Directives on Cyber Security for Network and Information Systems for all Public Institutions

This Directive aims at providing important instructions and guidelines for securing GoR entities ICT infrastructures and Information.

Purpose of the Directive

This Directive aims at providing important instructions and guidelines for securing GoR entities ICT infrastructures and Information by: 

To achieve the above, all GoR entities should have minimum security controls implemented within their network before connecting their network to Internet. These controls are described below:

Minimizing the Exposure of Systems to External Networks

Intrusion Prevention System (IPS)

Email Protection

Gateway Level Antivirus Protection

You must have gateway level antivirus protection to detect and disinfect the network traffic to ensure all detectable virus on the gateway not entering and infecting internal servers or systems 

Wireless Protection

Web Browsing Protection

Securing On-premises Hosted Services

Visibility and Monitoring

Patch Management

Security Assessment

End User/ End Point Protection

Implement Passwords Policy

Availability of Systems and Services

Ensure critical services are available whenever it required by:

Backups

 

Incident Management

Security Awareness

Conduct regular security awareness programs for the end-users and system administrators to secure institution's data and information from any attacks