National standard for information security by next year: Rais
The government is expected to put in place a Malaysian Standard (MS) for information security which will cater for organisations by early next year, said Minister in the Prime Minister's Department Dr Rais Yatim today.
Under the initiative, organisations can volunteer to have their information systems audited and awarded with the MS certification that will be in line with the Communications and Multimedia Act (CMC) 1998 on self-regulation.
According to Rais, the national standard is expected to become a component of the National Security Framework for Information Security, which is currently being formulated by the government.
"The framework is aimed at raising awareness on risk and to safeguard and foster confidence in information systems and promote the development and use of innovative communication systems," he said.
Rais, said this in his opening speech at the 2001 Emergency Response Planning Conference at the Senior Police Officers' Training College in Kuala Lumpur today.
'New risks'
In his speech, the minister also voiced his concern about the emergence of the new security risks in the advent of the electronic era.
According to him, "career criminals" who are involved in organised crime are now eyeing e-commerce, but the more terrifying prospect is that terrorists might target critical infrastructures such as the telephone system, the power grid or the air traffic control system through online manipulation.
"These systems run on computers and are vulnerable to cyber attacks," he said.
Rais said that since both the public and private sectors are increasingly dependent on information technology to transact information, there is an even greater vulnerability of any organisation to face e-fraud threat despite the comprehensive e-policy and hacker-proof security system that are in place.
"I wish to emphasise that weaknesses would tempt those with criminal intent to cripple the whole government machinery and thus undermine the security of the country," he said, adding that there is a dire need to raise everyone's level of preparedness to respond to such disaster.
Rais explained that with the emergence of the new security threat, the Malaysian government had taken several proactive steps.
Among others, the government has taken the measures to improve communications between their information security team with security groups from the private sectors, he said.
"This will allow effective discussions and knowledge sharing which could eventually pave the way for the implementation of information security guidelines for the whole country," Rais added.
Among the most commonly detected online abuses in Malaysia are incidents of unauthorised access, web defacements and the sending of viruses and and malicious codes.

