5
Information Security
5.1
Introduction
Information and the supporting processes, systems and networks that process,
store, retrieve, and transmit it, play a vital role in the conduct and success of
GoU and private sector operations. Therefore, organisations must protect the
information they handle internally and that they share with external partners.
Assuring the confidentiality, integrity and availability of information is necessarily
a corporate-level concern because security incidents threaten organisational
reputations, legal positions and the ability to conduct business operations.
5.1.1
GoU information security commitment
The GoU is committed to:
5.1.2
Achieving high standards of Information Security governance;
Treating information security as a critical business issue and creating a
security-conscious environment;
Demonstrating to third parties that it deals with information security in a
proactive manner; and
Applying the guiding principles outlined in section 3 such as implementing
controls that are proportionate to risk.
Applicability of information security requirements
Uganda is determined to thwart internal and external threat actors seeking to
breach the security of information assets within the country. Therefore, the
information security mandatory minimum-security requirements apply to:
i.
All staff in organisations with critical infrastructure including public and
civil servants, contractors, consultants, temporary employees, guests and
volunteers. The requirements also apply to third parties that access and
use of information that critical infrastructures handle;
ii.
All types of information i.e. written, printed on paper, stored electronically
or optically, transmitted by courier or using electronic means, recorded on
magnetic disk or tape, or spoken in conversation;
iii.
All information assets including that which public and private sector
critical infrastructure organisations use under license or contract. The
information can be in any form and recorded on any media, and all
computer hardware, computer software and communications networks
owned or operated by the organisations or on their behalf; and
iv.
Any device, regardless of ownership and including equipment privately
owned by public and civil servants, and citizens e.g., laptop computers,
tablet computers, smartphones, MP3 players, USB storage devices, etc.