Answer First
Primary Text
Protection of Government Critical Information Infrastructure (CII). - The DICT, in coordination with relevant government agencies and stakeholders, shall issue guidelines for the protection of government CII identified in the EGMP. All government CIIs shall undergo Vulnerability Assessment and Penetration Testing (VAPT) before deployment and an annual risk and security assessment.
All government CII shall create an organizational Computer Emergency Response Team (CERT) or Computer Security Incident Response Team (CSIRT) and immediately notify major information security incidents affecting their institution to the DICT's National Computer Emergency Response Team (NCERT), which shall be the central authority for all the sectoral and organizational CERTs in the country, subject to rules and regulations, protocols, guidelines and standards in cybersecurity.
Use With Care
Definitions and exceptions often appear before or after this text.
Court decisions may interpret, limit, or apply this provision.
Confirm amendment, repeal, effectivity, and official publication.