39
5.4
Recommendations:
- The Ministry of Communications, Science and Technology, in
conjunction with the Inter-ministerial Legal Reform Taskforce,
should review the OECD Guidelines and Implementation Plan and
other relevant information (e.g., APEC Cybersecurity Strategy,
Australia E-Security National Agenda) for consideration of adoption
of the Guidelines and the development of an Implementation Plan by
the Government of Botswana.
- The Ministry of Communications, Science and Technology, in
conjunction with the Inter-ministerial Legal Reform Taskforce,
consider ISO/IEC17799/BS7799 as a tool for setting rules for
government IT purchases and assessing compliance of government
systems with the “Risk assessment”, “Security design and
implementation”, “Security management” and “Reassessment”
principles of the Security Guidelines.
- The Ministry of Communications, Science and Technology, in
consultation with the Ministry of Trade and Industry, the Ministry of
Finance and Development Planning, the Ministry of Health, the
Botswana Telecommunications Authority, the Bank of Botswana,
the Botswana Stock Exchange, the Law Society and such
stakeholders as representatives of financial institutions, brokerage
houses, hospitals, business and consumer groups, and civil liberties
groups consider developing a National Policy for Security of
Information Systems and Networks.
- The Ministry of Trade and Industry, in consultation with the
Ministry of Trade and Industry, the Ministry of Finance and
Development Planning, the Ministry of Health, the Botswana
Telecommunications Authority, the Bank of Botswana, the
Botswana Stock Exchange, the Law Society and such stakeholders
as representatives of financial institutions, brokerage houses, and
business and consumer groups explore the implementation of
ISO/IEC17799/BS7799 for selected industries, such as financial
institutions and brokerage houses to provide an independently
certifiable standard of security and risk assessment.
- The Ministry of Health, in cooperation with the Ministry of Local
Government and in consultation with stakeholders from both the
public and private health systems such as the hospitals, local medical
associations, the Health Professions Council, the National AIDS
Coordinating Agency, and the Ministry of Communications, Science
and Technology, should work to improve the protection of personal
information,
by
considering
the
adoption
of
the
ISO/IEC17799/BS7799 standards or basing internal security
practices on the standards.