The National Information Technology Authority–Uganda (NITA-U) has taken another step in fortifying the country’s cybersecurity infrastructure with a stakeholder workshop aimed at reviewing and enhancing the National Information Security Framework (NISF).
The high-level engagement, held at Mestil Hotel, brought together representatives from government ministries, departments and agencies (MDAs) to share experiences and provide input on how the Framework can be updated to address current technological realities and growing cyber threats.
The NISF, developed in 2014, serves as the government’s blueprint for safeguarding digital systems and protecting citizen data. It outlines baseline standards and best practices to help MDAs strengthen their cybersecurity posture. However, with the rapid pace of technological advancements and the sophistication of cyber threats, NITA-U says the Framework must evolve to remain effective.
Speaking at the event, Mr. Arnold Mangeni, Director of Information Security at NITA-U, highlighted the importance of collaboration in shaping the future of the Framework.
“You have been using the Framework, so you know where the gaps are,” he told participants. “Your feedback will guide the consultant on what to enhance, ensuring that the updated NISF is not just a document on paper but a living tool that works better for all of us in protecting government systems and the data of our citizens.”
Mr. Johnson Tumusiime, Manager of Governance and Risk at NITA-U, reiterated that the Framework was originally designed to provide a baseline for information security across government institutions, ensuring protection of systems and data from cyber threats.

He noted that while the initial version was groundbreaking in 2014, emerging technologies and evolving risks make regular updates indispensable.
“Obviously with the changes in technologies, we saw that there was a need to improve it. And that’s what we’re doing today. We’re putting some insights, we’re putting some discussions, some requirements for customization based on the MDAs specific sector and scope. And that’s the feedback that we’re going to give our consultants .”
“The insights gathered here will help us align the framework with current realities and emerging threats,” he added.
One of the key challenges identified is the enforcement of standards across all MDAs and ensuring that institutions work collectively to implement cybersecurity recommendations.
Tumusiime stressed that continued engagement and platforms like this workshop will help bridge such gaps and foster stronger compliance.
The review exercise falls under the World Bank–funded UGA Digital Acceleration Project, which supports Uganda’s digital transformation agenda. By updating the NISF, NITA-U aims to build greater trust in government digital services, assure citizens of the safety of their personal data, and strengthen the resilience of Uganda’s public sector against cyberattacks.
At a time when cyber threats continue to grow in scale and complexity, the updated NISF is expected to provide government entities with the tools, guidance and confidence to deliver secure and reliable e-services to the public.

