Recently Updated Pages
Security Incident Management
Key steps: Prepare: maintain an incident response plan with roles, communication trees, and es...
Upgrade / Decommission
Goal: Safely retire or replace systems while preserving required records and preventing data leak...
Operations and Maintenance
Goal: Sustain security and privacy posture throughout operations. Maintain a schedule for vuln...
Deployment
Goal: Deploy securely with correct configurations, access controls and monitoring in place. Ap...
Testing
Goal: Verify security and privacy controls work as intended. Create a security test plan cover...
Development
Goal: Implement secure, privacy-aware code and configurations. Adopt secure coding standards (...
Architecture and design
Goal: Design an architecture that enforces privacy and security by construction. Produce secur...
Requirements and acquisition
Goal: Ensure requirements include explicit privacy and security criteria. Define functional, p...
Minimum Security and Privacy Controls
Data minimization and purpose limitation, collect only what is necessary. Strong encryption fo...
Core Principles
Combine the foundational Privacy by Design (PbD) principles with Security-by-Design objectives in...
List of Abbreviations
RISA: Rwanda Information Society Authority GoR: Government of Rwanda PbD: Privacy by Design ...
Introduction
This guideline provides practical, step-by-step guidance for embedding security and privacy princ...
Review and update
These guidelines will be reviewed annually or as needed by the RISA Skills Team in collaboration ...
Learning progress report
Throughout the training period, the training provider will share progress reports with the RISA S...
Support system for training delivery
Participants will receive several forms of support to ensure a smooth and productive learning exp...
Obligations for participants during the training
Participants are expected to actively commit to their training by following these guidelines: ...
Training delivery and learning materials
Once participants are approved, they are enrolled in their assigned training programs. For online...
Training application process
Eligibility To qualify for training opportunities, staff must meet the following conditions: ...
Scope
These guidelines apply to: All public servants in the ICT sector, including IT staff, support te...
Annual training plan
The annual training plan turns the sector’s capacity-building priorities into a practical schedul...