4
implementation with regards to the compliance framework of Cyber Security
policy needs to be constantly monitored, assessed, and improved.
For that matter, a holistic approach and appropriate legal and technical
structures could help to identify the potential threats and consequences
attached thereto, and properly it could investigate and no weak area be left
to be exploited by the wrongdoers.
1.3.3 Enforcement of Required Structures and Processes
The assurance of Cyber Security requires proper structures and processes for
governance, regulation, implementation, and enforcement. Any absence or
weakness of the regulation structures poses a threat to Cyber Security.
i.
Inadequate and Poor Quality of Resources
Cyber Security is a rapidly growing field that requires a continually updated set
of relevant skills and resources as the inadequacy of the required skills shall lead
to weaknesses in Cyber Security. Moreover, bridging the demand and supply
gap in the digital workforce is an emerging challenge. The absence of a
mechanism for ensuring the quantity and quality of these skills and resources is
a threat to the Cyber Security of the country.
ii.
Lack of Data Governance
Countries face the threat of data colonization whereby data is managed,
controlled, and processed out of the legal jurisdiction of the country and there
is limited or no bilateral agreement among the stakeholders in this regard.
Threat actors are liable to pollute the information domain and citizen data may
be sold to third parties without due consent or validation. Such proliferation
and abuse of data lead to the exploitation of selected segments of society.
Weak governance of data, poor data quality, and absence of data
stewardship generate unreliable information resources and poses a threat to
Cyber Security.
iii.
Reliance on External Resources
With the increasing use of information technology in all domains including
operations technology, critical information assets are likely to be exposed to
cyber-attacks. In absence of adequate local resources, reliance on external
National Cyber Security Policy 2021