Annex B- Guidelines for Operation and Management of IT Infrastructure in MDAs.pdf
PDF 834 KB Posted
- Attached to
- USAID/Uganda Fleet Management Activity Federal contract opportunity
- Solicitation number
- 72061720R00012
About this file
This federal contract opportunity solicitation requests support services for a Fleet Management Information System. USAID/Uganda seeks a contractor to design and implement a GPS-enabled FMIS for the Ugandan Ministry of Health that handles fleet management planning, fuel and maintenance management, vehicle bookings and real-time location tracking of up to 2,500 vehicles. The system must allow MOH real-time access to utilization reports. The solicitation provides details on the required FMIS features and functions to manage MOH's vehicle fleet through an electronic system. Interested offerors should review the full solicitation for submission instructions and additional requirement information.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SOL 72061720R00012 Amendment One.pdf | ||
| USAIDs Responses to Questions SOL 72061720R00012.pdf | ||
| SOLICITATION 72061720R00012- MOH Fleet Management .pdf | ||
| Annex C-List of MOH Motor Vehicles.pdf | ||
| Annex A-USAID MOH Fleet Management Assessment Report.pdf | ||
| Attachment B -Pricing Proposal Template.xlsx | XLSX spreadsheet | |
| Attachment A- Past Performance Information Template.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Version Number: 1.0
Date: September 2013
DOCUMENT DETAILS
Security Classification Government/Public
Authority National Information Technology Authority-Uganda (NITA-U)
Author National Information Technology Authority-Uganda (NITA-U)
Documentation Status Working Draft
Consultation Release
Final Version
CONTACT FOR ENQUIRIES AND PROPOSED CHANGES
All enquiries regarding this document should be directed to the Office of the Executive Director.
info@nita.go.ug
ACKNOWLEDGEMENT
This version of the guidelines and standards was developed and updated by the Department of
Architecture, Standards and Certification under the Directorate of Planning Research and
Development, National Information Technology Authority-Uganda (NITA-U).
Feedback was received from a number of staff from the other Directorates which was greatly appreciated.
mailto:info@nita.go.ug
Foreword
The National Information Technology Authority-Uganda a semi-autonomous corporate body established under the NITA-U Act 2009, to coordinate, promote and monitor IT development within the context of National Social and Economic development.
The Authority is financed in part by parliamentary appropriation. The NITA-U policies and operations are managed at arm’s length from Government. NITA-U is overseen by a Board of
Directors whose membership includes government and private-sector representation.
With the goal of enhancing Uganda's economic competitiveness and social well-being, NITA-U leads the efforts of Ugandans in the development and use of national and international IT standards and further intends to offer a range of IT standardization services to the citizens of
Uganda. One such service in line with the NITA-U mandate is the integration of all Government
IT systems in line with the strategy for rationalization of IT services in Government Ministries
Department and agencies
It is important that IT services are offered with the highest standards, in the most comprehensive way and with the best possible IT products to meet user expectation.
This document therefore provides general guidance in the operation, management, usage and maintenance of IT infrastructure implemented across Government Ministries, Department and
Agencies including local Governments to ensure availability and integrity of the infrastructure.
The NITA-U within its mandate shall continue to provide technical guidance in line with the operation, management and usage of all Government IT systems for efficient delivery of IT services across Government MDAs/LGs and local Governments.
EXECUTIVE DIRECTOR
TABLE OF CONTENTS
1. INTRODUCTION
1.1 Objectives of the Standards
1.1.1 Specific Objectives
1.2 Applicability
2. OPERATION OF IT EQUIPMENT
2.1 Guidelines for operating IT equipment
2.2 User Responsibilities
2.3 Information/Data Security
2.4 Information Backup Guidelines
2.5 IT equipment Electrical safety
3. MANAGEMENT AND USAGE OF IT INFRASTRUCTURE
3.1 Application for Admission to use the IT Infrastructure
3.2 Admission to use the IT Infrastructure
3.3 Rejection/Withdrawal of Admission to use the IT infrastructure
3.4 Guidelines for Usage of IT Infrastructure
3.5 Exclusion from Use of the IT Infrastructure
3.6 Responsibilities of the IT Personnel
3.7 User liability
3.7.1 Sustainable Use of IT Equipment
3.8 Password Management
3.8.1 Poor and weak passwords characteristics
3.8.2 Strong passwords features
4. WEBSITE MANAGEMENT AND UASGE
4.1 Posting Information on MDA Websites
4.2 Information Request and Feedback
4.3 Legislative and Sector Information
4.3 On-line/Electronic Forms
4.4 Information not permitted on MDAs/LGs Websites
4.5 Quality and Management of Web Content
4.6 Online Viewers/Consumer feedback
4.7 Decommissioning MDA/LG Websites
4.8 Security and Privacy of MDA/LGs Website
4.9 Web Access Platforms
4.10 Documentation
5. INFORMATION TECHNOLOGY EQUIPMENT ROOMS
5.1 IT Equipment Rooms and Facilities
5.2 Selection and Design of IT equipment rooms
5.3 Requirement for IT equipment rooms
5.3.1 Security Requirement for IT equipment rooms
5.3.2 Fire Safety Requirement for IT equipment rooms
5.3.3 Power Safety Requirement for IT equipment
5.3.4 Cooling Requirement for IT equipment
5.3.5 Construction of IT equipment Rooms
5.3.6 IT equipment Safety Requirement
5.4 Cabling Infrastructure Security
5.5 Management Information and Audits
5.6 Security Requirement for IT equipment and Information
6. IT EQUIPMENT AND SOFTWARE MANAGEMENT GUIDELINES
6.1 Hardware Management guideline
6.1.1 IT equipment User Responsibility
6.2 Software Management and Usage Guidelines
6.2.1 MDAs/Local Government Responsibilities
6.2.2 IT hardware and Software Acquisition
6.2.3 Software Installation Guidelines
6.2.4 Storage of Software and Documentation
7. MAINTENANCE AND REPAIR OF IT EQUIPMENT
7.1 Preparation for Maintenance of IT equipment
7.2 When to carry out Maintenance ................................................................ Error! Bookmark not defined.
7.2.1 Preventative Maintenance
7.2.2 Corrective Maintenance
7.3 Software Upgrade Guidelines
7.5 Maintenance of IT Equipment
7.6 General Guidelines for Maintenance of IT equipment
8. HUMAN CAPACITY DEVELOPMENT
8.1 End User Skills Development
REFERENCES
List of Acronyms
ER : Equipment Room
ICT : Information and Communications Technology
IT : Information Technology
LG : Local Government
MDA : Ministries, Department and Agencies
NITA-U: National Information Technology Authority-Uganda
PCs : Personal Computers
PDAs : Personal Digital Assistants
PDF : Portable Document Format
PPDA : Public Procurement and Disposal of Public Asset Authority
TR : Telecommunications Room
SLA : Service Level Agreement
SPAM : Self-Propelled Automatic Mail
TO : Telecommunications Outlet
UNBS: Uganda National Bureau of Standards
UPS : Uninterrupted Power Supply
List of figures
Figure 1: Schematic Diagram for the different types of Rooms
Figure 2: Flow Chart showing Corrective Maintenance
List of Tables
Table 1: Elements of Preventive Maintenance
Table 2: Steps to develop effective Preventive Maintenance Program
Table 3: Categories of Corrective maintenance
1. INTRODUCTION
This document is developed to guide government Ministries, Departments, Agencies
(MDAs/LGs)/Local Government in adoption of common standards in order to promote good practices in the Government-wide use of Information Technology (IT).
This document presumes the reader has some familiarity with basic IT and Internet terminology, development and design. It summarizes key aspects of IT issues and is intended to act as a ready reference guide.
This document has four (5) main sections:
1. Operation of IT equipment
2. Management and Usage of IT Infrastructure
3. IT Equipment and Software Management Guidelines
4. Maintenance and Repair of IT equipment
5. Human Capacity development
The use of these guidelines shall help to ensure that the use of IT infrastructure across government in the delivery of IT services is done to a consistently high standard. This shall lead to increased confidence and rapid uptake in the use of IT and the Internet within Government as well as increased customer satisfaction in government services delivery.
As stipulated in the NITA-U Act 2009; Objects of Authority; Section 4(b); one of the core objective of NITA-U is “To promote standardization in the planning, acquisition, implementation, delivery, support and maintenance of information technology equipment and services, to ensure uniformity in quality, adequacy and reliability of information technology usage throughout Uganda”
1.1 Objectives of the Standards
The main objective of these Standards is to provide best practice guidelines for use in the operation, usage, management, maintenance and repair of IT equipment in MDAs/LGs.
1.1.1 Specific Objectives
The specific Objectives shall be:
1. To facilitate proper usage and operation of IT equipment to extend their useful life
2. To enhance capacity to support and maintain IT equipment in MDAs/LGs and Local
Governments
3. To provide efficient and cost effective means of implementing and managing IT equipment in MDAs/LGs
4. To ensure that IT equipment are securely managed in the Government MDAs/LGs and local Government
1.2 Applicability
These set of guidelines shall be applicable to Government MDAs and Local Governments and may in addition be useful to Institutions outside Government settings such as the private sector organization Academia etc. The guidelines stipulated in this document provides best practices for appropriate management, operation, usage and maintenance of IT infrastructure by IT personnel, end-users and Administrators in those Institutions. It is intended to be applied along-side other established IT Policies within the respective MDAs.
2. OPERATION OF IT EQUIPMENT
It is important that MDAs/LGs observe these guidelines for operating IT equipment to ensure maximum utilization in a manageable and sustainable manner. Improper handling and operation of equipment leads to failure before their end of life.
2.1 Guidelines for operating IT equipment
1. The IT Units within the respective MDAs/LGs shall ensure that configurations of the components of the network or system shall be documented for the purpose of maintenance and future planning.
2. Only staffs within the respective MDAs/LGs are authorized to use IT equipment and software resources. Any other person will be required to seek approval from IT Unit for use of IT equipment and resources.
3. MDA should encourage staff to be considerate in their use of shared resources. Refrain from monopolizing systems, overloading networks with excessive data, degrading services, or wasting computer time, connection time, disk space, printer paper, manuals, or other resources.
4. All MDAs/LGs shall ensure that there is sufficient warranty on all IT equipment and software in use
5. The IT Unit in each MDA shall ensure that entry to the Server Room shall remain restricted to IT Unit staff.
6. All Data pertaining to the MDA shall be stored on appropriate Backup Media
2.2 User Responsibilities
In making acceptable use of IT resources users must:
1. Use IT resources only for authorized purposes
2. Scan any external disk (CD, flash disk, hard disk etc.) with Antivirus before using the same on the network/desktop; this will minimize the risk of virus infection.
3. New users should obtain official e-mail addresses from the IT Unit/department
4. Use only legal versions of copyrighted software in compliance with vendor license requirements.
5. Print only what should be printed noting that Information can still be useful in electronic form.
6. Shred any printed sheets before throwing them into the bins. No sheets bearing MDAs/LGs data should be discarded without being destroyed.
7. Ensure that requisite approval is sought before Diskettes/ flash disks containing
MDAs/LGs data are released to any other external party.
In making acceptable use and operation of IT resources users MUST NOT:
1. Use computer programs to decode passwords or access control information.
2. Attempt to circumvent or subvert system or network security measures
3. Use another person's system, files, or data without permission (note that permission from an individual user may not be sufficient - some systems may require additional authority).
4. Give passwords to others, without due consideration. It is necessary to contact IT Unit if one needs access to information, which they are not automatically authorized to access
5. Engage in any activity that might be purposefully harmful to systems or to any information stored thereon, such as creating or propagating viruses, worms, or "Trojan horse" programs; disrupting services; damaging files; or making unauthorized modifications to corporate data.
6. Waste shared computing or network resources, for example, by printing excessive amounts of paper, or by sending chain letters or unsolicited mass mailings
2.3 Information/Data Security
Due to the importance of data in any given enterprise, the IT Unit shall take regular backups and any other security measures to ensure that the MDAs/LGs data is safe and can be relied upon in the event of online data loss.
The following security measures shall be taken to safeguard MDAs/LGs data: -
1. The IT Unit will keep proper backup of all data in the MDAs/LGs.
2. The data backup will be on daily basis and retained for a period approved by Management.
All backups shall be securely kept and protected from any damage or data loss
3. Due to the frequent change in technology, the backup media shall be revised consistently to ensure that all the backups are accessible and can be redeployed when needed.
4. The Backup Media shall be kept in the designated secure and safe place appropriately.
5. The backups of computer systems shall be kept in safe internal and external areas to eliminate any chances of damage in the event of disaster.
6. Backup procedures shall be revised from time to time to ensure compliance with the current security trends
2.4 Information Backup Guidelines
The following shall be considered in backing up of MDAs/LGs Information:
1. MDAs/LGs shall ensure accurate and full records of the back-up copies and documented procedures for restoration should be developed;
2. Backup shall be done on a daily basis, for system states and data on all the servers.
3. Back-ups shall be stored in a remote location, at a sufficient distance to escape any damage from a disaster such as fires, floods or earthquakes from the main site;
4. MDAs/LGs shall ensure that back-up media are regularly tested to ensure that they can be relied upon for emergency use when necessary;
5. MDAs/LGs shall ensure that backup is protected by appropriate procedures such as encryption.
2.5 IT equipment Electrical safety
1. All electrical equipment should be maintained regularly. Always leave technical repairs to the experts.
2. Ensure that to have the necessary fire extinguishers positioned near any IT equipment room.
3. The location of IT equipment depends on the length of cables and the availability of sockets for telephones, data and power. It is essential that the location of the equipment does not increase the risk of danger to equipment or users.
4. Particular issues to be aware of are as follows:
(a) Cover and secure trailing power cables.
(b) Replace worn out leads or damaged plugs.
(c) Do not overload circuits, particularly when using long extension leads, as power surging can occur if much IT equipment is connected to a circuit, or when electrical floor cleaning equipment is plugged in.
(d) Avoid coiled cables, as the heat generated within them could be sufficient to start a fire.
(e) Be aware of accidental damage, particularly any cuts to power cable insulation, and also damage from dust, spilt liquid.
(f) Ensure that the correct fuse rating is fitted to the IT equipment
5. IT personnel shall ensure that connecting cables (to keyboards, mouse etc.) do not hang over the front of the computer workstation.
6. Trailing loops of cable at the rear of machines should be tidied to allow easy access to equipment for maintenance and to prevent equipment from being dragged accidentally from the workstation.
7. It is important to ensure that procedures are put in place for regular visual checks of plugs, leads & other electrical equipment for safety etc.
3. MANAGEMENT AND USAGE OF IT INFRASTRUCTURE
This section provides the fundamental set of principles for the proper usage of the IT
Infrastructure installed in the different MDAs/LGs.
The guidelines laid down below governs the terms and conditions for the use of the services that are offered within the IT infrastructure installed within the MDAs as well as the respective Local
Government headquarters.
It obliges the user to act in an appropriate manner and to use the provided IT resources in an economical way as well as to operate the system correctly.
3.1 Application for Admission to use the IT Infrastructure
The application for admission to use the IT infrastructure in the different MDAs/LGs shall contain the following information:
1. The Particulars of the Designated IT personnel who receives the application for admission;
2. The IT infrastructure/system (s) for which admission is requested;
3. Description of the intended use of the IT equipment and/or the planned activities(e.g.
research, teaching, storage and issue of information, administration and work related);
4. Statement of acceptance made by the applicant that he or she accepts the policy of use of the IT equipment and other related resources.
5. Warning that the applicant’s user activities may be recorded on the basis of the Policy in use.
3.2 Admission to use the IT Infrastructure
It is important for IT personnel in the respective MDAs/LGs to ensure that mechanisms (such as procedures to use and IT equipment) are put in place to allow staff use IT equipment.
1. To use the IT resources installed within the MDAs/LGs; the user must have a formal authorization issued by the responsible Network or System Administrator or any other designated IT personnel (e.g. a user ID, network connection or network access authorized by the Network/System Administrator)
2. The use of computerized services (e.g. details of e-mail addresses, internet access, extensive computing time or storage capacity, use of computer tools) are governed by the policy of use issued by each respective MDAs/LGs.
3. Computers and other related IT equipment that are operated by non-members of staff within the respective MDAs/LGs may not be connected to the network unless this has been authorized on the basis of special provisions and in cooperation with the Network
Administrator.
3.3 Rejection/Withdrawal of Admission to use the IT infrastructure
Admission to use of IT equipment and resources may be rejected, withdrawn or limited in part or as a whole, in particular when:
1. No acceptable application has been submitted or when the information given in the application is incorrect or obsolete;
2. The applicant’s intended activities are incompatible with the tasks for which the IT equipment or system has been installed to accomplish;
3. The current levels of use of IT equipment or resources exceed the capacities required for the intended use;
4. The purpose of use of the IT infrastructure will potentially impair the functionality of authorized IT systems in an unacceptable way;
3.4 Guidelines for Usage of IT Infrastructure
Upon admission to use the IT Infrastructure in the respective MDAs/LGs; staff shall be required to observe the following guidelines;
1. The users are entitled to use the IT Infrastructure as approved and as permitted by the policy in their respective MDAs/LGs. Any usage other than permitted by these regulations and policies requires special approval;
2. The users must comply with the provisions of these guidelines and act within the boundaries of their admission and observe the following:
(a) Users are required to refrain from all activities that will disrupt proper operation of the
IT Infrastructure in the respective MDAs/LGs
(b) They are required to handle all data processing systems, information and communication systems, as well as other resources of the IT Infrastructure with due care; to use only the IT equipment accorded to them as permitted.
(c) To take due care that their user passwords and user IDs are not made known to others and to make sure that these IT equipment are not accessed by unauthorized individuals; this includes the protection of the access with a strong password (difficult to guess) that must be kept confidential and should be changed on a regular basis;
(d) Not to gain knowledge of or make use of other individual‘s user IDs/passwords;
(e) Not to access information, and in particular, not to access other individual’s messages/information (E-mails etc.) without their authorization and not to pass on, use or modify any information gained without their approval;
(f) When using software (sources, objects), documentation material and other data, the user must adhere to the legal provisions (e.g. copyrights) and must comply with the contractual provisions (e.g. license agreements) under which the software was purchased.
(g) MDAs/LGs shall ensure that software are not copied and passed to third parties or to use them for purposes other than those permitted explicit permission has been granted by the relevant authorities.
(h) Not to correct, mend or rectify problems, damage and errors on any IT Infrastructure or resources and data media but to immediately report them to the responsible
Network/System Administrator or any other designated IT Personnel within the respective MDAs/LGs;
(i) Not to make changes to hardware installations and/or to the configuration of the operating systems, system files, and user files that are required by the system, and to the network, unless explicit approval has been obtained;
3.5 Exclusion from Use of the IT Infrastructure
Exclusion of MDAs/LGs staff from the use of IT Infrastructure shall be on the following grounds:
1. Users may temporarily or permanently be limited in or excluded from the use of the IT Infrastructure or resources;
(a) If they intentionally or negligently violate these guidelines and, in particular carrying out abusive actions (such as illegal and other acts motivated by racism, racial discrimination and related intolerance, hatred, violence, all forms of child abuse, including child pornography, and trafficking, and exploitation) on the IT Systems.
(b) When they abuse the use of IT Infrastructure and resources for illegal/criminal acts such as fraud and authorized use interception of data or information traversing the network etc.
(c) When they cause harm to the Government MDAs/LGs by unlawful user behavior
2. Temporary usage restrictions that will be implemented by the responsible
Network/System Administrator have to be lifted as soon as compliant use can be expected.
3. A permanent restriction or revocation of user rights is only possible in cases of severe and repeated violations and when compliance cannot be expected in the future, although actions have already been taken. The decision to permanently remove the privileges to use an IT Infrastructure system shall be made by Administrative notice upon application by the Network/system Administrator.
3.6 Responsibilities of the IT Personnel
The following shall be the responsibilities of IT Personnel across all MDAs/LGs:
1. Each designated IT personnel in the respective Government MDA/LGs shall inform users on the usage, important facts and the relevant rules and regulations to be complied with, and in particular, on their privileges and responsibilities.
2. IT personnel within the MDAs/LGs shall maintain a user file containing the personal data of the users. A summary of the type of data stored must be accessible to each user at any time.
3. IT personnel shall limit or block the use of IT Infrastructure or resources for purposes of troubleshooting, system administration and system extension, system security implementation as well as for maintenance. All the affected users have to be informed ahead of time.
4. IT personnel shall protect IT infrastructure and user data from unauthorized access by third parties. IT personnel may apply manual or automated check procedures on a regular basis to control the security of the systems.
5. IT personnel shall ensure that user passwords are changed on a regular basis. Changes made on user passwords, access privileges to user files and other user-relevant protective measures have to be communicated to the users appropriately.
6. IT personnel shall periodically document and evaluate how individual users use the IT infrastructure for the following reasons:
(a) To ensure correct operation of the IT Infrastructure and systems put in place.
(b) To plan resources and to administer the system.
(c) To determine the user patterns of the installed IT infrastructure
(d) To protect the personal data of other users
(e) For billing purposes
(f) To identify and correct system malfunction;
(g) To detect and prevent abusive, or unlawful use
7. IT personnel shall access user files deemed to be the source of malicious attack or abuse of MDAs/LGs computer system. This access shall be implemented in the presence of an administrator/staff authorized by the accounting officer and the process documented.
The affected user has to be notified immediately when the purpose for access of his/her user files have been attained. If the investigation provides evidence for punishable offences/criminal act, the IT personnel shall report the incident to the Accounting Officer in those particular MDAs/LGs.
8. IT personnel shall ensure that staffs do not store contents on computer systems that violate the MDAs/LGs IT Policy or the provisions contained in this guidelines. Ensure to put in place measures to block and seize such illegal content.
9. To ensure proper operation of the IT system, each IT personnel is required to check the e-mail traffic for malicious programs (e.g. virus, unsolicited bulk e-mail or SPAM) using automated procedure. If the investigation provides actual evidence that an e-mail contains a malicious program it must be automatically deleted;
10. IT personnel shall not communicate personal data or operating data, connection data and user data that enable the identification of individuals to third parties
3.7 User liability
Users of the all installed IT infrastructure shall be liable in case of the following:
1. Users shall be held liable for all hindrances incurred to the MDAs/LGs as a result of wrongful or illegal use of the IT Infrastructure, resources, user admission or that which arises as a result of the user’s intentional or negligent violation of these guidelines.
2. The user shall also be held liable for damages caused by third parties, if the user is accountable for third parties using his or her access and user privileges; this applies in particular to third parties using his or her user ID.
3. MDAs/LGs may claim compensation for the wrongful use of IT resources and other costs which have to be borne by the user such as damage caused on an IT asset.
3.7.1 Sustainable Use of IT Equipment
The following sustainable use of IT infrastructure shall be adhered to by all MDAs/LGs
1. MDAs/LGs shall ensure that users are trained to turn on and off any IT equipment for use and after use. Note that leaving non-critical computers powered on when not in use consumes powers.
2. A screen saver message reminding staff to turn IT equipment off when not in use should be implemented
3. MDAs/LGs shall ensure that staffs are trained to turn off monitors, printers, scanners and other IT equipment at night or after office hours.
4. Encourage the use of conferencing technologies (audio and video) for staff training and meetings, to reduce the need for travel
5. MDAs/LGs shall ensure centralized multi-function networked printing and scanning devices, deployed based on a workflow requirement are installed. Avoid proliferation of desktop peripherals such as printers, scanners and fax machines.
3.8 Password Management
Passwords are front line protection for user accounts and are important aspect of computer security. A poorly chosen password may result in the compromise of the MDAs/LGs entire network. All staffs are responsible for taking the appropriate steps, as outlined below, to select and secure their passwords.
The purposes of these guidelines are to establish a standard for creation of strong passwords, the protection of those passwords, and the frequency of change. All system users must observe the following password guidelines:
1. All system-level passwords (e.g. root, Administrator, admin, application administration accounts, etc.) must be changed regularly or whenever need arises.
2. All user-level passwords (e.g., email, web, desktop computer, etc.) must be changed at least every after (one) months.
3. User accounts that have system-level privileges granted through group memberships such as financial systems must have a unique password from all other accounts held by that user.
4. Passwords must not be inserted into email messages or other forms of electronic communication.
5. Passwords should not be written in note books for reference.
6. Password should not be shared
7. Report to the IT unit if you have forgotten your password
Some of the more common uses of passwords include: user level accounts, web accounts, email accounts, screen saver protection, voicemail password, and local router logins.
3.8.1 Poor and weak passwords characteristics
The following are some of the characteristics of weak passwords which the IT personnel in MDAs/LGs should encourage their staff to avoid:
1. The password contains less than eight characters
2. The password is a word found in a dictionary (English or foreign)
3. The password is a common usage word such as:
(a) Names of family, pets, friends, co-workers etc.
(b) Computer terms and names, commands, sites, companies, hardware, software.
(c) Birthdays and other personal information such as addresses and phone numbers.
(d) Word or number patterns like aaabbb, 12345, etc.
3.8.2 Strong passwords features
IT personnel shall encourage the use of strong passwords with the following characteristics:
(a) Use both upper and lower case characters (e.g., a-z, A-Z)
(b) Have digits and punctuation characters as well as letters e.g., 0-9,
(c) !@#$%^&*()_+|~-=\`{}[]:";'<>?,./)
(d) At least eight alphanumeric characters long
(e) Words not in any language, slang, dialect, jargon, etc.
(f) Avoid personal information, names of family, your car name etc.
(g) Passwords should never be written down or stored on-line. Try to create passwords that can be easily remembered.
4. WEBSITE MANAGEMENT AND UASGE
The Internet is becoming a preferred means of accessing government information and services.
Therefore, a crucial element of an effective web presence is quality and relevance of information posted on Government websites.
Government MDAs/LGs shall develop websites that contain informative and up-to-date content that is well-written, caters for the needs of a wide range of audiences and is easily accessible.
MDAs/LGs must therefore ensure that:
1. Information provided on website meets the needs of consumers
2. Information provided is current
3. There is a consistent approach across websites
4. At least a minimum set of information is provided
Information presented on a government website must be consistent with government policies to avoid the possibility of damage to both the government and consumers if information is incorrect or inappropriate.
4.1 Posting Information on MDA Websites
It is recommended that government MDAs/LGs include publications that are available to the public through other forms of media (such as hardcopy or audio) on their websites. The same shall be captured linked in the online library. Where this is not practicable due to, for instance, high costs, limited benefits, low demand, publication complexity information on how to obtain a copy in its original form should be posted on the website. Any decision not to publish in electronic form rests with the Accounting Officer.
4.2 Information Request and Feedback
MDAs/LGs are required to provide full contact details, including physical service locations, fax and telephone numbers, and mailing addresses. Email addresses shall also be provided, in particular, for the entity responsible for maintaining the website for the purpose of reporting fault. A general enquiry email address for the MDAs/LGs shall be established so as to protect the individual name and person, which consumers can contact in relation to the MDA/LGs service offerings.
4.3 Legislative and Sector Information
Policy documents, legislative and sectoral information related to the MDAs/LGs shall be provided on their website. This information shall not be duplicated on any other MDAs/LGs websites, instead links shall be provided to relevant resources at the various source websites.
These include, but not limited to:
(a) The Constitution of Uganda
(b) Legislation and legislative status information
(c) Bills and Acts
(d) Sectoral policy documents
(e) Circulars, Policy Documents, Publications and Reports among others.
4.3 On-line/Electronic Forms
There are several types of forms that can be used to present and collect information from users;
Interactive forms, e-forms and downloadable forms.
1. MDAs/LGs shall ensure that for interactive forms, appropriate security precautions shall be put in place to safeguard user information during transmission and storage.
MDAs/LGs shall also ensure that user input errors are minimized by helping users identify, avoid and correct mistakes.
2. MDAs/LGs shall ensure that e-forms and downloadable forms are in compatible formats and where special software is required, a link to download it must be provided. For these types of forms, pdf format is recommended.
3. Government MDAs/LGs shall continuously endeavor to provide online interactive forms, and where not possible, a downloadable format shall be made available.
4.4 Information not permitted on MDAs/LGs Websites
The following guidelines shall be provided:
1. Government websites shall not post information that does not promote the MDAs/LGs
Government policy. In addition, the following content shall not be permitted:
(a) Commercial banner advertisements
(b) Personal information
(c) Politically partisan content
2. Government websites can however acknowledge sponsors and partners at a section on their website but this decision rests with the appropriate senior executive within the
MDAs/LGs, provided it is consistent with government policy.
3. Banners that promote and link to other government MDAs/LGs are permissible, provided that no fees are charged in placing such banners.
4.5 Quality and Management of Web Content
The recommended best practice to ensure quality of content provided on the MDAs/LGs websites are as follows:
1. MDAs/LGs shall ensure that the content created for the website is of high quality, accurate, current and meets the needs of the users and the requirements of the government.
2. MDAs/LGs shall continuously endeavor to create web content that reflect relevancy and currency. Presentation of content shall seek to limit each page to one concept as well as provide information suitable for the web.
3. MDAs/LGs shall ensure that delivering information and services on the Internet is managed with the same level of quality and commitment as that employed when delivering information and services using conventional methods.
MDAs/LGs shall ensure that web content have the following characteristics:
1. Adaptability: Create content that can be presented in different ways without losing information or structure
2. Presentability: Consider the characteristics of created documents and how to best present them. Downloadable versions are recommended for lengthy documents. For PDF files, provide a link to the latest Document Reader.
3. Functionality: Web components shall work correctly and quickly
4. Authenticity: Each document included shall contain the following, but not limited to:
(a) Status of the document, where applicable
(b) Author and date
(c) Version and location of the original publication
(d) Contact details and feedback mechanisms
5. Usability: Website shall be simple and well organized
6. Relevancy: Web content shall be meaningful to the target audiences
7. Distinguishability: Make content easier for users to see and hear including separating foreground from background
8. Operability: All functionality of the content should be operable through a key board interface without requiring further user intervention
9. Readability: Make content readable and understandable
10. Well-written: good grammar and spelling
11. Appearance: shall be appealing to the target audiences
12. Timely: Up to date content
13. Compatibility: Content shall be accessible through the various media, end user devices and across different browser platforms
14. Robustness: Content must be robust enough that it can be interpreted reliably by a wide variety of user agents, including assistive technologies.
4.6 Online Viewers/Consumer feedback
MDAs/LGs shall use consumer feedback as a primary indicator of the success of the website.
Consumer feedback can help in determining website relevance, usefulness, currency of information and quality. All problems and consumer queries shall be attended to in a timely and professional manner. IT Officers shall be assigned to:
1. Review reported compliments, comments, problems and queries
2. Forward comments, problems and queries to the appropriate office in the MDA/LGs for action
3. Monitor timeliness of corrective action to be undertaken.
4. Respond to the consumer within defined timeframes
4.7 Decommissioning MDA/LG Websites
Government MDAs/LGs shall ensure that websites are regularly reviewed to ensure that they are relevant and up-to-date. An MDA/LGs website shall be retired on the following grounds:
1. When it has been rendered irrelevant due to re-organization of Government MDAs/LGs structures
2. When it does not serve a specific function or purpose of the Government MDA/LGs
3. When it was developed for a particular project or strategy that is no longer relevant or current
4. When it was launched as part of a government-sponsored campaign that has since come to an end
5. Is non-essential and website traffic statistics, where available, shows that the website is not being utilized.
When decommissioning websites, consideration shall be given to archiving the content as appropriate.
4.8 Security and Privacy of MDA/LGs Website
In ensuring MDA/LGs Website security and privacy the following shall be considered:
1. MDAs/LGs shall put in place measures or controls to protect web resources to assure the confidentiality, integrity and availability of information. MDAs/LGs shall ensure that information assets are safely and securely stored, processed, transmitted and destroyed.
2. MDAs/LGs shall develop website security plans and ensure that users are alerted of potential risks and how to avoid them when accessing the website.
3. MDAs/LGs shall ensure that information collected from users through electronic forms or e-mails are securely transmitted and stored by the taking appropriate measure such as data encryption.
4. Reasonable care shall be taken to protect personal information held by MDA/LGs from misuse, loss and unauthorized access, modification or disclosure. Where necessary, user registration for access and use of services such as access to government MDA/LGs databases shall be enforced.
5. MDA/LGs websites shall include a standard privacy policy statement that enumerates information collected about individuals when they visit the website, how it is used. It is important that MDA/LG complies with the undertakings and representations in its website privacy statement.
6. MDAs/LGs shall regularly conduct security threat and risk audits on their websites. They shall also create and regularly review a security plan that describes the necessary security mechanisms and procedures required to secure the website.
4.9 Web Access Platforms
The following shall be considered:
1. MDAs/LGs shall ensure that all websites developed are able to be displayed on all standard browsers. Web services shall be developed for delivery through various access devices mobile telephones, PDAs etc.
2. MDAs/LGs shall ensure that access platforms are adequately secured taking into consideration issues of authentication and repudiation.
4.10 Documentation
MDAs/LGs shall produce and maintain documentation of the development processes, administration and maintenance of the website including internet applications and databases for continuity.
5. INFORMATION TECHNOLOGY EQUIPMENT ROOMS
IT equipment shall be housed in secure IT rooms, protected by well-defined security boundaries, with appropriate security barriers and entry controls. They should be physically protected from unauthorized access, damage, and interference which should be in line with the identified risks.
The IT Unit/Department within the respective MDAs/LGs shall be responsible for managing data centers, training rooms, server rooms as well as monitor and review access mechanisms to all
IT facilities.
5.1 IT Equipment Rooms and Facilities
The schematic diagram below illustrates the various types of room and the connections between them. This diagram shows an ideal situation for large MDAs/LGs. For smaller institutions one IT room may often contain several functions but it is important to endeavor to create some redundancy for network availability as indicated in the diagram:
Figure 1 : Schematic Diagram for the different types of Rooms
5.2 Selection and Design of IT equipment rooms
IT facilities supporting critical or sensitive Government services shall be secured in suitable locations and rooms. The following considerations shall be made by MDAs/LGs and Local
Governments in the selection of suitable sites for the construction of IT equipment rooms:
1. MDAs/LGs shall take into account reasonable controls and measures to mitigate and guard against natural and man-made disasters including fire, flooding, explosion, vandalism and hazards related to electrical power.
2. Consideration shall be given to the following measures:
(a) Hazardous materials shall be stored safely at a safe distance from the site.
Combustible material such as stationary shall not be stored within the computer room until required.
(b) Fallback equipment and back-up media shall be sited at a safe distance to avoid damage from a disaster at the main site. In particular, Business Continuity Plans and associated equipment shall be stored in a location sufficiently separate to the main location.
(c) Appropriate safety equipment shall be installed in accordance with the
Occupational Safety and Health policies/laws in place.
(d) Environmental requirements of an equipment room shall be determined by
Manufacturer’s specification with due diligence and in consultation with certified professionals.
5.3 Requirement for IT equipment rooms
The requirement shall fall into the following categories:
5.3.1 Security Requirement for IT equipment rooms
The security mechanism to be deployed shall include and not limited to:
1. Access control by use of Bio-metric card logins and passes
2. Alarm systems to counter any unauthorized activity within the vicinity of the IT equipment rooms
3. Security Cameras to monitor activities around the IT equipment room or sites
4. Lockable doors and accessed achieved physical keys.
5. Intrusion detection systems installed to national, regional or international standards and regularly tested to cover all external doors and accessible windows
6. Ensure proper lighting systems are installed to provide clear visibility in and outside the IT equipment room.
5.3.2 Fire Safety Requirement for IT equipment rooms
The following shall be considered in guarding against fires in IT equipment rooms:
1. MDAs/LGs shall consider and ensure that fire and smoke detection systems and systems for detecting environment conditions as well as fire suppression systems are installed in the IT equipment rooms.
2. Fire safety equipment such as gas masks, fire extinguishers and water hydrant facilities shall be installed and located within the vicinity of the equipment room to counteract any fire out breaks.
5.3.3 Power Safety Requirement for IT equipment
The following shall be considered in the provision of power to the equipment.
1. MDAs/LGs shall ensure that the use of smooth energy sources to equipment is adhered too.
2. MDAs/LGs shall use surge protectors to protect equipment against power surges and dips
3. To ensure network availability MDAs/LGs shall ensure that alternative sources of energy exist and that appropriate backup power sources (solar, generators and backup batteries etc.) with appropriate ratings are installed to power up the IT equipment.
4. The supply of fuel to the generator shall be adequate to ensure that the generator can run for a prolonged period.
5. MDAs/LGs shall ensure that the backup power sources are regularly tested, and any necessary requirements included as part of any contingency planning processes.
6. MDAs/LGs shall ensure that proper Uninterrupted Power Supplies (UPS) with appropriate ratings are installed to protect the equipment from power surges
7. Emergency power off switches should be located near emergency exits in equipment rooms to facilitate rapid power down in case of an emergency. Emergency lighting should be provided in case of main power failure.
5.3.4 Cooling Requirement for IT equipment
The following guidelines shall be considered and implemented:
1. MDAs/LGs shall ensure that proper air conditioners/cooling systems with appropriate ratings commensurate with the equipment in place and the size of the equipment room are installed to provide suitable cooling in line with the manufacture requirement or specifications for the equipment.
2. It is important to ensure that the cooling systems are regularly checked for any fault or to fill-up the gas cylinders to provide sufficient cooling.
5.3.5 Construction of IT equipment Rooms
The following consideration shall be made in the construction of IT rooms:
1. MDAs/LGs shall ensure that security barriers such as walls, card controlled entry gates or manned reception desks) are constructed to protect areas that contain information and information processing facilities (IT equipment).
2. The perimeters of a building or site containing information processing facilities should be physically sound (i.e. there should be no gaps in the perimeter or areas where a break-in could easily occur).
3. The external walls of the IT room shall be of solid construction and all external doors shall be suitably protected against unauthorized access with control mechanisms, e.g. bars, alarms, locks etc. doors and windows should be locked when unattended.
4. Emergency evacuation procedures shall be developed with due consideration of the security of the IT resources.
5. MDAs/LGs shall make separate considerations for storage rooms for the spare equipment/equipment destined for disposal. MDAs/LGs shall ensure that IT equipment rooms are not used for storage of any kind.
6. Ensure that the IT equipment room is not constructed in or near flood prone areas such as in or near wetlands, swamps and water catchment areas etc.
7. Where the proposed site/location for the IT equipment room is on the first floor or floors above the ground floor the maximum floor load shall be considered commensurate with the total weight of all the IT equipment scheduled to be installed.
8. Ensure that the equipment racks are firmly fixed to the floor of the equipment room to with stand vibration caused by earth quakes or any heavy activity within the vicinity of the equipment room.
5.3.6 IT equipment Safety Requirement
MDAs/LGs shall ensure that all IT equipment is protected from physical and environmental threats. Appropriate measure shall be put in place to protect equipment against physical threats and environmental hazards. The following considerations shall be made in ensuring the safety of
IT equipment:
1. IT equipment containing sensitive data should be positioned in restricted areas to reduce the risk of information being accessed and viewed by unauthorized persons during their use and storage.
2. IT equipment demanding special protection should be isolated/secluded and securely protected against any potential unauthorized access.
3. Controls should be adopted to minimize the risk of potential physical threats, e.g. theft, fire, explosives, smoke, water (or water supply failure), dust, vibration, chemical effects, electrical supply interference, communications interference, electromagnetic radiation, and vandalism among others.
5.4 Cabling Infrastructure Security
MDAs/LGs shall ensure that power or cables carrying data or supporting IT technology services shall be adequately protected from interception or damage. The following guidelines shall be considered in the implementation of cabling security:
1. Power cables should be segregated from cables carrying IT services or data to prevent interference
2. Network cables or cables carrying IT Services shall be clearly identified and marked to minimize errors during handling and patching
3. IT units shall ensure that the patch cables used to connect equipment/carrying specific IT service are well documented for ease of reference during maintenance.
4. IT Units shall ensure that cables are installed in armored conduits especially for critical IT services and systems.
5. MDAs/LGs shall ensure that the inspection and termination boxes for all cabling system are securely locked.
6. Ensure controlled access to all installed patch panels, power or data cables rooms.
5.5 Management Information and Audits
1. IT Units within the respective MDAs/LGs shall monitor all aspects of connections over the network. The use of network monitoring tools shall be employed to automate the auditing tasks needed and complement manual auditing. Auditing shall include the following:
(a) Authentication database showing the specific login entries;
(b) All entity router/network device configurations;
(c) Client equipment where tampering may be reasonably suspected;
(d) Bandwidth management;
(e) Monitoring of access points;
(f) Monitoring unauthorized use of network and network facilities.
2. The IT Units shall immediately investigate and document any unauthorized changes whenever detected.
3. All MDAs/LGs connections shall be reviewed on regular basis, by mutual agreement. The
IT units shall come up with and document routine maintenance processes. The unit shall come up with SLA for maintenance of network resources with external service provider and ensure that they are adhered to.
5.6 Security Requirement for IT equipment and Information
Detailed requirement for Information and equipment security shall be adhered to as provided in the in the International Standards; ISO/IEC 27002: Information technology — Security techniques —
Code of Practice for information security management. The International standard has been adopted as National
IT Standards through Uganda National Bureau of Standards.
MDAs/LGs shall make reference and adhere to the above international standards which provide best practice guidelines for Information Security management of IT…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .