39 5.4 Recommendations: - The Ministry of Communications, Science and Technology, in conjunction with the Inter-ministerial Legal Reform Taskforce, should review the OECD Guidelines and Implementation Plan and other relevant information (e.g., APEC Cybersecurity Strategy, Australia E-Security National Agenda) for consideration of adoption of the Guidelines and the development of an Implementation Plan by the Government of Botswana. - The Ministry of Communications, Science and Technology, in conjunction with the Inter-ministerial Legal Reform Taskforce, consider ISO/IEC17799/BS7799 as a tool for setting rules for government IT purchases and assessing compliance of government systems with the “Risk assessment”, “Security design and implementation”, “Security management” and “Reassessment” principles of the Security Guidelines. - The Ministry of Communications, Science and Technology, in consultation with the Ministry of Trade and Industry, the Ministry of Finance and Development Planning, the Ministry of Health, the Botswana Telecommunications Authority, the Bank of Botswana, the Botswana Stock Exchange, the Law Society and such stakeholders as representatives of financial institutions, brokerage houses, hospitals, business and consumer groups, and civil liberties groups consider developing a National Policy for Security of Information Systems and Networks. - The Ministry of Trade and Industry, in consultation with the Ministry of Trade and Industry, the Ministry of Finance and Development Planning, the Ministry of Health, the Botswana Telecommunications Authority, the Bank of Botswana, the Botswana Stock Exchange, the Law Society and such stakeholders as representatives of financial institutions, brokerage houses, and business and consumer groups explore the implementation of ISO/IEC17799/BS7799 for selected industries, such as financial institutions and brokerage houses to provide an independently certifiable standard of security and risk assessment. - The Ministry of Health, in cooperation with the Ministry of Local Government and in consultation with stakeholders from both the public and private health systems such as the hospitals, local medical associations, the Health Professions Council, the National AIDS Coordinating Agency, and the Ministry of Communications, Science and Technology, should work to improve the protection of personal information, by considering the adoption of the ISO/IEC17799/BS7799 standards or basing internal security practices on the standards.

Select target paragraph3