Bangladesh Government IT and security personnel should familiarize themselves with the information security roles and services provided by Bangladesh Government organizations There is a number of organizations that are involved in providing information security advice to government agencies. GOBISM provides contact information of the responsible agency, where other agencies can seek advice and assistance relating to the implementation on GOBISM and other issues related to information security. The table below contains a brief description of the other organizations which have a role in relating to information security within government. Organization Bangladesh Police Comptroller and General Services Law enforcement in relation to electronic crime and other high tech crime Auditor Independent assurance over the performance and accountability of public sector organizations, including IT audit and better practice guides for areas including information security Bangladesh Computer Services to government agencies and critical infrastructure providers to Council assist them to defend against cyber threats Ministry of Home Affairs Guidance on risk management, authentication standards and e‐gov services Ministry of Commerce Development, co‐ordination and oversight of Bangladesh Government policy on e‐commerce, online services and internet National Archives Provides information on the archival of Government information Ministry of Law Advice on how to comply with Privacy Act and related legislation 5.2. Industry Engagement and Outsourcing Objective: Recommended Control 1: Industry handling government information implements the same security measures as government agencies Where an agency has outsourced information technology services and functions, any ITSMs within the agency should be independent 10

Select target paragraph3