SA's cybersecurity plans
The South African department of communications on Friday published its plans for a national cybersecurity policy in the Government Gazette. The document outlines plans to create a multi-tier cybersecurity structure to monitor and act on perceived Internet-based threats to state security.
The proposal says that South Africa “does not have a coordinated approach in dealing with Cybersecurity. Whilst various structures have been established to deal with Cybersecurity issues, the structures are inadequate to deal with Cybersecurity issues holistically.
There are various legal provisions addressing Cybersecurity in South Africa. However these provisions do not adequately address the legal challenges South Africa faces to effectively deal with cybercrime,” the document says. “Bridging the technology/law divide remains a fundamental challenge.”
The other crucial element noted by the proposal is the need to strengthen the country’s collaboration with international agencies to confront threats posed by the “global nature of ICTs”.
Cybersecurity structures
Based on the need to establish “holistic” cybersecurity policies, the department of communications is proposing a multi-tier structure to monitor national and sectoral threats. Overseeing the cybersecurity strategy will be the National Cybersecurity Advisory Council (NCAC). The NCAC is intended to both advise government on cybersecurity issues as well as promote cybersecurity relationships with other governments. The NCAC will also be in charge of developing and promoting public-private partnerships around security.
While the NCAC is more strategic in its outlook the operational side of cybersecurity will be managed by a National Computer Security Incident Response Team (CSIRT), a Government CSIRT and Sector CSIRTs. The National CSIRT will be established under the department of communications and co-ordinate analysis of cybersecurity events, information dissemination to other CSIRTs and “act appropriately on threats”.
The Government CSIRT will “act as a single point of contact for all organs of state” as far as cybersecurity is concerned. The Government CSIRT will also co-ordinate responses across all government departments and audit the state of cybersecurity readiness in all state organs.
The Sector CSIRTs will be established in different sectors and will report to the National CSIRT.
The proposal says that there is a need for “a vigilant and proactive approach to information security through continuous mapping, assessment and prediction of potential threats.” Among the objectives of the national cybersecurity policy will be the job of developing “technical, regulatory and legal measures” to reduce cybersecurity threats.
The cybersecurity proposal can be downloaded from here and interested parties have 30 days from its publication, on 19 February, to make submissions.
SA’s cybersecurity plans << Discussion