MyMIS
The ICT security process
must cover various
aspects in achieving a
secure enviroment
The ICT security process must cover all aspects of operation, including
mechanisms used by hardware and software systems, networks, databases
and other related systems and facilities. The goal is to achieve a secure
working environment for employees and other persons working at or visiting
the government’s facilities as well as to help establish processes to ensure
the protection of information.
ICT security processes
should mirror
management’s direction
The ICT security process should mirror the management’s direction in
relation to:
(a) overall organisational policy;
(b) organisational roles and responsibilities;
(c) personnel;
(d) government’s asset classification and control;
(e) physical security;
(f) system access controls;
(g) network and computer management;
(h) application development and maintenance;
(i) business continuity;
(j) compliance to standards as well as legal and statutory requirements;
(k) classification and protection of information media;
(l) employee awareness programmes; and
(m) incident reporting and response.
1.2
This handbook provides
guidelines on ICT
security based on
international standards
Standards Framework
This handbook provides essential guidelines to government employees on
the ICT security process in the public sector. It is based mainly on two
standards i.e. the MS ISO/IEC 13335 (Part 1 - 3) and the BS 7799 (Part
1 and 2). It also makes references to the Canadian Handbook on Information
Technology Security, German IT Baseline Protection Manual and other related
ISO standards.
Various levels of details of standards can be viewed in the model depicted
in Figure 1.1. In comparison to other standards and documents of ICT security
management particularly to their level of detail, this handbook can be positioned
along with the BS 7799, the Canadian MG-9 and the American National
Institute of Science and Technology (NIST). This is warranted by the fact
that this handbook is jurisdictional and specific to the Malaysian public sector.
Description of model
(Figure 1.1)
In the model, the areas and level of details of these standards varies between
each standard. Level 1, 2, 3 and 4 represent the Guidelines for the Management
of IT Security (GMITS) or ISO/IEC 13335. It indicates the depth of knowledge
required to understand the respective level. As an example, a Level 1 document
needs no prior knowledge on ICT security management while a Level 2
document needs at least some understanding of the previous level.
Level 1 to level 4 of the
model
The model progresses from Level 1 ‘Concepts and Models’ to Level 2 ‘Managing
and Planning IT’, Level 3 ‘Techniques for the Management of IT’ before
detailing ‘Selection of Safeguards, Management Guidance on Network and
Guidelines for the Management of Trusted Third Parties’ in Level 4.
Copyright MAMPU
Chapter 1 - 2