My bookmarksSign up free

RA 12254 Section 12

RA 12254 Section 12

Protection of Government Critical Information Infrastructure (CII).

Section 12

SEC. 12. Protection of Government Critical Information Infrastructure (CII). - The DICT, in coordination with relevant government agencies and stakeholders, shall issue guidelines for the protection of government CII identified in the EGMP. All government CIIs shall undergo Vulnerability Assessment and Penetration Testing (VAPT) before deployment and an annual risk and security assessment. All government CII shall create an organizational Computer Emergency Response Team (CERT) or Computer Security Incident Response Team (CSIRT) and immediately notify major information security incidents affecting their institution to the DICT's National Computer Emergency Response Team (NCERT), which shall be the central authority for all the sectoral and organizational CERTs in the country, subject to rules and regulations, protocols, guidelines and standards in cybersecurity.

Read the full instrument → · Open the chapter this section belongs to: CHAPTER III →

Other provisions in CHAPTER III

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of July 4, 2026

CitationRA 12254 Section 12 (LawPlayer, data as of July 4, 2026)

Source: Supreme Court E-Library, Republic of the Philippines. Philippine laws are public documents (works of the government).

Continue your research