Advanced Search
Search Results
727 total results found
User documentation [Mandatory]
This documentation is created for end-users and should explain in the simplest way possible how users can effectively use the software. User documentation provides an overview of the product’s functionality and gives basic guidelines on how to use it. The docu...
Software configuration and maintenance documentation [Mandatory]
Software maintenance and configuration document is a document that provides key information required to effectively maintain the software. It includes the configurations required for the software including security settings, installation instructions, versio...
Certificate Revocation
Objective: Make sure your system checks whether a certificate is still valid and has not been revoked. Guidelines: Your system must check that a certificate has not been revoked before accepting it. Use one or both of these standard protocols: OSCP (O...
Certificate Expiration
Objective Prevent expired certificates from being used in your system. Guidelines Automatically check the certificate's validity period (start and end dates) every time you validate it. Never accept an expired certificate for any operation. Show the us...
Signature Validation
Objective: Confirm that digital signatures are authentic (made by the right person) and that the signed document has not been changed. This includes Long-Term Validation (LTV) and time-based validity. Guidelines: Build validation into your system so that ...
Password Management
Objective: Keep user certificate passwords safe. Guidelines: Never store user certificate passwords in a database or in any file that others could access. Always use HTTPS so that passwords are encrypted while travelling between the user's browser and yo...
Timestamp Validation
Objective: Make sure the date and time attached to a digital signature are accurate and can be trusted. Guidelines: Use a trusted Time Stamping Authority (TSA) to attach accurate, synchronized timestamps to digital signatures. Using a centralized timesta...
Objectives
These guidelines aim at providing a uniform framework for the design, configuration, and management of digitalization across government institutions in Rwanda to: Harmonize and ensure security and protection of critical systems, infrastructure, data and inf...
Benefits
Adoption of these guidelines will allow government institutions to: Have a high quality and reliable work environment. Efficiently deliver government services to citizens. Remove duplication and reduce costs related to digitalization operations. Enable ...
Scope
These guidelines shall be strictly adhered to by all government institutions, including institutions at central and local government as well as all their affiliated agencies and parastatals.They cover areas including network infrastructure, hardware and end-us...
Principles
These digitalization implementation guidelines shall be used as best practices for digitalization deployment. Digitalization offices shall submit sector level compliance reports annually as an assessment tool to evaluate enforcement of these guidelines. Al...
Network design
The following parameters shall be based on while designing institution network: Number of users in the institution: The number of network users shall be both employees and guests. Services accessed or offered by the institution: Services shall be defined ...
Network Implementation
Network equipment: The network equipment and devices comprising the core network infrastructure to provide connectivity and security features shall among others include a rack, minimum routers, switches, and access points, as well as a firewall. Network ca...
Network Management
Network performance: Redundancy, load balancing, application response time, and quality of service shall be controlled and assured. Network maintenance: Each institution shall elaborate a network maintenance plan together with the disaster recovery (DR), bu...
User devices
Institutional devices used by employees shall be labeled (tagged), recorded and proper naming shall be done. They shall not be used to illegally process, distribute, or store any data protected by copyright of intellectual property. These devices shall not be ...
Precaution measures
Offices with digitalization equipment shall be locked to prevent theft and other risks. Digitalization equipment shall not be placed next to air conditioners as humidity and heat can shorten the life of internal components. Users shall not eat, drink or sm...
Stolen computers
In case of a stolen computer, the user shall immediately report to the supervisor and to Rwanda investigation bureau (RIB) and to the administrator in charge. Institution’s rules and regulations governing loss of public properties shall be applied.
User responsibilities
Users shall ensure proper use of digitalization equipment in accordance with all provisions of these guidelines. Users are required to report any misuse or potential threats to digitalization equipment. It is the user’s responsibility to seek guidance when...
Hardware acquisition, maintenance
All IT equipment shall be checked once in every quarter and maintained according to the elaborated maintenance plan. Institutions shall always refer to RISA hardware acquisition and maintenance framework contracts.
Hardware disposal
Following the institution’s disposal committee resolutions regarding digitalization equipment to be disposed, the current electronic devices’ disposal guidelines shall be adhered to.