Overview
This document establishes a comprehensive framework for standardizing government email usage across all ministries, departments, and agencies within the Republic of Malawi. Aligned with international best practices from leading digital governments worldwide, this policy enhances security, efficiency, professionalism, and legal compliance of government communications while reinforcing national digital sovereignty and reducing cyber risks.
Strategic Importance
Email serves as the primary communication infrastructure for modern government operations, facilitating critical exchanges between ministries, international partners, and citizens. The absence of comprehensive standards exposes government communications to cybersecurity vulnerabilities, operational inefficiencies, and legal non-compliance risks. This framework establishes world-class standards ensuring all government email communications meet the highest levels of security, professionalism, and regulatory compliance.
Key Benefits
This framework delivers enhanced cybersecurity through comprehensive email security controls that protect against phishing, malware, and unauthorized access. Standardized systems enable seamless inter-governmental communication between ministries and departments and strengthen legal compliance with data protection laws, cybersecurity regulations, and records management requirements. Uniform, credible communication practices enhance Malawi's international reputation while standardized infrastructure and processes reduce IT costs and improve service quality. The framework maintains government control over critical communication infrastructure in support of digital sovereignty.
Description
1. Introduction and Scope
1.0 Normative Language (Mandatory Keywords)
The following keywords are used to express requirement strength in this standard:
- SHALL / MUST: Mandatory requirement. Non-compliance requires an approved exception.
- SHOULD: Recommended requirement. If not implemented, rationale should be documented.
- MAY: Optional requirement.
- MUST NOT / SHALL NOT: Prohibited requirement.
1.1 Purpose
To establish world-class email communication standards that position Malawi's government as a digitally mature, secure, and professionally competent public sector organization capable of effective domestic and international engagement.
This policy framework defines comprehensive standards governing email usage across all government entities, ensuring secure, professional, and legally compliant communications that align with international best practices and enhance Malawi's standing in the global digital governance landscape.
1.2 Scope of Application
This policy applies to:
- All government ministries and departments: Comprehensive coverage across all ministerial portfolios
- State-owned enterprises and parastatals: Government-controlled commercial entities and statutory bodies
- Local government authorities: Municipal, city, and district councils
- Government contractors and consultants: External parties authorized to use government email infrastructure
All email communications: Any electronic mail transmitted on behalf of the Government of Malawi, regardless of originating entity
This policy applies universally to all personnel and entities operating within or on behalf of the Government of Malawi.
1.3 Definitions and Key Terms
Government email – Electronic mail transmitted on behalf of the Government of Malawi using government email infrastructure (e.g. @gov.mw, ministry domains); subject to this standard regardless of originating entity.
Email domain – The hierarchical addressing structure (e.g. gov.mw, mda.gov.mw, department.ministry.gov.mw) that identifies the organisational source and authority of government communications.
TLS (Transport Layer Security) – Encryption of email in transit between mail servers and (where applicable) client to server; minimum TLS 1.2 (TLS 1.3 preferred) per PKI and Server Hardening Standards.
SPF, DKIM, DMARC – Sender Policy Framework, DomainKeys Identified Mail, and Domain-based Message Authentication: mechanisms to authenticate and protect email from spoofing and phishing; required for government domains.
Archival and retention – Storage of email for the period required by law, FOI, and records management; retention schedules and secure deletion per Data Protection Act where personal data is concerned.
Acceptable use – Use of government email for government business and (where policy permits) limited personal use in line with Malawi Government Acceptable Use Standards; prohibited use includes harassment, illegal activity, and circumvention of security.
Phishing – Attempts to obtain credentials or sensitive information via fraudulent email; government email systems must be protected (filtering, awareness) and incidents reported per Incident Response.
2. Core Objectives and Success Metrics
2.1 Primary Objectives
Security – Government email is protected by TLS in transit, authentication (SPF, DKIM, DMARC), filtering against phishing and malware, and access control (IAM); zero successful phishing and 99.9% availability target.
Professionalism and compliance – Email usage is professional and legally compliant; 100% policy adherence within 18 months; retention and archival align with FOI and Data Protection Act.
Standardisation – Consistent domain structure, security controls, and processes across all ministries so that inter-governmental and citizen-facing communications are credible and secure.
Efficiency – Timely response (e.g. under 24 hours for urgent matters) and cost optimisation through standardised infrastructure and processes.
Digital sovereignty – Government retains control over critical communication infrastructure and data; vendor or cloud email used only under governed arrangements per Cloud and Vendor Risk Standards.
2.2 Key Performance Indicators (KPIs)
The following measurable objectives demonstrate the effectiveness of these standards:
- Metric
- Target
- Strategic Rationale
- Security
- Zero successful phishing attacks<br>99.9% email availability
- Protects sensitive government data and ensures mission-critical communication availability
- Compliance
- 100% policy adherence within 18 months
- Ensures universal adoption and consistent application of standards across all government entities
- Efficiency
- Average email response time under 24 hours for urgent matters
- Facilitates timely decision-making and maintains operational responsiveness
- Professional Standards
- 95% adherence to email etiquette guidelines
- Preserves institutional credibility and enhances international reputation
- Cost Optimization
- 20% reduction in email-related IT costs through standardization
- Delivers fiscal responsibility while improving service quality and security posture
- Retention and archival
- 100% of email records retained and retrievable per retention schedule and FOI timelines
- Supports legal compliance and e-discovery
3. Email Domain Standardization and Management
3.1 Hierarchical Domain Structure
Email domains serve as the organizational identifier within the email addressing system, establishing the authoritative source and organizational hierarchy of communications. The government email infrastructure employs a structured hierarchical domain architecture:
gov.mw
│
├── Ministries / MDAs
│ └── ministry.gov.mw
│ ├── department.ministry.gov.mw
│ └── service.ministry.gov.mw
│
├── Government Agencies / Authorities
│ └── agency.gov.mw
│
└── Local Government Authorities
└── council.gov.mw
└── city.council.gov.mwThis hierarchical structure enables clear identification of organizational origin, facilitates efficient routing and filtering, and ensures consistent naming conventions across all government entities.
3.2 Email Address Standards
- Individual Accounts
- Every government employee receives a standardized email address:
- Primary Format: `employment_number@boma.gov.mw`
- Example: `12345@boma.gov.mw`
- Rationale: Provides unique identifier, eliminates address conflicts, enables automated account management
- Alias Format: `firstname.lastname@department.gov.mw`
- Example: `john.banda@finance.gov.mw`
- Rationale: Professional presentation, facilitates recognition and recall, supports external communications
- Duplicate Resolution: `firstname.lastname.01@department.gov.mw`
- Example: `john.banda.01@finance.gov.mw`
- Rationale: Resolves naming conflicts while maintaining professional format, scalable numbering system
- Long Names: `f.lastname@department.gov.mw` (when name exceeds 30 characters)
- Example: `m.mwalechuluwa@finance.gov.mw`
- Rationale: Maintains address length within technical constraints while preserving professional appearance
- Functional Accounts
- These are shared email addresses for specific purposes:
- Address Type
- Format
- Purpose
- Example
- General Inquiries
- `info@mda.gov.mw`
- Public questions
- `info@health.gov.mw`
- Press/Media
- `press@mda.gov.mw`
- Media communications
- `press@finance.gov.mw`
- Public Services
- `services@mda.gov.mw`
- Citizen services
- `services@education.gov.mw`
- Technical Support
- `support@mda.gov.mw`
- IT help
- `support@ict.gov.mw`
- Emergency Contact
- `emergency@mda.gov.mw`
- Urgent matters
- `emergency@health.gov.mw`
Functional accounts are managed by designated service teams rather than individual users, ensuring continuous availability and consistent service delivery across operational hours.
3.3 Email Domain Governance
Domain governance establishes the decision-making framework, accountability structures, and operational procedures for email domain management across the government.
- Central Registry
- Managed By: Ministry of Information and Communication Technology (MoICT)
- Department: E-Government Division
- Responsibility: Maintains master list of all government email domains
- Approval Process
- Before creating a new email domain, organizations must:
- Submit formal request with business justification
- Demonstrate need (e.g., new ministry, reorganization)
- Receive approval from E-Government Division
- Complete technical setup within 30 days
- DNS Management
The Domain Name System (DNS) provides the critical infrastructure translating human-readable domain names into IP addresses required for email routing and delivery. DNS failures prevent email delivery entirely.
- Centralized DNS Services: Unified management of all government domains through a single authoritative system
- Redundant Servers: Geographically distributed DNS servers ensure high availability and fault tolerance
- 24/7 Monitoring: Continuous monitoring and automated alerting for DNS health and performance issues
- Certificate Management
SSL/TLS certificates provide cryptographic proof of server identity and enable encrypted communications, preventing man-in-the-middle attacks and ensuring data confidentiality.
- Automated Provisioning: Certificate issuance automated through integration with certificate authorities
- Automatic Renewal: Proactive certificate renewal prevents service interruptions and security warnings
- Zero-Downtime Renewal: Seamless certificate rotation ensures continuous service availability
4. Comprehensive Security Framework
4.1 Multi-Layered Security Architecture
The defense-in-depth security model employs multiple complementary security layers, ensuring that compromise of any single control does not result in system-wide failure. Each layer provides independent protection while contributing to overall security posture.
Layer 1: Network Security
Network security protects the underlying infrastructure that transports email communications, implementing controls at the network perimeter and within the network architecture.
- Border Email Security: Advanced threat protection deployed at network ingress/egress points, performing deep packet inspection and threat analysis before traffic enters the internal network
- IP Reputation Filtering: Real-time blocking of email traffic originating from IP addresses associated with known malicious activity, leveraging threat intelligence feeds and reputation databases
Geo-Blocking: Selective blocking of email traffic from geographic regions with elevated cybercrime rates or geopolitical risk factors, configurable based on threat intelligence
- Network Segmentation: Logical and physical separation of email infrastructure from other network segments, limiting lateral movement in case of compromise and reducing attack surface
- DDoS Protection: Distributed denial-of-service mitigation capabilities including traffic scrubbing, rate limiting, and automated scaling to maintain service availability under attack
Layer 2: Email Security Gateway
The email security gateway performs comprehensive analysis and filtering of all inbound and outbound email traffic before messages reach user mailboxes or leave the organization.
- Advanced Spam and Malware Filtering: Multi-engine threat detection achieving 99.9% accuracy through signature-based detection, heuristic analysis, machine learning, and behavioral analysis
- Sandboxing: Dynamic analysis of suspicious attachments and URLs in isolated virtual environments, detecting zero-day threats and advanced persistent threats that evade signature-based detection
- URL Rewriting: Real-time URL analysis and rewriting through secure proxy services, enabling safe link checking, click-through tracking, and protection against malicious websites
Data Loss Prevention (DLP) Scanning: Content analysis and policy enforcement preventing transmission of sensitive data including personally identifiable information, financial data, and classified information
Layer 3: Encryption and Authentication
Encryption and authentication mechanisms ensure message confidentiality, integrity, and authenticity throughout the email lifecycle.
TLS 1.3 Mandatory: Transport Layer Security 1.3 provides state-of-the-art encryption for email in transit, protecting against interception and man-in-the-middle attacks while ensuring forward secrecy
S/MIME Encryption: Secure/Multipurpose Internet Mail Extensions provides end-to-end encryption for sensitive communications, ensuring only intended recipients can decrypt message content
End-to-End Encryption: Advanced encryption protocols for classified materials ensuring that email service providers cannot access message content, providing maximum confidentiality for highly sensitive communications
Digital Signatures: Cryptographic signatures using public key infrastructure provide message authentication, integrity verification, and non-repudiation, proving message origin and detecting tampering
Layer 4: Access Control
Access control mechanisms enforce authentication and authorization policies, ensuring only authorized users can access email accounts and systems.
Multi-Factor Authentication (MFA): Mandatory multi-factor authentication combining password (knowledge factor) with time-based one-time passwords from authenticator applications (Microsoft Authenticator, Google Authenticator), significantly reducing account compromise risk
Single Sign-On (SSO): Centralized authentication through Boma Auth enables seamless access to all government systems while maintaining security through centralized policy enforcement and session management
Privileged Access Management (PAM): Enhanced security controls for administrative accounts including just-in-time access, session recording, and approval workflows, protecting high-value targets from compromise
Zero-Trust Network Access: Security model requiring continuous verification of user identity and device security posture regardless of network location, eliminating implicit trust in internal networks
4.2 Email Authentication Standards
Email authentication protocols provide cryptographic verification of email sender identity, preventing email spoofing and ensuring recipients can trust message origins. These standards form the foundation of email security and deliverability.
Governance Structure
Who Manages Email Authentication?
- E-Government Division (MoICT)
- Overall policy and standards
- Central coordination
- Compliance monitoring
- IT Security Office
- Technical implementation
- Security monitoring
- Incident response
- Ministry IT Teams
- Day-to-day management
- User support
- Local configuration
- Decision-Making Process:
- Policy changes: E-Government Division + IT Security Office
- Technical issues: IT Security Office + Ministry IT Teams
- Compliance violations: Escalated to senior management
- Mandatory Implementation
- All government email domains MUST implement these four authentication standards:
- SPF (Sender Policy Framework)
SPF prevents email spoofing by authoritatively declaring which mail servers are permitted to send email on behalf of a domain. Receiving servers verify sender IP addresses against published SPF records.
- Configuration Example: ``` v=spf1 include:_spf.gov.mw ~all ```
- Configuration Elements:
- `v=spf1`: SPF protocol version 1
- `include:_spf.gov.mw`: Delegates to central government SPF policy for consistency
- `~all`: Soft fail mechanism (quarantine non-matching emails rather than hard reject, allowing gradual enforcement)
- DKIM (DomainKeys Identified Mail)
DKIM provides cryptographic authentication by attaching digital signatures to email messages. Receiving servers verify signatures using public keys published in DNS, confirming message authenticity and integrity.
Requirements:
- Minimum 2048-bit RSA keys providing strong cryptographic security
- Monthly key rotation schedule reducing exposure window if keys are compromised
- Automatic signing of all outgoing emails ensuring comprehensive coverage
- DMARC (Domain-based Message Authentication, Reporting & Conformance)
DMARC provides policy-based email authentication by instructing receiving servers how to handle emails that fail SPF or DKIM verification. It enables domain owners to protect their brand reputation and prevent spoofing.
Policy Progression:
Phase 1 (Months 1-6): `p=quarantine` - Emails failing authentication are quarantined (delivered to spam/junk folders) while allowing monitoring and adjustment
Phase 2 (Months 7-12): `p=reject` - Emails failing authentication are rejected at the server level, providing maximum protection
Rationale for Gradual Implementation: Phased approach allows identification and remediation of legitimate email sources that may initially fail authentication, preventing service disruption while achieving security objectives.
BIMI (Brand Indicators for Message Identification)
BIMI enables visual brand authentication by displaying verified government logos in supporting email clients. This provides immediate visual confirmation of email authenticity and enhances brand recognition.
Requirements:
Official government logos approved by the Communications Department, ensuring consistent visual identity
Verified Mark Certificates (VMC) from accredited certificate authorities, providing cryptographic proof of logo authenticity
Consistent branding standards across all ministries maintaining unified government visual identity
Configuration Requirements Summary
Standard
- Purpose
- Key Requirement
- SPF
- Prevent spoofing
- Include central SPF record
- DKIM
- Verify authenticity
- 2048-bit keys, monthly rotation
- DMARC
- Policy enforcement
- Start with quarantine, move to reject
- BIMI
- Visual authentication
- Official logos with VMC
- DMARC Reporting and Enforcement Operations (Procedure)
Procedure: (1) Establish a government mailbox or service endpoint to receive DMARC aggregate reports; restrict access and retain reports as operational security evidence. (2) Review reports on a defined cadence (e.g. weekly during rollout, then monthly) to identify unauthorized senders and legitimate sources failing SPF/DKIM. (3) Remediate legitimate senders (align SPF/DKIM) and block or investigate unauthorized sources. (4) Only advance enforcement (quarantine → reject) when monitoring shows legitimate sources are consistently passing or are explicitly excepted with compensating controls. (5) Retain evidence of reviews and enforcement changes for audit.
4.3 Advanced Threat Protection
Advanced persistent threats (APTs) and sophisticated attack techniques require specialized detection and response capabilities beyond traditional signature-based security controls. An effective defense combines proactive threat hunting, multi-layered technical controls, and robust operational processes.
4.3.1 Targeted Threat Defense
Beyond standard malware and spam, modern adversaries employ social engineering tactics that are low-tech, high-impact, and designed to bypass traditional filters by exploiting human trust.
Business Email Compromise (BEC), Executive Impersonation, and Spear Phishing: These attacks involve impersonating a trusted individual (e.g., a Minister, CEO, or vendor) to trick an employee into performing an unauthorized action, such as making a wire transfer or releasing sensitive data. Because these emails often contain no links or attachments, they can evade standard security filters.
On-Premise Mitigation:
- Inbound Email Tagging: The email gateway SHALL be configured to automatically add a visual banner (e.g., `[EXTERNAL]`) to the subject line or body of all emails originating from outside the government network. This provides an immediate visual cue to users that the email is not from a trusted internal colleague.
- Display Name Anomaly Detection: The email security gateway SHOULD use algorithms to detect impersonation attempts where the attacker uses a known display name (e.g., "John Banda") but with a different, external email address.
- Domain Spoofing Prevention: Strict enforcement of DMARC with a `p=reject` policy is the primary defense against direct domain spoofing.
- User Awareness: Training (Section 9) MUST include specific modules on identifying BEC characteristics, such as unusual requests, urgent language, and mismatched email addresses.
QR Code Phishing (Quishing): Attackers embed malicious links within QR codes in the body of an email. When a user scans the QR code with their personal or work mobile device, it directs them to a phishing site, bypassing URL scanners that inspect email body text.
On-Premise Mitigation:
- Image Analysis and OCR: The email security gateway SHOULD be capable of performing Optical Character Recognition (OCR) on images attached to or embedded in emails to identify QR codes. Once identified, the underlying URL can be extracted and analyzed by the gateway's URL filtering engine.
- Mobile Device Security: While the email system is on-premise, this threat extends to mobile devices. MDM policies (Section 7.1) SHOULD be used to enforce the use of approved QR code scanner apps that include security checks.
- User Education: Users MUST be trained to treat QR codes in emails with the same level of suspicion as regular links and to verify the source before scanning.
AI-Powered Social Engineering: The increasing availability of advanced AI makes it easier for attackers to generate highly convincing, personalized, and context-aware phishing emails at scale. These attacks are grammatically perfect, mimic the subject's writing style, and can be used to create sophisticated, multi-stage social engineering campaigns.
On-Premise Mitigation: Defense against AI-powered attacks relies on a combination of advanced detection techniques that go beyond simple pattern matching.
- Enhanced Behavioral Analysis: The AI-powered detection capabilities mentioned below must be tuned to identify subtle anomalies in email content, sender-recipient relationships, and communication patterns that might indicate a sophisticated, AI-generated attack.
- Zero Trust Principles: Applying a Zero Trust mindset (see Section 4.4) is crucial. Every email, regardless of its apparent source, must be treated with suspicion and verified.
4.3.2 Advanced Security Operations
AI-Powered Threat Detection:
- Machine Learning Algorithms: Adaptive threat detection systems that learn from historical attack patterns, user behavior, and email characteristics to identify novel threats and zero-day attacks.
- Behavioral Analysis: Anomaly detection identifying deviations from normal email patterns including volume spikes, unusual recipients, atypical content, and timing anomalies that may indicate compromised accounts.
Incident Response Automation:
SOAR Integration: Security Orchestration, Automation, and Response platforms enable automated threat detection, analysis, containment, and remediation, reducing mean time to detection (MTTD) and mean time to response (MTTR).
Threat Intelligence Integration:
- National Sources: Integration with Malawi's national cybersecurity agencies and Computer Incident Response Team (CIRT) for localized threat intelligence.
- International Sources: Participation in global threat intelligence sharing networks including ISACs (Information Sharing and Analysis Centers) and commercial threat feeds.
Regular Security Testing:
- Penetration Testing: Authorized security assessments by certified ethical hackers identifying vulnerabilities before malicious actors exploit them, conducted annually or after significant system changes.
- Vulnerability Assessments: Automated and manual security scanning identifying misconfigurations, unpatched systems, and known vulnerabilities, conducted quarterly with continuous monitoring.
5. Professional Communication Standards
5.1 Email Structure and Format
Professional email standards ensure consistent, clear, and credible communications that enhance trust, facilitate efficient information processing, and maintain the government's professional reputation. Adherence to these standards optimizes communication effectiveness and supports operational efficiency.
1. Subject Line Standards
Purpose: The subject line serves as the primary information retrieval mechanism and priority indicator, enabling recipients to quickly assess email importance, content, and required action.
Requirements:
- Maximum 60 characters: Keeps it concise and visible on mobile devices
- Classification prefix: `[URGENT]`, `[CONFIDENTIAL]`, `[ROUTINE]`
- Clear purpose: What action is needed or what information is provided
- Project/reference numbers: When applicable, include for tracking
- Good Examples:
- `[URGENT] Budget Approval Required - Finance Dept - Ref: FIN-2026-001`
- `[ROUTINE] Monthly Staff Meeting - March 2026`
- `[CONFIDENTIAL] Personnel Review - John Banda`
- Bad Examples:
- `Meeting` (too vague)
- `[URGENT]` (no context)
- `This is about the thing we discussed yesterday` (unclear)
2. Professional Salutation
Choose the appropriate level of formality:
- Level
- When to Use
- Examples
- Formal
- Ministers, Permanent Secretaries, international partners
- "Dear Honourable Minister,"<br>"Dear Permanent Secretary,"<br>"Dear Director General,"
- Semi-Formal
- Colleagues in other ministries, senior officials
- "Dear Mr. Banda,"<br>"Dear Ms. Mwale,"<br>"Dear Dr. Phiri,"
- Informal Internal
- Close colleagues in same department (with prior relationship)
- "Dear John,","Hello Mary,"
Important: When in doubt, use a more formal tone. It's better to be too formal than too casual in government communications.
3. Email Body Structure
The Three-Part Structure (for routine communications):
Opening Paragraph: Purpose and context
Why are you writing?
What is the background?
- Example: "I am writing to request approval for the Q1 2026 budget allocation for the Health Ministry's vaccination program, as discussed in last week's cabinet meeting."
- Middle Paragraphs: Detailed information and supporting data
What are the facts?
What evidence supports your request?
- Example: "The program requires MK 50 million to purchase vaccines for 500,000 citizens. This aligns with our commitment to achieve 80% vaccination coverage by end of 2026, as outlined in the National Health Strategy."
- Closing Paragraph: Action required and timeline
What do you need from the recipient?
When do you need it?
Example: "I would appreciate your approval by Friday, February 21, 2026, to ensure timely procurement. Please let me know if you need any additional information."
Length Guidelines:
- Routine communications: Maximum 3-4 paragraphs
- Complex matters: Use attachments for detailed information
- Simple requests: 1-2 paragraphs may suffice
4. Standardized Signature Block
Why Standardized? Consistent signatures look professional and provide necessary contact information.
- Required Format: ``` [Full Name] [Official Position Title] [Ministry/Department/Agency Name] [Physical Address]
- Phone: [+265-xxx-xxx-xxx] | Mobile: [+265-xxx-xxx-xxx] Email: [name.surname@mda.gov.mw] Website: [www.mda.gov.mw]
- Government of Malawi
- [Confidentiality Notice] ```
- Example: ``` John Banda Senior Accountant Ministry of Finance Capital Hill, Lilongwe 3
- Phone: +265-1-789-456 | Mobile: +265-999-123-456 Email: john.banda@finance.gov.mw Website: www.finance.gov.mw
- Government of Malawi
This email and any attachments are confidential and intended solely for the addressee. If you are not the intended recipient, please notify the sender immediately and delete this email. ```
Confidentiality Notice Options:
- Standard: "This email and any attachments are confidential..."
- Internal Use: "This email is for internal government use only..."
- Public Information: "This email may be subject to public disclosure..."
5.2 Response Time Standards and Escalation
Why Response Times Matter: Timely responses show professionalism and ensure government operations run smoothly.
- Response Time Framework
- Priority Level
- Acknowledgment
- Full Response
- Examples
- Critical/Emergency
- Within 30 minutes
- Within 2 hours
- Security breaches, natural disasters, public health emergencies
- Urgent
- Within 2 hours
- Within 24 hours
- Ministerial requests, time-sensitive decisions, citizen complaints
- High Priority
- Within 4 hours
- Within 48 hours
- Policy matters, budget approvals, inter-ministerial coordination
- Normal
- Within 1 working day
- Within 3 working days
- Routine correspondence, information requests, standard procedures
- Low Priority
- Within 2 working days
- Within 5 working days
- General inquiries, non-urgent matters, informational updates
- Acknowledgment Definition: A formal confirmation of message receipt indicating awareness of the communication and providing expected response timeline, demonstrating professional responsiveness and managing sender expectations.
- Example Acknowledgment: ``` Subject: Re: [URGENT] Budget Approval Required
Dear Director,
I acknowledge receipt of your email regarding the Q1 budget approval. I will provide a full response by 5:00 PM today, February 17, 2026.
Best regards, John Banda ```
Escalation Procedures
When to Escalate: If you cannot meet the response time, escalate immediately.
Escalation Levels:
- Automated Escalation (System-Generated)
- Overdue responses trigger automatic notifications
- Supervisor receives alert after 2 hours overdue
- Escalates to department head after 24 hours overdue
- Supervisor Notification (Manual)
- For urgent matters requiring immediate attention
- When you need additional resources or authority
- Example: "I need approval for emergency procurement"
- Cabinet Office Escalation
- For ministerial communications
- Cross-ministerial coordination issues
- Matters requiring high-level decision-making
- International Protocol
- For diplomatic communications
- International partner requests
- Follows diplomatic protocols and timelines
- Escalation Template: ``` Subject: [ESCALATED] [URGENT] Budget Approval Required
- Dear [Supervisor Name],
I am escalating the attached email from [Sender Name] regarding [Topic] as it requires [Reason for Escalation] and cannot be resolved at my level.
Original Request: [Brief summary] Required Action: [What is needed] Timeline: [When response is needed]
Thank you, [Your Name] ```
5.3 Email Classification and Handling
Email classification provides a systematic framework for categorizing information sensitivity and applying appropriate security controls, handling procedures, and retention policies. Classification ensures information receives protection commensurate with its sensitivity and legal requirements.
- Classification Levels
- Level
- Description
- When to Use
- Example
- OPEN
- General information, publishable
- Public announcements, general information
- Press releases, public meeting notices
- INTERNAL
- Government use only, not for public release
- Internal discussions, draft documents
- Staff meeting minutes, internal memos
- CONFIDENTIAL
- Sensitive information requiring protection
- Personal data, financial information, policy drafts
- Employee records, budget details, policy proposals
- RESTRICTED
- Classified information with access controls
- National security, legal matters, high-level decisions
- Security briefings, legal advice, cabinet decisions
- How to Classify: Add classification in both subject line and email body.
- Example Subject Line: ``` [CONFIDENTIAL] [URGENT] Personnel Review - John Banda ```
- Example Email Body Header: ``` CLASSIFICATION: CONFIDENTIAL
- Dear Director,
- [Email content] ```
- Handling Requirements
- Based on Classification:
- Classification
- Encryption Required
- Access Controls
- Retention Period
- OPEN
- Optional
- Public
- 3 years
- INTERNAL
- Recommended
- Government employees only
- 7 years
- CONFIDENTIAL
- Mandatory
- Authorized personnel only
- 10 years
- RESTRICTED
- Mandatory + End-to-End
- Specific named recipients
- Permanent archive
- Marking Requirements:
- Subject Line: Include classification prefix
- Email Body: Classification header at top
- Attachments: Classify separately if different from email
- Access Controls:
- OPEN: No restrictions
- INTERNAL: Government email addresses only
- CONFIDENTIAL: Specific department/role restrictions
- RESTRICTED: Named individuals only, no forwarding
- Audit Trails:
- All classified emails are logged
- Access attempts are recorded
- Regular audits ensure compliance
- Retention and Disposal:
- Follow retention schedule (see Section 6.2)
- Secure deletion when retention period expires
- Legal hold procedures for ongoing investigations
6. Legal Compliance and Governance
6.1 Data Protection Compliance
The government processes substantial volumes of personal data in the course of public service delivery. Data protection legislation establishes legal frameworks protecting citizen privacy rights while enabling necessary government functions. Compliance ensures lawful, ethical, and secure handling of personal information.
Malawi Data Protection Act (2024) Requirements
The Data Protection Act establishes comprehensive legal requirements governing the collection, processing, storage, and disclosure of personal data, ensuring citizen privacy rights are protected while enabling effective government operations.
Key Requirements:
- Lawful Basis for Processing
- Legal Requirement: Personal data processing must be based on one of six lawful grounds specified in the Act
- Permissible Bases: Consent, contract performance, legal obligation, vital interests, public task, legitimate interests
- Email Application: Include personal data in emails only when necessary for a lawful purpose and document the legal basis
- Data Minimization Principles
- Legal Requirement: Collect and process only the minimum personal data necessary for the specified purpose
- Email Application: Restrict personal data inclusion to information directly relevant to the communication purpose
- Example: Service inquiry emails should include only relevant identifiers, not comprehensive personal histories
- Individual Rights Implementation
- Access Rights: Citizens may request copies of their personal data held by government entities
- Rectification Rights: Citizens may request correction of inaccurate personal data
- Erasure Rights: Citizens may request deletion of personal data under specified circumstances
Email Application: Establish procedures to respond to data subject requests within statutory timelines (typically 30 days)
Privacy Impact Assessments
- Legal Requirement: Conduct assessments evaluating privacy risks before implementing new systems or processes handling personal data
- When Required: New email systems, significant system modifications, processing of sensitive personal data
- Process: Document privacy risks, mitigation measures, and compliance strategies
Data Breach Notification Procedures
- Timeline: Notify the Data Protection Authority within 72 hours of breach discovery
- Notification Content: Breach nature, affected data categories, approximate number of affected individuals, likely consequences, mitigation measures
- Recipient Notification: Notify affected individuals without undue delay if breach poses high risk to rights and freedoms
Electronic Transactions and Cybersecurity Act (2016) Alignment
The Electronic Transactions and Cybersecurity Act provides the legal framework recognizing electronic communications as legally equivalent to paper documents, establishing requirements for digital signatures, cybersecurity, and electronic record keeping.
Key Requirements for Email:
- Legal Recognition of Electronic Communications
- Legal Status: Electronic communications including email have equivalent legal validity to paper documents
- Legal Implication: Emails constitute admissible evidence in legal proceedings when properly authenticated
- Operational Requirement: Maintain comprehensive records with authentication mechanisms ensuring legal defensibility
- Digital Signatures
- Legal Validity: Digitally signed emails have equivalent legal force to handwritten signatures when using approved systems
- Technical Requirement: Implement PKI-based digital signature systems meeting Act requirements for official communications
- Standard: X.509 certificates issued by recognized certificate authorities (see Section 7.2)
- Cybersecurity Requirements
- Legal Obligation: Government entities must implement appropriate cybersecurity measures protecting electronic systems
- Technical Requirement: Deploy comprehensive security controls as specified in Section 4 of this document
- Compliance Requirement: Conduct regular security assessments and maintain incident reporting procedures
- Data Integrity
- Legal Requirement: Ensure electronic communications maintain integrity and detect unauthorized modification
- Technical Implementation: Deploy authentication mechanisms (DKIM, digital signatures) providing cryptographic proof of integrity
- Monitoring Requirement: Conduct regular audits and integrity checks detecting potential tampering
- Record Keeping
- Legal Requirement: Maintain proper records of electronic communications meeting legal and regulatory requirements
- Operational Requirement: Archive emails according to retention schedules specified in Section 6.2
- Legal Hold Procedures: Preserve emails relevant to ongoing legal proceedings, investigations, or audits
- How This Policy Aligns:
- Section 4 (Security Framework) addresses cybersecurity requirements
- Section 6.2 (Records Management) addresses record keeping
- Section 4.2 (Email Authentication) ensures data integrity
- Section 7.2 (PKI Infrastructure) supports digital signatures
- International Compliance
Why International Compliance Matters: Malawi communicates with international partners and must meet their data protection standards.
- GDPR Compliance (European Union)
- When It Applies: Emails to/from EU citizens or organizations
- Key Requirements: Consent, right to erasure, data portability
- In Practice: Get consent before sending marketing emails, honor deletion requests
- CCPA Considerations (California, USA)
- When It Applies: Emails to/from California residents
- Key Requirements: Disclosure of data collection, opt-out rights
- In Practice: Inform recipients about data collection, provide opt-out options
- African Union Data Protection Guidelines
- Scope: All African countries
- Key Requirements: Regional standards for data protection
- In Practice: Follow AU guidelines as baseline
- SADC Regional Data Protection Standards
- Scope: Southern African Development Community
- Key Requirements: Regional harmonization
- In Practice: Align with SADC standards for regional communications
6.2 Records Management and Retention
Introduction: Records Management Framework
Records management encompasses the systematic control of email records throughout their lifecycle, from creation through final disposition. This framework ensures government emails are properly organized, secured, accessible, and disposed of in accordance with legal, regulatory, and operational requirements.
Strategic Importance:
- Legal Compliance: Statutory and regulatory requirements mandate retention of certain records for specified periods
- Accountability and Transparency: Records provide evidence of government decisions, actions, and rationale, supporting accountability and enabling transparency
- Historical Preservation: Records of significant government actions must be preserved for historical and research purposes
- Operational Efficiency: Systematic organization enables rapid information retrieval supporting decision-making and service delivery
- Citizen Rights: Freedom of Information legislation grants citizens rights to access government records, requiring effective retrieval capabilities
- Email Records Definition: Any email that documents, evidences, or relates to government business, policy decisions, administrative actions, or service delivery. This includes:
- Policy formulation and decision-making
- Financial transactions and budget approvals
- Personnel actions and human resources matters
- Public service delivery and citizen interactions
- Inter-ministerial coordination and intergovernmental communications
- Scope of This Section:
- Retention schedules specifying retention periods by record type
- Archival procedures ensuring secure long-term storage
- Retrieval mechanisms enabling efficient access when needed
- Disposition procedures for secure deletion after retention periods expire
- Retention Schedule
A retention schedule establishes legally compliant timelines specifying retention periods for different categories of email records based on legal requirements, operational needs, and historical value. Retention periods reflect statutory limitations, regulatory requirements, and organizational information governance policies.
- Retention Period Rationale: Different record categories require different retention periods based on:
- Legal Requirements: Statute of limitations, regulatory retention mandates, and legal discovery obligations
- Operational Needs: Business continuity requirements and ongoing reference needs
- Historical Value: Records of enduring historical significance require permanent preservation
- Data Protection: Data minimization principles require deletion when retention periods expire unless legal hold applies
- Record Type
- Retention Period
- Reason
- Examples
- Routine Correspondence
- 3 years
- General communications, no long-term value
- Meeting confirmations, general inquiries, routine memos
- Policy and Administrative
- 7 years
- Documents policy decisions and administrative actions
- Policy drafts, administrative procedures, staff directives
- Legal and Contractual
- 10 years
- Legal requirements, contract disputes
- Contracts, legal advice, procurement documents, dispute resolution
- Historical Significance
- Permanent archive
- Important for historical record
- Cabinet decisions, major policy announcements, significant events
- Personal Data
- Minimized retention periods
- Data protection requirements
- Employee records (as per employment law), citizen data (minimum necessary)
- How to Apply Retention:
- Classify Email: Determine what type of record it is
- Set Retention Date: Calculate when retention period ends
- Archive: Move to archive system
- Review: Before deletion, review for historical value
- Delete: Securely delete after retention period (unless legal hold applies)
Procedure: (1) Classify each email or mailbox category against the retention schedule; document classification rationale where disputed. (2) Set retention end date and move to archive per schedule; ensure FOI retrieval can be met (e.g. within 21 days). (3) Before disposal, confirm no legal hold applies; perform secure deletion and record disposition. (4) Retain evidence of retention and disposal for audit; review retention schedule annually.
Example:
- Email sent: February 17, 2026
- Type: Routine correspondence
- Retention: 3 years
- Delete after: February 17, 2029
- Archival Requirements
Email archiving involves the systematic transfer of emails from active production systems to dedicated archival storage systems designed for long-term preservation, compliance, and retrieval. Archival systems provide secure, cost-effective storage optimized for retention rather than active use.
- Archival Rationale: Separation of active and archival storage provides:
- Performance Optimization: Active systems maintain optimal performance by removing older emails
- Cost Efficiency: Archival storage uses cost-effective media optimized for long-term retention
- Security: Dedicated archival systems provide enhanced security controls for long-term data protection
- Compliance: Archival systems support legal and regulatory requirements for long-term record keeping
- Retrieval Capability: Specialized archival systems enable efficient search and retrieval of historical records
- Archival Standards:
- Automated Daily Backups
- What: System automatically backs up all emails daily
- Why: Protects against data loss
- Storage: Encrypted backups in secure locations
- Geographic Replication
- What: Copies stored in multiple locations
- Why: Disaster recovery (if one location fails, others available)
- Locations: Primary data center + backup data center (different geographic regions)
- Regular Archive Integrity Testing
- What: Periodically check that archived emails are still readable
- Frequency: Quarterly
- Why: Ensure archives haven't corrupted over time
- Legal Hold Procedures
- What: Preserve emails relevant to legal proceedings
- When: Ongoing investigations, litigation, audits
- Process: Mark emails for preservation, prevent deletion
- Duration: Until legal matter resolved
- Freedom of Information Act Compliance
- What: Citizens can request access to government records
- Requirement: Be able to find and provide requested emails
- Timeline: Respond within 21 days (as per FOI Act)
- Process: Search archives, review for exemptions, provide access
- Archive Access:
- Who Can Access: Authorized personnel only
- How to Request: Submit request through records management system
- Response Time: Within 5 working days for routine requests
- Fees: May apply for extensive searches (as per FOI Act)
6.3 Audit and Compliance Monitoring
Audit and compliance monitoring involves systematic evaluation of email system operations, user behavior, and policy adherence to ensure standards are effectively implemented and maintained. Continuous monitoring enables proactive identification of compliance gaps and security issues.
- Audit Objectives: Comprehensive auditing ensures:
- Policy Adherence: Standards are consistently applied across all government entities
- Security Effectiveness: Security controls are functioning as designed and detecting threats
- Legal Compliance: Statutory and regulatory requirements are being met
- Risk Management: Issues are identified and remediated before they escalate
- Continuous Improvement: Audit findings inform policy refinement and system enhancements
- Continuous Monitoring
- Real-Time Compliance Dashboard
- What: Live view of email system compliance
- Metrics: Policy violations, security incidents, response times
- Access: IT Security Office, E-Government Division
- Updates: Real-time
- Automated Policy Violation Detection
- What: System automatically flags violations
- Examples:
- Sending confidential emails without encryption
- Including personal data unnecessarily
- Missing required signatures
- Response: Automatic alerts to supervisors
- Email Usage Analytics and Reporting
- What: Statistics on email usage
- Metrics: Volume, response times, classification usage
- Frequency: Monthly reports
- Purpose: Identify trends, optimize operations
- Incident Tracking and Resolution
- What: Log and track security incidents
- Process: Report → Investigate → Resolve → Document
- Timeline: Track from detection to resolution
- Reporting: Quarterly incident reports to management
- Daily Security Log Analysis
- What: Review security logs every day
- Focus: Unusual activity, failed login attempts, policy violations
- Action: Investigate anomalies immediately
- Responsibility: IT Security Office
6.6 Verification and Evidence Baseline (Audit-Ready Email)
To make the standard auditable, ministries and central operators SHOULD maintain evidence that, at minimum, demonstrates:
- SPF/DKIM/DMARC records and current policy per domain
- MFA enforcement for email access (where required)
- Retention/archiving configuration aligned with the retention schedule
- Incident reporting and response records for email-related incidents
- Exception register entries for any deviations (with expiry and review)
- Compliance Reporting
- Monthly Reports:
- Policy compliance rates
- Security incidents
- Response time performance
- Training completion
- Quarterly Reports:
- Trend analysis
- Incident summaries
- Recommendations for improvement
- Budget and resource needs
- Annual Reports:
- Comprehensive compliance review
- Year-over-year comparisons
- Strategic recommendations
- Presentation to senior management
6.4 Related Standards
This document should be read alongside other Malawi Government IT standards that apply to email and its supporting systems. The Malawi Government IAM Standards define identity, authentication (MFA, SSO/Boma Auth), and access control that underpin email access. The Malawi Government PKI and Certificate Management Standards govern TLS and S/MIME certificates used for email. The Malawi Government Secrets Management Standards apply to any credentials used by email systems or administrators. The Government Server Security Hardening Standards define the security baseline for servers that host email. The Malawi Government Incident Response Standards define how security incidents affecting email are classified, contained, and reported (including to MACRA where a data breach involves email). The Malawi Government Backup and Recovery Standards and Malawi Government Logging and Evidence Standards apply to email archival, retention, and audit logs. The Malawi Government Acceptable Use Standards define acceptable use of government IT including email.
6.5 Safe Exception Process
Exceptions to mandatory email standards (e.g. MFA, TLS, retention) SHALL be requested, documented, and reviewed as follows. Exception requests must include: system or service name; requirement(s) from which exception is sought; justification; compensating controls and timeline; proposed end date; and sign-off from System Owner and Security Officer. Request: The System Owner (or delegated authority) submits an exception request using the government exception form or template, stating the requirement(s) from which an exception is sought, justification, and proposed compensating controls. Documentation: Each exception SHALL document justification; compensating controls and timeline for remediation; risk acceptance by the System Owner and validation by the Security Officer; and maximum exception duration (not to exceed 12 months unless re-approved). Review: Exceptions SHALL be reviewed at least quarterly; extensions require re-approval. Register: All exceptions SHALL be recorded in a central or ministry-level exception register and made available for internal and external audit.
7. Technical Infrastructure and Architecture
7.1 Infrastructure Requirements
Email infrastructure encompasses the physical facilities, network architecture, server systems, and software platforms that collectively enable email service delivery. Robust infrastructure design ensures reliability, security, performance, and scalability.
- Infrastructure Criticality: Enterprise-grade infrastructure is fundamental to email service quality:
- Reliability: Redundant systems and fault-tolerant design ensure continuous availability
- Security: Secure infrastructure architecture protects against threats and vulnerabilities
- Performance: Optimized systems ensure timely email delivery and retrieval
- Scalability: Infrastructure must accommodate growth in users, volume, and functionality
- Compliance: Infrastructure design must support regulatory and legal requirements
- Primary Infrastructure
- Government-Owned Data Centers
Tier III+ Standards: Uptime Institute Tier III+ certification ensuring 99.982% availability (maximum 1.6 hours unplanned downtime annually)
- Redundancy: N+1 redundancy for power, cooling, and network infrastructure
- Concurrent Maintainability: Systems can be maintained without service interruption
- Digital Sovereignty: Government ownership ensures strategic control and security oversight
- Redundant Systems Architecture
- Power Infrastructure: Multiple utility feeds, redundant UPS systems, backup generators with automatic failover
- Environmental Controls: Redundant HVAC systems ensuring optimal operating temperatures and humidity
- Network Connectivity: Diverse carrier connections with automatic failover, eliminating single points of failure
- Rationale: Redundancy ensures service continuity despite component failures
- Service Level Agreement (SLA)
- Uptime Commitment: 99.95% availability target (maximum 4.4 hours downtime annually)
- Financial Remedies: Service credits and penalties for SLA non-compliance incentivizing performance
- Monitoring: Real-time monitoring and alerting ensuring immediate issue detection
- Reporting: Monthly SLA compliance reports with trend analysis and improvement recommendations
- Disaster Recovery
- Recovery Time Objective (RTO): 4-hour maximum time to restore service following disaster declaration
- Recovery Point Objective (RPO): 1-hour maximum acceptable data loss, ensuring near-continuous data protection
- Geographic Separation: Disaster recovery site located in separate geographic region reducing correlated risk
- Testing Regime: Quarterly disaster recovery exercises validating procedures and identifying improvement opportunities
- Capacity Planning
- Growth Projection: Infrastructure designed to accommodate 50% growth over 5-year planning horizon
- Rationale: Government email usage trends upward with digital transformation initiatives
- Process: Annual capacity assessments, proactive expansion before reaching utilization thresholds
- Budget Integration: Capacity expansion costs included in multi-year IT budget planning
- Client Applications
Email client applications provide the user interface and functionality enabling employees to access, compose, send, receive, and manage email communications.
Desktop Applications (for office computers):
- Microsoft Outlook: Primary recommended application
- *Why*: Full-featured, integrates with other Microsoft products
- *Support*: Full technical support available
- Mozilla Thunderbird: Alternative option
- *Why*: Open-source, no licensing costs
- *Support*: Limited support, for technical users
- Mobile Applications (for smartphones and tablets):
- Microsoft Outlook Mobile: Recommended for iOS and Android
- *Why*: Secure, full-featured, integrates with desktop Outlook
- Nine Email: Alternative for Android
- *Why*: Advanced security features
- *Support*: Limited support
- Web Applications (access via internet browser):
- Outlook Web App (OWA): Primary webmail interface
- *Why*: Works on any device with internet browser
- *Access*: Available from anywhere with internet
- Government-Approved Webmail: Alternative web interface
- *Why*: Customized for government needs
- *Features*: Enhanced security, government branding
- Mobile Device Management (MDM)
- Definition: Enterprise mobility management platform providing centralized administration and security enforcement for mobile devices
- Mandatory Enrollment: All mobile devices accessing government email infrastructure must be enrolled in MDM system
Security Capabilities:
- Remote device wipe and lock capabilities for lost or stolen devices
- Policy enforcement including password complexity, encryption requirements, and app restrictions
- Threat detection and security posture monitoring
- Compliance Requirement: MDM enrollment is mandatory prerequisite for mobile email access
7.2 Email Server Architecture and Standards
Email server architecture encompasses the design principles, system configurations, and technical standards governing the servers that process email—receiving messages from external sources, storing messages in user mailboxes, and transmitting messages to recipients.
- Architecture Criticality: Well-architected email systems provide:
- Reliability: Fault-tolerant design ensuring continuous service availability
- Security: Defense-in-depth architecture protecting against threats and vulnerabilities
- Performance: Optimized systems delivering low latency and high throughput
- Scalability: Architecture supporting growth without fundamental redesign
- Maintainability: Systems designed for efficient operations and troubleshooting
- Server Architecture Principles
- High Availability
- What: Systems designed to keep running even if components fail
- How: Multiple servers, automatic failover
- Target: 99.95% uptime
- Scalability
- What: Ability to handle growth in email volume
- How: Modular design, can add capacity easily
- Planning: Designed for 50% growth over 5 years
- Security by Design
- What: Security built into architecture, not added later
- How: Network segmentation, access controls, encryption
- Standards: Follow industry best practices
- Performance Optimization
- What: Fast email delivery and retrieval
- Targets:
- Email delivery: Under 30 seconds
- Email retrieval: Under 2 seconds
- Monitoring: Continuous performance monitoring
- Email Server Components
- Mail Transfer Agents (MTA)
- What: Servers that send and receive emails between organizations
- Standards: SMTP (Simple Mail Transfer Protocol)
- Security: TLS 1.3 encryption mandatory
- Authentication: SPF, DKIM, DMARC
- Mail Delivery Agents (MDA)
- What: Servers that deliver emails to user mailboxes
- Standards: IMAP, POP3
- Security: Encrypted connections required
- Mail User Agents (MUA)
- What: Email client applications (Outlook, webmail)
- Standards: IMAP, POP3, MAPI, CalDAV, CardDAV
- Security: MFA required, encrypted connections
- Storage Systems
- What: Systems that store emails
- Requirements:
- High-capacity storage
- Fast retrieval
- Redundant backups
- Architecture: Distributed storage for reliability
- Standards Compliance
- Email Protocols: Standardized communication protocols enabling interoperability between email systems:
- Protocol
- Purpose
- When Used
- Security Requirement
- SMTP
- Sending emails
- Between email servers
- TLS 1.3 encryption
- IMAP
- Accessing emails
- Email clients reading emails
- TLS encryption, MFA
- POP3
- Downloading emails
- Alternative to IMAP
- TLS encryption, MFA
- MAPI
- Rich email features
- Microsoft Outlook
- Encrypted connections
- CalDAV
- Calendar access
- Calendar applications
- TLS encryption
- CardDAV
- Contact access
- Contact management
- TLS encryption
Protocol Rationale: Different protocols serve distinct functions within the email ecosystem. SMTP handles message transmission, IMAP/POP3 enable message retrieval, while CalDAV and CardDAV extend functionality to calendar and contact management.
REST APIs (for third-party integrations):
- What: Modern way for applications to interact with email systems
- Use Cases: Mobile apps, workflow systems, document management
- Security: API keys, OAuth authentication
- Documentation: Available for approved developers
- Public Key Infrastructure (PKI)
Public Key Infrastructure provides the cryptographic framework for managing digital certificates and encryption keys, enabling secure email through authentication, encryption, and digital signatures.
Components:
- Certificate Authority (CA): Issues and validates digital certificates
- Digital Certificates: Prove identity and enable encryption
- Key Management: Secure storage and rotation of encryption keys
- Uses in Email:
- S/MIME Encryption: Encrypt email content
- Digital Signatures: Sign emails to prove authenticity
- TLS Certificates: Encrypt email transport
- Government PKI:
- Managed By: National PKI Authority (under MoICT)
- Standards: X.509 certificates, 2048-bit minimum key size
- Certificate Lifecycle: Issue → Validate → Renew → Revoke
- Benefits:
- Secure email communications
- Legal validity of digital signatures (per Electronic Transactions Act)
- Interoperability with international partners
7.3 Integration and Interoperability
System integration enables seamless connectivity between email infrastructure and other government IT systems, providing unified user experiences and centralized security management.
- Integration Benefits: Effective integration delivers:
- User Experience: Single sign-on eliminates multiple authentication requirements
- Security: Centralized identity and access management improves security posture
- Efficiency: Automated workflows reduce manual processes and errors
- Data Consistency: Integrated systems maintain synchronized data across platforms
- Cost Optimization: Shared infrastructure reduces duplication and operational costs
- System Integrations
- Active Directory/LDAP Integration
- System: Centralized directory services providing user authentication and authorization
- Purpose: Unified identity management enabling single sign-on across government systems
- Benefits:
- Reduced authentication friction improving user productivity
- Centralized user lifecycle management streamlining operations
- Automated account provisioning and deprovisioning ensuring timely access control
- Protocol Standard: LDAP (Lightweight Directory Access Protocol) v3 for directory access
- PKI Infrastructure Integration
- What: Digital certificate system
- Purpose: Enable digital signatures and encryption
- Integration: Automatic certificate issuance for email accounts
- Benefits: Secure email without manual certificate management
- SIEM Systems Integration
- What: Security Information and Event Management
- Purpose: Centralized security monitoring
- Integration: Email security events feed into SIEM
- Benefits:
- Centralized security view
- Faster threat detection
- Coordinated incident response
- Document Management Systems
- What: Systems for storing and managing documents
- Purpose: Handle large attachments, maintain document versions
- Integration: Attachments automatically stored in document management system
- Benefits:
- Reduced email storage needs
- Better document organization
- Version control
- Workflow Systems
- What: Systems for approval processes
- Purpose: Route emails for approvals, track workflows
- Integration: Emails trigger workflow processes
- Benefits:
- Automated approvals
- Audit trails
- Faster decision-making
- Standards Compliance
Standards Importance: Adherence to industry-standard protocols ensures interoperability between diverse systems, enables vendor flexibility, and facilitates future system integration without proprietary lock-in.
Email Access Standards:
- IMAP: Modern standard for email access
- POP3: Legacy standard, still supported
- Recommendation: Use IMAP for better features
- Email Transport Standards:
- SMTP: Universal standard for sending emails
- Requirement: TLS 1.3 encryption mandatory
- Calendar and Contact Standards:
- CalDAV: Standard for calendar access
- CardDAV: Standard for contact management
- Benefits: Works with any standards-compliant application
- Rich Client Functionality:
- MAPI: Microsoft's protocol for advanced Outlook features
- Use: When using Microsoft Outlook
- Benefits: Full-featured email experience
- Modern Integration:
- REST APIs: Modern way to integrate applications
- Use: Mobile apps, custom applications
- Benefits: Flexible, developer-friendly
8. Security Incident Response and Management
8.1 Incident Classification
A security incident is any event that compromises the confidentiality, integrity, or availability of email systems, data, or services. Incidents may result from malicious activity, system failures, or policy violations.
Classification Rationale: Incident classification enables appropriate resource allocation, ensures proper procedures are followed, and facilitates effective response coordination. Classification determines response priority, team composition, and escalation requirements.
- Severity Levels
- Level
- Description
- Examples
- Response Time
- Critical
- Nation-state attacks, major data breaches affecting >1000 citizens
- Foreign government hacking, massive data theft
- Immediate (within 1 hour)
- High
- Malware infections, unauthorized access, service disruption
- Ransomware attack, account compromise, email system down
- Urgent (within 4 hours)
- Medium
- Policy violations, suspicious activities, minor security events
- Phishing attempt caught, policy violation, suspicious login
- Standard (within 24 hours)
- Low
- User education needs, configuration issues, routine maintenance
- User needs training, minor configuration error
- Normal (within 3 days)
- How to Classify:
- Assess Impact: How many people affected? How sensitive the data?
- Assess Urgency: Is system still compromised? Is data still at risk?
- Assign Level: Use classification matrix above
- Escalate if Uncertain: When in doubt, escalate to higher level
8.2 Response Procedures
Incident response encompasses the systematic processes for detecting, analyzing, containing, eradicating, and recovering from security incidents. Structured response procedures ensure consistent, effective incident handling while minimizing business impact and preventing recurrence.
- Procedural Importance: Well-defined procedures enable:
- Rapid Response: Clear procedures reduce decision time during incidents
- Consistent Handling: Standardized approaches ensure all incidents receive appropriate treatment
- Damage Minimization: Quick containment limits impact scope and duration
- Lessons Learned: Structured processes facilitate post-incident analysis and improvement
- Legal Compliance: Proper procedures ensure regulatory and legal requirements are met
- Incident Response Team
- Who Responds? A dedicated team with specific roles:
- Role
- Responsibility
- Who Fills This Role
- Incident Commander
- Overall coordination, decision-making
- Senior security official (Director level)
- Technical Lead
- Technical investigation, containment
- IT security specialist
- Communications Lead
- Internal/external communications
- Public relations officer
- Legal Counsel
- Legal advice, compliance
- Government attorney
- Subject Matter Experts
- Domain-specific knowledge
- Relevant specialists (finance, health, etc.)
- When Team Activates:
- Critical incidents: Immediately
- High incidents: Within 1 hour
- Medium incidents: As needed
- Low incidents: Standard procedures
- Response Timeline
- Critical Incidents (Nation-state attacks, major breaches):
- Detection to Containment: 1 hour
- *What Happens*: Identify threat, stop it from spreading
- Containment to Eradication: 24 hours
- *What Happens*: Remove threat completely
- Recovery to Normal Operations: 48 hours
- *What Happens*: Restore systems, verify security
- Post-Incident Review: Within 2 weeks
- *What Happens*: Learn from incident, improve procedures
- High Incidents (Malware, unauthorized access):
- Detection to Containment: 4 hours
- Containment to Eradication: 72 hours
- Recovery to Normal Operations: 1 week
- Post-Incident Review: Within 2 weeks
- Response Steps (for any incident):
- Detection
How was incident discovered?
Automated monitoring, user report, external notification?
Document initial detection
Assessment
What happened?
What systems/data affected?
- Classify severity level
- Containment
- Stop the threat from spreading
- Isolate affected systems
- Preserve evidence
- Eradication
- Remove threat completely
- Patch vulnerabilities
- Clean infected systems
- Recovery
- Restore systems to normal
- Verify security
- Monitor for recurrence
- Lessons Learned
What went well?
What could be improved?
- Update procedures
- Incident Reporting
- Who to Report To:
- IT Security Office: All incidents
- Supervisor: Medium and above
- Senior Management: High and Critical
- Data Protection Authority: Data breaches (within 72 hours)
- Law Enforcement: Criminal activity
- What to Report:
- What happened (description)
- When it happened (timeline)
- Who/what is affected
- What you've done so far
- What help you need
- Reporting Template: ``` INCIDENT REPORT
- Date/Time: [When discovered] Reported By: [Your name and contact] Severity: [Critical/High/Medium/Low]
- DESCRIPTION: [What happened]
- AFFECTED SYSTEMS: [Which systems/data affected]
- ACTIONS TAKEN: [What you've done so far]
- REQUESTED SUPPORT: [What help you need] ```
8.3 Business Continuity Planning
Business continuity planning ensures government operations continue despite email system failures or disruptions. Continuity plans provide alternative communication channels, backup systems, and recovery procedures maintaining essential government functions.
- Continuity Criticality: Email infrastructure is mission-critical for government operations. Business continuity planning ensures:
- Service Continuity: Essential government services continue during disruptions
- Communication Resilience: Alternative channels maintain inter-organizational communication
- Rapid Recovery: Pre-planned procedures accelerate system restoration
- Risk Mitigation: Continuity planning reduces operational and reputational risk
- Continuity Measures
- Backup Email Systems
- What: Secondary email system ready to activate
- Failover Time: 15 minutes
- Capacity: Handle 100% of normal load
- Testing: Quarterly failover drills
- Alternative Communication Channels
- WhatsApp Business: For urgent communications
- SMS: For critical alerts
- Phone: For immediate coordination
- In-Person: When systems completely down
- Work-from-Home Email Access
- What: Procedures for accessing email remotely
- Requirements: VPN access, MFA, secure devices
- Capacity: Support 100% of workforce
- Testing: Regular remote access drills
- Emergency Contact Trees
- What: Lists of who to contact in emergencies
- Structure: Hierarchical (supervisor → department head → ministry head)
- Updates: Quarterly review and updates
- Distribution: Available offline (printed, saved on phones)
- Regular Business Continuity Testing
- Frequency: Quarterly drills
- Types:
- Tabletop exercises (discussion-based)
- Functional exercises (test specific procedures)
- Full-scale exercises (simulate real failure)
- Documentation: After-action reports, improvement plans
- Business Continuity Scenarios
- Scenario 1: Email System Down
- Duration: Up to 4 hours
- Response: Activate backup system
- Communication: SMS alerts to all staff
- Priority: Critical communications via phone/SMS
- Scenario 2: Cyberattack
- Duration: Variable
- Response: Isolate systems, activate backups
- Communication: Secure channels (encrypted messaging)
- Priority: Contain threat, protect data
- Scenario 3: Natural Disaster
- Duration: Days to weeks
- Response: Activate disaster recovery site
- Communication: Satellite phones, radio
- Priority: Restore critical services first
- Scenario 4: Power Outage
- Duration: Hours to days
- Response: Backup generators, remote access
- Communication: Mobile networks, satellite
- Priority: Keep critical systems running
9. Training and Awareness Program
9.1 Mandatory Training Requirements
Human factors represent both the greatest vulnerability and most effective defense in cybersecurity. Technology controls alone cannot prevent all threats; well-trained employees serve as the critical first line of defense. Comprehensive training ensures all personnel possess the knowledge and skills necessary for secure, professional email usage.
- All Government Employees
- Email Security Awareness (Annual)
- Duration: 2 hours
- Content:
- Recognizing phishing emails
- Creating strong passwords
- Using MFA
- Safe email practices
- Reporting security incidents
- Format: Online modules + interactive exercises
- Assessment: Quiz at end (80% pass rate required)
- Certificate: Issued upon completion
- Phishing Simulation Tests (Quarterly)
- What: Fake phishing emails sent to test awareness
- Purpose: Identify employees who need additional training
- Process:
- Send simulated phishing email
- Track who clicks/responds
- Provide immediate feedback
- Require training for those who fail
- Goal: Reduce click rate below 5%
- Data Protection Training (Annual)
- Duration: 1.5 hours
- Content:
- Data Protection Act requirements
- Handling personal data in emails
- Individual rights (access, deletion)
- Data breach procedures
- Format: Online training + case studies
- Assessment: Scenario-based questions
- Professional Communication Skills (Biennial - Every 2 Years)
- Duration: 3 hours
- Content:
- Email etiquette
- Writing clear, professional emails
- Response time standards
- Classification and handling
- Format: Workshop with practice exercises
- Assessment: Write sample emails, peer review
- IT Administrators
- Email System Administration (Annual Certification)
- Duration: 16 hours (2 days)
- Content:
- Server configuration
- User management
- Security settings
- Troubleshooting
- Backup and recovery
- Format: Hands-on training, lab exercises
- Certification: Valid for 1 year, renewal required
- Provider: Vendor-certified trainers
- Cybersecurity Best Practices (Continuous Education)
- Frequency: Monthly updates
- Content:
- Latest threats
- Security patches
- Best practices
- Case studies
- Format: Webinars, newsletters, online resources
- Requirement: Minimum 12 hours per year
- Incident Response Procedures (Semi-Annual)
- Duration: 4 hours
- Content:
- Incident classification
- Response procedures
- Evidence preservation
- Reporting requirements
- Format: Tabletop exercises, simulations
- Assessment: Simulated incident response
- Vendor-Specific Training (As Required)
- When: New systems, major updates
- Content: System-specific features and procedures
- Format: Vendor-provided training
- Requirement: Complete before system goes live
- Senior Officials
- Executive Cybersecurity Briefings (Quarterly)
- Duration: 1 hour
- Content:
- Current threat landscape
- Recent incidents
- Strategic security decisions
- Budget and resource needs
- Format: Presentation by IT Security Office
- Audience: Ministers, Permanent Secretaries, Directors
- Crisis Communication Training (Annual)
- Duration: 4 hours
- Content:
- Communicating during security incidents
- Media relations
- Internal communications
- Stakeholder management
- Format: Workshop with simulations
- Assessment: Crisis communication exercise
- International Communication Protocols (Annual)
- Duration: 3 hours
- Content:
- Diplomatic email protocols
- International data protection requirements
- Cross-border communication best practices
- Cultural considerations
- Format: Workshop with international experts
- Assessment: Scenario-based exercises
- Digital Diplomacy Best Practices (Biennial)
- Duration: 2 days
- Content:
- Representing Malawi digitally
- International email standards
- Building digital relationships
- Managing international communications
- Format: Intensive workshop
- Assessment: Practical exercises
9.2 Awareness Campaigns
Awareness campaigns provide continuous reinforcement of security and professionalism principles beyond formal training sessions. These initiatives maintain security consciousness, reinforce best practices, and adapt to evolving threats through regular communication and engagement.
- Ongoing Initiatives
- Monthly Cybersecurity Newsletters
- Content:
- Latest threats and how to avoid them
- Success stories (caught phishing attempts)
- Tips and best practices
- Upcoming training opportunities
- Format: Email newsletter, also posted on intranet
- Engagement: Include quizzes, prizes for participation
- Phishing Simulation Campaigns
- Frequency: Quarterly (in addition to required tests)
- Variety: Different types of phishing (fake invoices, urgent requests, etc.)
- Feedback: Immediate education when someone clicks
- Tracking: Measure improvement over time
- Security Awareness Posters and Materials
- Locations: Office walls, break rooms, near printers
- Topics:
- "Think Before You Click"
- "Report Suspicious Emails"
- "Use Strong Passwords"
- "Keep Your Email Professional"
- Updates: Refresh quarterly with new threats
- Lunch-and-Learn Sessions
- Frequency: Monthly
- Duration: 30 minutes during lunch
- Topics: Rotating topics (phishing, data protection, email etiquette)
- Format: Informal, interactive
- Attendance: Voluntary but encouraged
- Recognition Programs for Security Champions
- What: Recognize employees who excel at security
- Criteria:
- Caught phishing attempts
- Reported security issues
- Completed all training
- Helped colleagues
- Recognition: Certificates, public acknowledgment, small prizes
- Frequency: Quarterly awards
- Campaign Effectiveness
- Measuring Success:
- Phishing click rates (should decrease)
- Security incident reports (should increase - means people are reporting)
- Training completion rates (target: 95%)
- Employee surveys (satisfaction with training)
- Continuous Improvement:
- Review campaign effectiveness quarterly
- Adjust based on feedback
- Try new approaches
- Learn from other organizations
9.3 Competency Assessment
Competency assessment involves systematic evaluation of employee knowledge, skills, and behaviors related to secure and professional email usage. Regular assessment validates training effectiveness and ensures standards are maintained in practice.
- Assessment Rationale: Training effectiveness requires validation through assessment:
- Knowledge Retention: Assessment confirms learning retention over time
- Practical Application: Evaluation verifies skills are applied in real-world scenarios
- Gap Identification: Assessment results identify areas requiring additional training or support
- Standards Maintenance: Ongoing assessment ensures consistent adherence to standards across the organization
- Regular Evaluations
- Annual Knowledge Assessments
- Who: All employees
- Format: Online quiz covering:
- Email security basics
- Data protection requirements
- Professional communication standards
- Incident reporting procedures
- Pass Rate: 80% required
- Consequences: Retraining required if fail
- Tracking: Results recorded in HR system
- Practical Skills Demonstrations
- Who: Employees in high-risk roles (finance, HR, executives)
- Format:
- Simulated phishing email (can you identify it?)
- Write professional email (does it meet standards?)
- Classify email correctly (do you understand classifications?)
- Frequency: Annual
- Assessment: Pass/fail with feedback
- Phishing Simulation Performance Metrics
- What: Track performance on phishing simulations
- Metrics:
- Click rate (target: <5%)
- Report rate (target: >90% report suspicious emails)
- Improvement over time
- Individual Tracking: Track each employee's performance
- Intervention: Additional training for repeat failures
- Professional Communication Evaluations
- Who: Random sample of employees
- Method: Review actual emails sent
- Criteria:
- Proper formatting
- Professional tone
- Correct classification
- Appropriate response time
- Frequency: Quarterly sample
- Feedback: Individual feedback provided
- Certification Maintenance Tracking
- Who: IT administrators, security personnel
- What: Track certifications and continuing education
- Requirements:
- Maintain vendor certifications
- Complete required continuing education
- Stay current with best practices
- Tracking: Centralized certification database
- Consequences: Loss of admin access if certifications lapse
- Assessment Results and Actions
- Individual Results:
- Provided confidentially to employee
- Include strengths and areas for improvement
- Action plan for improvement if needed
- Aggregate Results:
- Department-level reports
- Ministry-level reports
- Government-wide reports
- Used to identify training needs
- Remediation:
- Additional training for those who fail
- One-on-one coaching if needed
- Re-assessment after remediation
- Escalation if repeated failures
- Recognition:
- Acknowledge high performers
- Share best practices
- Use as examples in training
9. Framework Alignment
This standard contributes to compliance with international frameworks:
- ISO/IEC 27001:2013 – control families A.7, A.8, A.9, A.10, A.13, A.17
- NIST SP 800-53 Rev. 5 – families IA, AC, SC, AT, RA
- Benchmarks – none specific; may reference CIS mail/server guidelines
Refer to `ISO27001_Mapping.md` and `Multi_Framework_Mapping.md` for the complete mapping tables.
10. Appendices
Appendix A: Email Address Examples
Ministry Level:
- `john.banda@finance.gov.mw`
- `mary.mwale@health.gov.mw`
- `peter.phiri@education.gov.mw`
- Department Level:
- `jane.kamanga@accounts.finance.gov.mw`
- `david.chilima@hospitals.health.gov.mw`
- Agency Level:
- `sarah.kumwenda@revenue.gov.mw`
- `michael.mwenda@customs.gov.mw`
- Local Government:
- `lisa.chisale@lilongwe.council.gov.mw`
- `thomas.mphande@blantyre.council.gov.mw`
- Functional Accounts:
- `info@finance.gov.mw`
- `press@health.gov.mw`
- `services@education.gov.mw`
Appendix B: Email Classification Guide
Quick Reference:
- Classification
- Marking
- Encryption
- Who Can Access
- Retention
- OPEN
- `[OPEN]`
- Optional
- Public
- 3 years
- INTERNAL
- `[INTERNAL]`
- Recommended
- Government only
- 7 years
- CONFIDENTIAL
- `[CONFIDENTIAL]`
- Mandatory
- Authorized personnel
- 10 years
- RESTRICTED
- `[RESTRICTED]`
- Mandatory + E2E
- Named individuals
- Permanent
- When to Use Each:
- OPEN: Public announcements, general information, press releases
- INTERNAL: Staff meetings, internal memos, draft documents
- CONFIDENTIAL: Personal data, financial information, policy drafts
- RESTRICTED: National security, legal matters, cabinet decisions
Appendix C: Response Time Quick Reference
Priority Levels:
- Priority
- Acknowledge
- Respond
- Examples
- Critical
- 30 min
- 2 hours
- Security breach, disaster
- Urgent
- 2 hours
- 24 hours
- Ministerial request, complaint
- High
- 4 hours
- 48 hours
- Policy matter, budget
- Normal
- 1 day
- 3 days
- Routine correspondence
- Low
- 2 days
- 5 days
- General inquiry
Appendix D: Security Incident Reporting Form
``` SECURITY INCIDENT REPORT
- Date/Time Discovered: ________________ Reported By: ________________ Contact: ________________ Severity: [ ] Critical [ ] High [ ] Medium [ ] Low
- DESCRIPTION: _________ _________
- AFFECTED SYSTEMS/DATA: _________ _________
- ACTIONS TAKEN SO FAR: _________ _________
- REQUESTED SUPPORT: _________ _________
- ADDITIONAL INFORMATION: _________ _________ ```
- Appendix E: Glossary of Terms
- Authentication: The process of verifying the identity of a user, system, or email sender through credentials, certificates, or other identity proof mechanisms.
- Authorization: The process of determining what actions, resources, or data an authenticated entity is permitted to access based on assigned roles and permissions.
- DMARC: Domain-based Message Authentication, Reporting & Conformance - An email authentication protocol that enables domain owners to publish policies specifying how receiving servers should handle emails that fail SPF or DKIM verification, preventing email spoofing and brand impersonation.
- DKIM: DomainKeys Identified Mail - An email authentication method that attaches cryptographic signatures to email messages, enabling receiving servers to verify message authenticity and integrity using public keys published in DNS.
- Encryption: The cryptographic process of converting plaintext data into ciphertext using algorithms and keys, ensuring confidentiality and preventing unauthorized access to information.
- MFA: Multi-Factor Authentication - A security mechanism requiring multiple independent authentication factors (typically something you know, something you have, something you are) to verify identity, significantly reducing account compromise risk.
- Phishing: Social engineering attacks delivered via email designed to deceive recipients into disclosing sensitive information such as passwords, financial data, or personal information through fraudulent communications appearing to originate from legitimate sources.
- PKI: Public Key Infrastructure - A comprehensive system for managing digital certificates, public-private key pairs, and certificate authorities, enabling secure authentication, encryption, and digital signatures.
- SPF: Sender Policy Framework - An email authentication protocol that enables domain owners to specify which mail servers are authorized to send email on behalf of their domain, preventing email spoofing.
- TLS: Transport Layer Security - A cryptographic protocol providing encryption and authentication for data in transit, ensuring confidentiality and integrity of email communications during transmission.
- Appendix F: Control and Legal Mapping
| Requirement summary | Malawian law (Act, section/regulation) | Framework reference |
|---|---|---|
| Email security; MFA; TLS; retention; breach | Data Protection Act (2024); Electronic Transactions and Cybersecurity Act (2016); FOI | NIST SP 800-53 (AU, SC); CIS; IAM, PKI, Incident Response standards |
- Appendix G: Evidence and Artifact Checklist
- Domain and security: Domain and address governance; SPF/DKIM/DMARC; MFA and TLS; security incident reporting and response.
- Retention and compliance: Retention and archival per FOI/DPA; exception register where applicable (requirement, justification, review/expiry).
- Appendix H: Templates (Minimum)
- The following templates are provided (or referenced) within this document and SHOULD be used as the standard formats:
- Email signature block template (Section 5.1)
- Acknowledgement and escalation templates (Section 5.2)
- Security incident report form (Appendix D)
- Exception request content requirements (Section 6.5)
References
Data Protection Act No. 3 of 2024 (Malawi).
Electronic Transactions and Cybersecurity Act (2016) (Malawi).
Freedom of Information Act (Malawi).
Malawi Government IAM Standards (MFA, SSO/Boma Auth, identity lifecycle).
Malawi Government PKI and Certificate Management Standards (TLS, S/MIME, certificates).
Malawi Government Secrets Management Standards (credentials, no secrets in config).
Government Server Security Haerdening Standards (server-level security baseline).
Malawi Government Incident Response Standards (security incident handling and reporting).
Malawi Government Backup and Recovery Standards (email archival and retention).
Malawi Government Logging and Evidence Management Standards (audit and retention of email-related logs).
African Union Convention on Cyber Security and Personal Data Protection (AUCC).
SADC Model Law on Data Protection and SADC data protection standards.
