5 Information Security 5.1 Introduction Information and the supporting processes, systems and networks that process, store, retrieve, and transmit it, play a vital role in the conduct and success of GoU and private sector operations. Therefore, organisations must protect the information they handle internally and that they share with external partners. Assuring the confidentiality, integrity and availability of information is necessarily a corporate-level concern because security incidents threaten organisational reputations, legal positions and the ability to conduct business operations. 5.1.1 GoU information security commitment The GoU is committed to: 5.1.2  Achieving high standards of Information Security governance;  Treating information security as a critical business issue and creating a security-conscious environment;  Demonstrating to third parties that it deals with information security in a proactive manner; and  Applying the guiding principles outlined in section 3 such as implementing controls that are proportionate to risk. Applicability of information security requirements Uganda is determined to thwart internal and external threat actors seeking to breach the security of information assets within the country. Therefore, the information security mandatory minimum-security requirements apply to: i. All staff in organisations with critical infrastructure including public and civil servants, contractors, consultants, temporary employees, guests and volunteers. The requirements also apply to third parties that access and use of information that critical infrastructures handle; ii. All types of information i.e. written, printed on paper, stored electronically or optically, transmitted by courier or using electronic means, recorded on magnetic disk or tape, or spoken in conversation; iii. All information assets including that which public and private sector critical infrastructure organisations use under license or contract. The information can be in any form and recorded on any media, and all computer hardware, computer software and communications networks owned or operated by the organisations or on their behalf; and iv. Any device, regardless of ownership and including equipment privately owned by public and civil servants, and citizens e.g., laptop computers, tablet computers, smartphones, MP3 players, USB storage devices, etc.

Select target paragraph3