PART EIGHT
PRINCIPLES ON ASSURANCE & MONITORING
8.1 Introduction:
i.
Vulnerabilities exist in critical national information infrastructure for several
reasons including: technological flaws, non-existent or weak security controls,
non-compliance with defined security policies, dearth of effective mitigating
strategies and plans amongst others.
ii.
Absence of a feedback reporting mechanism on how effective implemented
controls are safeguarding the nation's cyberspace will lead to an assumed,
unverified and false sense of protection.
iii.
The policy provides for the creation of a National Assurance & Monitoring
mechanism for the nation’s cyberspace.
8.2 Focal Points:
The National Assurance & Monitoring Mechanism, under the supervision and
coordination of NCCC will achieve the following outcomes:
i.
Motivate compliance to national cybersecurity standards.
ii.
Ensure collection of relevant data that validates previous cyber security
initiatives, and support its' on-going improvements.
iii.
Provide feedback on the status of the nations' cyber security posture,
thus enabling stakeholders, partners and policy-makers to develop sound
cyber
security
countermeasures
and
risk
mitigation
strategies.