Cambodian ICT Masterplan 2020
First, in pursuing e-Government and public-sector informatization initiatives, a comprehensive
framework act that sets out broad outlines and high-level principles should be introduced.
This framework act must include key provisions on legal grounds for large-scale, long-term
investments, coordination systems among government agencies concerned, policy development
to bridge digital divide, informatization planning, progress monitoring and assessment, as
well as effective IRM. Second, proactive campaigns and education programs designed to raise
awareness of informatization initiatives as collective efforts of the government and citizens
should be conducted. To this end, support for such programs and capacity-building activities
for government officials and citizens needs to be guaranteed by law, especially in the early stage
of informatization. Lastly, in parallel with the high-level principles laid down in the framework
act, subsidiary legislations of each relevant government department should be drawn up either
simultaneously or sequentially. The good examples of such subsidiary legislations include the
Digital Signature Act, Electronic Commerce Act, Personal Information Protection Act, Citizen
Registration Act, Customs Act, and Government Procurement Act.
6. Cyber Security
6.1 Introduction
As ICT infrastructure policies are vitalized, information security becomes important issues in
Cambodia as well as in the world. However, although Cambodia has tried to establish national
cyber security base through CamCERT organization, there are some limitations such as lack of
comprehensive cyber security system to ensure ICT service reliability, absence of relevant laws,
regulations, policy, standard & norm, low level of knowledge and know-how skill on cyber
security, and outdated infrastructure for cyber security (e.g. Information systems, ICT devices).
To overcome these limitations and enhance the nationwide cyber security, it is needed to enhance
cyber security system in Cambodia such as enactment completion of relevant legislations and
establishment of government-wide leadership & organization. Moreover, it is necessary to expand
cyber security activities through enhancing CERT system, protecting major infrastructure and
distributing the standard. It is also crucial to build health culture for cyber security through
making measures for unhealthy information distribution prevention, implementing illegal spam
mail prevention system and executing awareness education & promotion for cyber security.
18