MyMIS Chapter 1 INTRODUCTION 1.1 General Definition “Public Sector ICT Security can be defined as the process of ensuring business continuity and services provision free from unacceptable risk. It also seek to minimize disruptions or damage by preventing and minimizing security incidents” – Public Sector ICT Security Policy (Appendix A). Security of information within the government’s ICT system is a major concern The security of information within the Government of Malaysia’s Information and Communications Technology (ICT) system is a subject of major concern. Threats such as impersonation, malicious code, misuse of data, easily available penetration tools, powerful analytical techniques contribute in whole or in part to the necessity of providing adequate protection to public sector ICT assets. These threats if left unchecked, will result in painful explaination at the very minimum or untold damage to the country. Apart from incurring financial losses, both in terms of resources and unavailable services, these threats severely jeopardises the confidentiality, integrity and availability of official government information and in the end may be of detriment to the country. The hardest thing to comprehend is that an attack can be easily mounted by anyone from anywhere courtesy of the information superhighway and the misused concept of global instantaneous information sharing. Some examples of common threats are listed in Appendix B. Need for effective Public Sector ICT Security management Over the years, government agencies have been religiously collecting vast amount of information. It is in the early 70’s that these information have been deposited into digital format and since then, these repositories have unknowingly become exposed because of the invaluable information they keep and now in a format easily manipulated without stringent audit trail. The government realises this and that the government is also aware that there is an urgent need to secure the vast information resource through effective management of the security of ICT systems. In this regard, efforts are being made to ensure Public Sector ICT Security management achieve and maintain a high level of confidentiality, integrity and availability. A comprehensive approach to ICT Security processes is required A comprehensive approach is required in planning, developing, operating and maintaining the government’s ICT security processes. The ICT security measures need to be incorporated early, in the requirement specification and design of the ICT system, before the implementation stage to ensure a cost-effective and comprehensive system. The main steps include: (a) assessing the current security strengths and vulnerabilities; (b) developing ICT security policies, standards and processes; (c) designing and developing a customised security architecture; and (d) evaluating and selecting the best security system for the organisation. Copyright MAMPU Chapter 1 - 1

Select target paragraph3