Answer First
Primary Text
Responsibility of the National and Local Governments. - All agencies, offices, and instrumentalities of the national and local governments, including SUCs and GOCCs, shall be responsible for:
(a) Providing information security protections commensurate with the risk and magnitude of the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of information collected or maintained by or on behalf of the agency; and information systems used or operated by an agency, its contractor, or by other organizations on its behalf;
(b) Determining the levels of information security appropriate to protect such information and information systems, and implementing the same in coordination with the DICT;
(c) Periodically testing and evaluating information security controls and techniques to ensure that they are effectively implemented;
(d) Ensuring procedures, standards, and guidelines, including information security standards promulgated by the DICT and information security standards promulgated by the DICT and information security standards and guidelines for national security systems issued in accordance with law and as directed by the President of the Philippines;
(e) Ensuring that information security management processes are integrated with agency strategic and operational planning processes; and
(f) Adopting the Privacy-by-Design, Privacy Engineering, and Privacy-by-Default principles in developing, implementing, and deploying systems, processes, software applications, and services throughout the processing of personal data.
Use With Care
Definitions and exceptions often appear before or after this text.
Court decisions may interpret, limit, or apply this provision.
Confirm amendment, repeal, effectivity, and official publication.