MyMIS
Chapter 1
INTRODUCTION
1.1
General
Definition
“Public Sector ICT Security can be defined as the process of ensuring business
continuity and services provision free from unacceptable risk. It also seek
to minimize disruptions or damage by preventing and minimizing security
incidents” – Public Sector ICT Security Policy (Appendix A).
Security of information
within the government’s
ICT system is a major
concern
The security of information within the Government of Malaysia’s Information
and Communications Technology (ICT) system is a subject of major concern.
Threats such as impersonation, malicious code, misuse of data, easily available
penetration tools, powerful analytical techniques contribute in whole or in
part to the necessity of providing adequate protection to public sector ICT
assets. These threats if left unchecked, will result in painful explaination at
the very minimum or untold damage to the country. Apart from incurring
financial losses, both in terms of resources and unavailable services, these
threats severely jeopardises the confidentiality, integrity and availability of
official government information and in the end may be of detriment to the
country. The hardest thing to comprehend is that an attack can be easily
mounted by anyone from anywhere courtesy of the information superhighway
and the misused concept of global instantaneous information sharing. Some
examples of common threats are listed in Appendix B.
Need for effective Public
Sector ICT Security
management
Over the years, government agencies have been religiously collecting vast
amount of information. It is in the early 70’s that these information have
been deposited into digital format and since then, these repositories have
unknowingly become exposed because of the invaluable information they
keep and now in a format easily manipulated without stringent audit trail.
The government realises this and that the government is also aware that
there is an urgent need to secure the vast information resource through
effective management of the security of ICT systems. In this regard, efforts
are being made to ensure Public Sector ICT Security management achieve
and maintain a high level of confidentiality, integrity and availability.
A comprehensive
approach to ICT Security
processes is required
A comprehensive approach is required in planning, developing, operating
and maintaining the government’s ICT security processes. The ICT security
measures need to be incorporated early, in the requirement specification
and design of the ICT system, before the implementation stage to ensure
a cost-effective and comprehensive system. The main steps include:
(a) assessing the current security strengths and vulnerabilities;
(b) developing ICT security policies, standards and processes;
(c) designing and developing a customised security architecture; and
(d) evaluating and selecting the best security system for the organisation.
Copyright MAMPU
Chapter 1 - 1