0% found this document useful (0 votes)
13 views3 pages

Cybersecurity Framework for PH Government

Uploaded by

LORY LEE PALIS
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views3 pages

Cybersecurity Framework for PH Government

Uploaded by

LORY LEE PALIS
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Module 2 – Information Security & Risk

Management
Focus: Government Digitalization in the Philippines

2.1 ISO 27001 & Cybersecurity for Government


Information Security Management Systems (ISMS)
● Definition: An ISMS is a structured framework of policies, processes, and controls
designed to protect an organization’s sensitive information.
Goal: To ensure confidentiality, integrity, and availability (CIA) of information.
● Application in Government:

○ Protecting citizen records (e.g., PhilHealth member info, PhilSys national ID


database).
○ Securing inter-agency communication (e.g., DSWD–DOH data sharing).
○ Preventing leaks of confidential government contracts and budget allocations.

Example: The Department of Information and Communications Technology (DICT) promotes


ISO 27001 certification among agencies handling critical information infrastructures (CIIs)
like e-Government portals, GovMail, and online payment systems.

Risk Assessment, Risk Treatment & Mitigation Strategies


● Risk Assessment: Identifying possible threats and vulnerabilities.
Example: A hacker exploiting weak passwords in the Bureau of Internal Revenue (BIR)
e-filing system.

● Risk Treatment Options:


○ Avoid – Stop the risky activity.
○ Transfer – Get cyber insurance or outsource to a secure provider.
○ Mitigate – Add controls like multi-factor authentication.
○ Accept – Acknowledge and monitor if cost of fixing is higher than the risk.

● Mitigation Strategies in PH Government:

○ Regular penetration testing in DICT-run systems.


○ Encryption of government financial transactions.
○ Data backup servers located in National Government Data Center (NGDC) in
Clark and Davao.

Business Continuity & Disaster Recovery Planning (BCP & DRP)


● Business Continuity Plan (BCP): Ensures essential services continue even during
cyberattacks or disasters.
● Disaster Recovery Plan (DRP): Focuses on restoring IT systems quickly.

Example:

● During Typhoon Odette (2021), government offices activated backup systems to restore
communication.
● The Philippine Statistics Authority (PSA) maintains redundant servers for PhilSys data
in case of natural disasters.

2.2 Government Cybersecurity Policies


NIST Cybersecurity Framework Basics
● Identify, Protect, Detect, Respond, Recover.
● The DICT uses NIST as a reference in the National Cybersecurity Plan (NCSP) 2022.

Example in PH:

● Identify: DICT identifies critical assets (GovMail, e-Gov Pay).


● Protect: Use of encryption in PhilHealth and PhilSys.
● Detect: Deployment of DICT’s Cybersecurity Bureau monitoring.
● Respond: Immediate shutdown of compromised accounts in GovMail.
● Recover: Restore government cloud services from NGDC backups.

Government-Mandated Controls
● Firewalls – Prevent unauthorized access (e.g., DOST firewalls filtering traffic to
research databases).
● Data Encryption – Required in all government systems that store personal data under
the Data Privacy Act (RA 10173).
● Access Management – Use of biometrics in government offices and role-based access
in systems (e.g., only accountants can approve budget in DBM’s eBudget).

Incident Response Reporting & Compliance


● Under the Cybercrime Prevention Act (RA 10175) and DICT rules, agencies must:

○ Report breaches within a specified period.


○ Document response actions.
○ Cooperate with the National Computer Emergency Response Team (NCERT-
PH).

Example:
In 2023, when the PhilHealth ransomware attack happened, DICT and NCERT-PH
coordinated with PhilHealth to contain the breach, restore systems, and notify the public.

Common questions

Powered by AI

Risk assessment in the Philippine government identifies potential threats and vulnerabilities, enabling the formulation of effective cybersecurity strategies. For instance, the assessment might reveal weak passwords in systems like the Bureau of Internal Revenue’s (BIR) e-filing system, prompting the implementation of stronger security measures such as multi-factor authentication. Such risk assessments help in choosing appropriate risk treatment options to avoid, transfer, mitigate, or accept risks .

The cyber risk mitigation strategies employed by the Philippine government enhance its cybersecurity posture by implementing proactive measures such as regular penetration testing of DICT-operated systems, encryption of financial transactions, and the strategic placement of backup servers in National Government Data Centers (NGDCs) in locations such as Clark and Davao. These actions help to identify vulnerabilities before they are exploited, protect sensitive data during transactions, and ensure data recovery capabilities in case of system failures or cyber attacks, thereby strengthening the overall cyber resilience and preparedness of government operations .

The deployment of biometric access management in Philippine government offices enhances security by ensuring that only authorized personnel can access sensitive areas and information. It provides a robust layer of security since biometric identifiers, such as fingerprints or facial recognition, are unique to each individual and difficult to forge, unlike traditional passwords or ID cards. This method is an effective way of preventing unauthorized access and reducing the risk of data breaches within government infrastructures .

Business continuity and disaster recovery planning aid the Philippine government by ensuring continuity of essential services and swift restoration of IT systems during disruptions, such as cyber attacks or natural disasters. A Business Continuity Plan (BCP) ensures that government operations can continue during crises, while a Disaster Recovery Plan (DRP) focuses on quickly restoring IT services. For instance, during Typhoon Odette in 2021, backup systems were activated to restore communication in affected offices, and the Philippine Statistics Authority maintains redundant servers to secure the PhilSys data against potential disasters .

Data encryption is critical in the government systems of the Philippines to protect the confidentiality and integrity of sensitive personal data against unauthorized access and potential breaches. It is implemented as a mandatory requirement for all government systems that store personal data, as stipulated under the Data Privacy Act (RA 10173). This ensures that even if data is intercepted, it remains unreadable and secure, thereby bolstering the overall security architecture of government information systems .

ISO 27001 provides a structured framework of policies, processes, and controls aimed at protecting sensitive information. In the Philippines, this standard is applied to protect citizen records, secure inter-agency communications, and prevent leaks of confidential government contracts and budget allocations. The Department of Information and Communications Technology (DICT) encourages ISO 27001 certification among agencies handling critical information infrastructures such as e-Government portals and GovMail to maintain the confidentiality, integrity, and availability of data .

The Philippine government ensures compliance with incident response reporting requirements by mandating breach reports and documentation of response actions under the Cybercrime Prevention Act (RA 10175) and DICT rules. Agencies must report breaches within a specified period and cooperate with the National Computer Emergency Response Team (NCERT-PH). In instances like the PhilHealth ransomware attack in 2023, DICT and NCERT-PH coordinated with PhilHealth to contain the breach, restore systems, and publicly notify about the incident, demonstrating structured and compliant incident response procedures .

The National Cybersecurity Plan (NCSP) 2022 shapes cybersecurity policies in the Philippines by providing a comprehensive framework based on the NIST Cybersecurity Framework principles: Identify, Protect, Detect, Respond, and Recover. The DICT employs these principles to protect critical assets like GovMail and e-Gov Pay, using encryption for systems such as PhilHealth and PhilSys. The plan ensures that incident response and recovery protocols are in place, such as the deployment of DICT's Cybersecurity Bureau for monitoring and the restoration of services from NGDC backups, thereby enhancing the overall cyber resilience .

Government-mandated controls in the Philippines, such as firewalls, data encryption, and access management, are effective measures in preventing unauthorized access to sensitive data. Firewalls, like those used by the Department of Science and Technology (DOST), filter traffic to secure research databases, while encryption is mandated for all government systems storing personal data as per the Data Privacy Act (RA 10173). Access management practices, such as biometrics in offices and role-based access in systems (e.g., budget approval restricted to certain roles in the Department of Budget and Management's eBudget), add multiple layers of security to control and monitor access effectively .

The Philippine government might choose to 'accept' a cyber risk when the cost of mitigating the risk exceeds the potential impact or when the likelihood of the risk materializing is low. Accepting a risk involves acknowledging its presence and continuously monitoring it rather than expending resources on mitigation. This approach is pragmatic in cases where mitigation options offer negligible security benefits or where resource allocation is better served addressing higher priority risks. However, accepted risks must be clearly documented and tracked to ensure they remain within acceptable thresholds .

You might also like