Table of Contents Page i Acknowledgement Chief Secretary to the Government iii Table of Contents v List of Tables xiii List of Figures xiv List of Appendices xv Chapter 1 INTRODUCTION 1 - 1 1.1 General 1 - 1 1.2 Standards Framework 1 - 2 1.3 Handbook Coverage 1 - 3 1.4 Audience 1 - 4 Chapter 2 MANAGEMENT SAFEGUARDS 2.1 2.2 Public Sector ICT Security Policy 2 - 1 2.1.1 Central Level 2 - 2 2.1.2 Ministry/State Level 2 - 2 2.1.3 Departmental Level 2 - 3 Public Sector ICT Security Programme Management 2.2.1 2.2.2 2.3 2 - 1 2 - 3 Central Public Sector ICT Security Programme Management 2 - 4 Operating Level Public Sector ICT Security Programme Management 2 - 4 Public Sector ICT Security Risk Management 2 - 5 2.3.1 Formation of Risk Management Committee 2 - 5 2.3.2 Identification of Risks and Threats 2 - 6 2.3.3 Evaluation of Risks and Threats 2 - 6 2.3.4 Identification of Necessary Safeguards 2 - 7 2.3.5 Managing Residual Risks 2 - 8 2.3.6 Implementing Safeguards and Monitoring Effectiveness 2 - 8 Uncertainty Analysis 2 - 8 2.3.7 v

Select target paragraph3