Specific Objectives Strategies/ Actions Deliverables/ Outputs Lead Implementing Agency and Support Time Frame Control Mechanisms, etc. National Vulnerability Register and Vulnerability Disclosure Framework MACRA/MALAWI CERT 3.4.1.6 Undertake continuous monitoring and regular testing to detect errors, vulnerabilities, and intrusions in CII Security Audits and tests to detect errors and vulnerabilities CII Ministry of ICT CII /Ministry of ICT Within 6 months and continuous Within 6 months and continuous MACRA/Malawi CERT Frequency update vulnerability register of of Frequency vulnerability disclosures of MACRA/Malawi CERT CII Number and frequency of security audits and tests; CII Effectiveness of security audits and tests Intrusion detection systems/exercis es Regional and international collaboration programmes Possible Funding Sources and Mechanisms Control Mechanisms, etc. 3.4.1.5 Create a National Vulnerability Register and Framework for regular vulnerability monitoring and disclosure for CII 3.4.1.7 Promote and enhance regional and international cooperation in the protection of the critical information infrastructure (CII) Key Performance Indicators Effectiveness of intrusion detection tests/systems; Ministry of ICT MACRA/MALAWI CERT Within 6 months and continuous Extent of international cooperation in the protection of CII Ministry of ICT MACRA/MALAWI CERT Enhanced Page | 35

Select target paragraph3