My bookmarksSign up free

RA 12254 CHAPTER VI

Section 23–25 · 3 provisions

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails.Read the official text ↗

Data and Information Security.

Section 23

SEC. 23. Data and Information Security. - All resources, information, or data stored in or transmitted through the government information systems and all networks interconnected to and interoperable with it, the portals, and websites shall be kept secure and free from interference or unauthorized access that can hamper or otherwise compromise the confidentiality, integrity, and availability of the ICT assets. Access to and use of the resources, information, and data in the government information systems shall be limited to the government and its duly authorized officers and agents, in accordance with all relevant laws, rules, and regulations on data and information privacy and the pertinent rules on confidentiality of government information: Provided, That the data used by all concerned government agencies, office, and instrumentalities with access to information systems and used data stored therein shall be destroyed or disposed of in accordance with acceptable standards and guidelines existing under the law for disposal of data upon fulfillment of its purposes. Any person who shall knowingly commit an act which results to the compromise of the security and integrity of the government information systems and all networks interconnected to and interoperate with it, to the detriment of the government and the public shall incur criminal liability in accordance with the provisions of applicable and relevant penal laws.

Responsibility of the National and Local Governments.

Section 24

SEC. 24. Responsibility of the National and Local Governments. - All agencies, offices, and instrumentalities of the national and local governments, including SUCs and GOCCs, shall be responsible for: (a) Providing information security protections commensurate with the risk and magnitude of the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of information collected or maintained by or on behalf of the agency; and information systems used or operated by an agency, its contractor, or by other organizations on its behalf; (b) Determining the levels of information security appropriate to protect such information and information systems, and implementing the same in coordination with the DICT; (c) Periodically testing and evaluating information security controls and techniques to ensure that they are effectively implemented; (d) Ensuring procedures, standards, and guidelines, including information security standards promulgated by the DICT and information security standards promulgated by the DICT and information security standards and guidelines for national security systems issued in accordance with law and as directed by the President of the Philippines; (e) Ensuring that information security management processes are integrated with agency strategic and operational planning processes; and (f) Adopting the Privacy-by-Design, Privacy Engineering, and Privacy-by-Default principles in developing, implementing, and deploying systems, processes, software applications, and services throughout the processing of personal data.

Master Data Management.

Section 25

SEC. 25. Master Data Management. - In order to have access to the most updated data, the government shall establish and maintain measures to ensure that the parent government agency responsible for a set of data shall own, maintain, update, and protect the data while giving access through a secure API to other agencies.

Back to RA 12254 — full text

Provisions on this page are reproduced verbatim from official open data. See the attribution line.

Source: Supreme Court E-Library, Republic of the Philippines. Philippine laws are public documents (works of the government).