DICT, CICC adopt green-amber-red framework for government cyber readiness
- CICC, Cybersecurity, DICT
The Department of Information and Communications Technology (DICT) and the Cybercrime Investigation and Coordinating Center (CICC) have adopted a green-amber-red framework to assess the cybersecurity readiness of government agencies amid heightened vigilance across the public sector.
In a joint statement issued on Wednesday, Sept. 9, the agencies said the framework forms part of measures under a Joint Cybersecurity Advisory covering national government agencies, government-owned and controlled corporations, local government units, and operators of critical information infrastructure.
Under the framework, green means an organization requires continued vigilance and does not mean that it has zero cybersecurity risk.
An amber status indicates conditions that require remediation and monitoring, while red means immediate reporting and response are required.
The DICT and CICC said covered organizations have been directed to undertake prescribed cybersecurity measures within 24 hours of receiving the advisory.
Each organization must also provide its agency head or chief executive with a one-page cyber readiness assessment identifying its most serious risks, immediate actions taken, and assistance required.
Priority measures include addressing critical vulnerabilities, enforcing multi-factor authentication for critical and privileged accounts, removing unnecessary internet exposure, strengthening security monitoring, verifying backup recoverability, reviewing third-party access, and validating incident-response and service-continuity procedures.
The agencies stressed that the 24-hour requirement is a deadline for urgent action and assessment, rather than an assurance that every cybersecurity risk has already been eliminated.
βSuspected serious incidents must be escalated immediately. Agencies must not wait for the completion of the 24-hour assessment before reporting a potential compromise.β the joint statement read.
The DICT and CICC said assessments should accurately identify weaknesses, actions taken, and unresolved concerns requiring assistance, with the exercise expected to result in protective action rather than merely another compliance report.
Agency heads and chief executives were also directed to lead implementation, as employee awareness alone cannot substitute for proper system maintenance, effective security controls, and leadership accountability.
The agencies said they would coordinate with affected government offices to provide verified public updates on incidents affecting government services, distinguishing confirmed findings from preliminary assessments and explaining available service alternatives when necessary.
DICT, through its Cybersecurity Bureau and National Computer Emergency Response Team, together with CICC and other cybersecurity and law enforcement partners, will continue monitoring threats and coordinating defensive measures across government and critical infrastructure.
