Advanced Search
Search Results
727 total results found
Awareness, Training and Best Practices
Provide role-specific training and general awareness sessions. Topics should include: Data protection law and privacy (Law No 058/2021). Secure development lifecycle and secure configuration. Phishing awareness and safe handling of sensitive data. Inci...
Compliance, Audit and Continuous Improvement
Schedule regular audits, internal and external assessments, and maintain documented evidence for compliance. Update controls and PIAs when legal/regulatory or threat landscapes change. Use KPIs (e.g: time-to-patch, vulnerabilities found vs remediated) to drive...
References
Law No 058/2021 Relating to the Protection of Personal Data and Privacy. Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software, CISA, October 2023. Minimum Cybersecurity Standards for Public Institutions, NCSA,...
Objectives
This guideline aims to provide clear, actionable instructions to embed security and privacy into software systems used by the Government of Rwanda. It seeks to: Ensure confidentiality, integrity, availability, and privacy of personal data throughout the sof...
Scope
What this guideline covers This guideline applies to all software systems developed, acquired, deployed, or maintained by Government of Rwanda (GoR) institutions. It provides step-by-step instructions, controls, and best practices for embedding privacy and se...
Signature and Certification Processing Time
Objective Set clear expectations for how long signing and certification operations should take. Guidelines Under normal operating conditions, a signature or certification operation is expected to complete within this range: Expected processin...
Signature Appearance
Objective Make sure the visible signature on a document looks professional and never hides the document's content. Guidelines When a signature image is placed on a document: The image must have a transparent background. It must not have a solid white (o...
Protection of Signed Documents Against Unauthorized Modification
Objective Once a document is signed or certified, protect it so that any later change can be detected. Guidelines After a document has been digitally signed or certified: Any change to the document must cause the signature validation to fail or clearly s...
Prevention of Additional Untrusted Signatures
Objective Stop anyone from quietly adding an unauthorized or untrusted signature to a document that was already signed by the system. Guidelines A document signed through the PKI system must be protected so that extra, untrusted signatures cannot be added w...
Prevention of Unauthorized Document Changes
Objective Protect signed documents from any action that could damage their integrity or trustworthiness. Guidelines Signed documents must be protected against: Adding new content. Removing existing content. Modifying existing content. Adding annotatio...
Verification After Signing
Objective Every system that integrates with the PKI service must offer a way to verify a document after it has been signed. Guidelines At a minimum, the verification must confirm: The digital signature is cryptographically valid. The document has not be...
Closing: Compliance and Integration Assessment
By following these guidelines, developers can be confident that their PKI integration meets the required standards for security and reliability. Build these practices into your development process from the start.