Annex 1: Documents referred to in the Policy Government Information Security Policy This model policy is aligned to the information security standard ISO /IEC 17799. Government organizations may modify and customize this policy to suit their respective organizations' needs, and thus create organizational information security policies. The policy is available in the Re-engineering government section in www.icta.lk. ISO 8601 The International Standard for the representation of dates and times. The standard describes a large number of date/time formats. The document can be purchased from the Sri Lanka Standards Institution, Elvitigala Mawatha, Colombo 08. ISO 10646 ISO/IEC 10646 was published in 1993. Its name is “Universal Multiple-Octet Coded Character Set”. It is a standardized coded character set with the purpose to eventually include all characters used in all the written languages in the world (and, in addition, all mathematical and other symbols). The current edition covers at least all major languages. ISO / IEC 17799 The international Information Security standard, ISO/IEC 17799, Second Edition, 2005, is comprehensive in its coverage of security issues, and establishes guidelines and general principles for initiating, implementing, maintaining and improving security management in an organization. The standard was originally prepared by the British Standards Institution (as BS 7799 Part 1) and was later adopted by ISO (the International Organization for Standardization and IEC (the International Electro-technical Commission).The document can be purchased from the Sri Lanka Standards Institution, Elvitigala Mawatha, Colombo 08. Section 15: obligations, and of any security requirements. Especially, relevant is section 15.1.3 Protection of organizational records, wherein the following controls are given; Important records should be protected from loss, destruction, and falsification in accordance with 22

Select target paragraph3