b) Through the ISSD of MCIT enforce the adaptation of ISO 2700 series and other International standards for Information Security Management System (ISMS), information assurance, Information Systems and IT infrastructure audits, Vulnerability assessment, Risk management of the critical information infrastructures (CII), Business continuity, ensure Application security through Software Development Life Cycle (SDLC) and best practices and Penetration testing of IT infrastructures. c) Enforce data classification of all governmental entities in order to ensure data confidentiality and apply access controls (Physical, Technical and Administrative) to ensure accountability. d) Periodically conduct risk assessment and security standard compliance of the critical information infrastructures (CII). 3. Establishing a regulatory framework a) MCIT will work together with the Ministry of Justice (MoJ) to develop legal framework and conduct for addressing cybersecurity issues b) Develop the Cyber Law of Afghanistan and Child Online Protection policy with support and cooperation’s of US-DOC, CLDP, European Commission, UNCITRAL and International Multilateral Partnership Against Cyber Threats (IMPACT) c) Develop legal framework for private Certification Authority (CA) and secure electronic transaction system for business and financial institutes d) Develop legal framework and policies to assure secure mobile computing, cloud computing, mobile governance and internet governance e) Develop regulatory framework for auditing and certifying IT infrastructures for the sack of cyber security within the government and for those Solution providers (SPs) who are providing IT services to the government f) Organize awareness campaign for all regulatory frameworks and periodically update the regulatory frameworks with the evolving technological advancements. 4. Enhance AFCERT capabilities a) AFCERT as the focal point will act as first responder to any cyber incident or computer crime investigations within the government and private sector b) Coordinate crime scene investigation report with law enforcement for further processes c) Provide cyber related awareness to all government and nongovernment agencies through its Network Operation Center (NOC), workshops, seminars, email, magazines and newsletters d) Extend its operation hours to 24/7 service availability within the timeframe of two years e) Assist provinces in establishing the provincial CERTs f) Keep strong engagement and coordination with regional CERTs in order to fight against cyber crimes Information  Systems  Security  Directorate  -­‐  MCIT  

Select target paragraph3