are secure and resilient. The protection of Malawi’s information infrastructure including CIIs necessitates collaboration of all relevant stakeholders including public and private institutions that own or operate the information infrastructure which supports the wellfunctioning of the Malawian society. Consequently, the Government of Malawi will work with all relevant stakeholders to identify and understand the vulnerabilities and levels of cybersecurity of Malawi’s information infrastructure, especially CIIs. The Government will also work with relevant stakeholders to establish measures that will address current and future cyber threats and risks to the national information infrastructure, and drive improvements where necessary. 4.5.1. Specific Objective 1: Identify the Critical Information Infrastructure of Malawi. Actions: 4.5.1.1. Establish a National CII Register 4.5.1.2. Create a National Vulnerability Register and Framework for regular vulnerability monitoring and disclosure for CII 4.5.1.3. Establish a National Risk Register and Regulations and/or Guidelines that promote continuous risk assessment and management across CIIs in Malawi 4.5.2. Specific Objective 2: Protect the Critical Information Infrastructure of Malawi. Actions: 4.5.2.1. Develop a National CII Governance Framework which provides details on CII protection procedures and processes 4.5.2.2. Establish Mandatory Equipment Specifications, Mandatory Guidelines, Regulations, Security Requirements, Procedures relating to the management of risks by CIIs 4.5.2.3. Undertake continuous monitoring and regular testing to detect errors, vulnerabilities, and intrusions in CII 4.5.2.4. Promote and enhance regional and international cooperation in the protection of the critical information infrastructure (CII) 4.5.3. Specific Objective 3: Continuously manage cyber threats and risks to enhance incident response. Actions: 12

Select target paragraph3