IRR of REPUBLIC ACT NO. 12254 IMPLEMENTING RULES AND REGULATIONS OF THE E-GOVERNANCE ACT (REPUBLIC ACT NO. 12254) March 24, 2026
[ IRR of REPUBLIC ACT NO. 12254, March 24, 2026 ]
IMPLEMENTING RULES AND REGULATIONS OF THE E-GOVERNANCE ACT (REPUBLIC ACT NO. 12254)
Pursuant to Section 38 of Republic Act (R.A.) No. 12254, otherwise known as "An Act Institutionalizing the Transition of the Government to E-Governance, Strengthening the ICT Academy, and Appropriating Funds Therefor" (Act), the following Implementing Rules and Regulations, hereinafter referred to as the IRR, are hereby promulgated:
RULE I
GENERAL PROVISIONS
SECTION 1.Title.- This IRR shall be known as the "2026 Implementing Rules and Regulations of the E-Governance Act".
SECTION 2.Declaration of Policy.- The State recognizes the vital role of information and communication in nation-building and the necessity of leveraging the power of information and communications technology (ICT) to drive national development and progress.
The State hereby adopts a policy to establish, foster, and sustain a digitally empowered and integrated government through the implementation of a regulated, secure, and robust information and communication system aimed at facilitating responsive and transparent online citizen-centered services, thereby optimizing the potential of open data for promoting economic growth while balancing the rights to freedom of information and data privacy of every Filipino.
SECTION 3. Purposes and Objectives. - The purposes and objectives of this IRR are to:
| (a) | define the roles and responsibilities of various agencies in the entire digital transformation process and provide effective leadership in developing and promoting electronic government services and processes; |
| (b) | promote interoperability of government systems and processes through a consolidated process architecture, while allowing government agencies, offices, and instrumentalities to implement the proper controls and safeguards deemed appropriate on ICT and information assets; |
| (c) | provide citizen-centered government information and services, and improve public trust and citizen participation in the government; |
| (d) | enable access to government information and services, in accordance with the Constitution and relevant laws, while leveraging ICT and emerging technologies to enhance process efficiency, data security, and overall effectiveness; |
| (e) | strengthen transparency and accountability efforts of the national and local governments; |
| (f) | foster an informed and data-driven decision-making process for policymakers by utilizing data analytics results, among other pertinent factors; |
| (g) | strengthen resilience against information technology disruptions, including, but not limited to, cybersecurity attacks, by incorporating best practices both from public and private sectors, locally and internationally; |
| (h) | promote electronic transactions, particularly where mobility of citizens is restricted during disasters or pandemics; |
| (i) | foster job creation, promote sustainability, and ensure up-to-date qualification and competency standards of ICT positions within the government; |
| (j) | encourage sustainability and fortify manpower capabilities by continuously upskilling ICT professionals through the Academy; and |
| (k) | reduce costs and burdens for businesses and other government entities. |
| (a) | back-end government operations within, between, and across agencies; |
| (b) | government-to-government transactions, particularly those involving sharing and processing of data and information between and among government agencies for policy, planning, and decision-making purposes; and |
| (c) | other similar government operations. |
| (a) | Application Programming Interface (API)refers to an intermediary that allows interaction between applications, programs, software components, systems, hardware, and micro-services of different individuals or organizations; | |
| (b) | Blockchainis a shared, immutable ledger that facilitates the process of recording transactions and tracking tangible or intangible assets in a business network, where virtually anything of value can be tracked and traded, reducing risk and cutting costs for all involved; | |
| (c) | Change managementrefers to the deliberate and structured approach to transitioning individuals, teams, and organizations from a current state to a desired future state of organizational success; | |
| (d) | Chief Information Officer (CIO)refers to a senior government official responsible for the development, planning, and implementation of the government entity's Information System Strategic Plan (ISSP) or ICT plan, and management of the agency's ICT systems, platforms, and applications; | |
| (e) | Chief Information Security Officer (CISO)refers to the individual or entity responsible for carrying out functions and responsibilities relevant to cybersecurity in a government agency and who serves as the primary liaison of the agency to the Sectoral Computer Emergency Response Team and the National CERT. The CISO ensures that information resources and technologies are effectively protected; oversees the development, implementation, and enforcement of cybersecurity policies; and works alongside the CIO in procuring cybersecurity products and services, and managing disaster recovery and business continuity plans; | |
| (f) | ComputerEmergency Response Team(CERT)orComputer Security Incident ResponseTeam(CSIRT)refers to a specialized group responsible for preventing, detecting, analyzing, responding to, and assisting in recovering from cybersecurity incidents and threats that affect information and communication systems at the organizational, sectoral or national level, providing advisory services, vulnerability analysis, threat intelligence dissemination, and coordinated incident response across multiple stakeholders; | |
Agency CERT refers to a CERT of a government agency while Sectoral CERT refers to a CERT at the sectoral level and which coordinates with Agency CERTs. | ||
National CERT (NCERT) refers to the CERT organized and managed by the DICT as the central coordinating body for all Agency and Sectoral CERTs; | ||
| (g) | Common Data Setsrefers to standardized collections of data elements that are uniformly defined, structured, and shared across multiple systems, organizations, or sectors to ensure interoperability, consistency, and data quality; | |
| (h) | Critical Information Infrastructure (CII)refers to the computer systems and/or networks, whether physical or virtual, and/or the computer programs, computer data, and/or traffic data that are vital to this country that the incapacity, destruction, or interference with such system and assets would have a debilitating impact on security, national or economic security, national health and safety, or any combination of those matters.-Government sectors initially classified as CIIs are the following: transportation (land, sea, air), energy, water, health, emergency services, public finance, banking and finance, business process outsourcing, telecommunications, space, and media; | |
| (i) | Digitalizationrefers to the process of using digital technologies to enhance the operations of the government, and provide new revenue and value-producing opportunities; | |
(j) | Digital Transformationrefers to the process of optimizing, reconstructing, and integrating digital technology into all areas of government to maximize resource configuration, improve operational efficiency and innovation capability, and enhance value delivery of stakeholders; | |
| (k) | E-Governancerefers to the use of ICT by the government to provide public services in a more friendly, convenient, affordable, efficient, and transparent manner. Further, it is the application of ICT for delivering government services through integration of various stand-alone systems, platforms, and applications between Government-to-Citizens (G2C), Government-to-Businesses (G2B), and Government-to-Government (G2G) services. It is often linked to back-office processes and interactions within the entire government framework; | |
| (l) | E-Governmentrefers to the use of ICT by the government to enhance access to and delivery of government services for an efficient, responsive, ethical, accountable, and transparent government; | |
| (m) | Emerging technologiesrefers to rapidly developing technologies that are generally new, or current technologies finding new applications, whose development, practical applications, and impact are still uncertain. They are often perceived as disrupting the status quo and allowing for innovative solutions, such as in government service delivery. Emerging technologies shall include, but shall not be limited to, artificial intelligence, quantum computing, blockchain, autonomous systems, and similar innovations with similar characteristics; | |
| (n) | Enterprise Architecturerefers to the structured framework that defines the principles, standards, and integrated design of government business processes, information flows, data assets, applications, and technology infrastructure. It provides a coherent blueprint that guides agencies in planning, implementing, and governing digital systems to ensure interoperability, security, efficiency, and alignment with national digital government objectives; | |
| (o) | Government JCT workersrefers to government personnel performing ICT-related functions such as but not limited to systems and infrastructure development, implementation and maintenance, cybersecurity, data governance, data privacy, ICT Policy and Planning, and other ICT matters. Personnel of the EGov Unified Project Management Office (EGov UPMO), and government personnel designated as CIOs, CISOs, and working at CERTs/ CSIRTs shall also be considered as government ICT workers; | |
| (p) | Government Internet Protocol Exchange (GIIPX)refers to a secure, managed, and interoperable IP-based network infrastructure established to connect, integrate, and facilitate data exchange among government agencies; | |
| (q) | JCT Assetsrefer to any data, device, equipment, infrastructure, system, or component thereof, utilized to ensure or support the proper efficient operation and implementation of JCT-related programs and delivery of ICT services; | |
| (r) | JCT Planrefers to the sum of set of goals, measures, strategies, agenda, budget, and timeline for the implementation of ICT programs and projects and the use of ICT, including digital platforms, to deliver public services or otherwise perform government functions; | |
| (s) | Information and Communications Technology (JCT)refers to the totality of electronic means to access, create, collect, store, process, receive, transmit, present, regulate, and disseminate information; | |
| (t) | Information Securityrefers to the preservation of confidentiality, integrity and availability of information. This may also involve other properties, such as authenticity, accountability, non-repudiation, and reliability of information. For the purposes of this IRR, "cybersecurity" refers to the protection of ICT systems, networks, applications, and data in cyberspace, and is a subset of "information security"; | |
| (u) | Information Security Standards (ISS)refer to generally accepted cybersecurity standards which aim to protect and secure the confidentiality, integrity, availability, authenticity, and non-repudiation of information; | |
| (v) | Information Systems Strategic Plan (ISSP)refers to the three (3)-year plan that serves as the government entity's roadmap for using ICT as a strategic resource to support the attainment of its goals, mission, and vision. It is also a written expression that aims to coordinate national ICT plans, efforts, knowledge, information, resource-sharing, and database-building, and to link a government entity's ISSPs with national ICT goals; | |
| (w) | Interoperabilityrefers to the ability of different operating and software systems, applications, and services to communicate and exchange data in an accurate, effective, and consistent manner with different platforms and agencies; | |
| (x) | Major or material information security incidentrefers to a single event or a series of unwanted or unexpected events whose nature and scope are determined to have or likely to have a significant impact on a government agency's network, such as causing the stoppage, disruption, or degradation of operations or compromising the integrity, confidentiality, or availability of the information transmitted within its network; | |
| (y) | Master datarefers to the original, authoritative dataset validated and maintained by the government agency, also known as the "parent agency," that has the statutory mandate to collect, generate, and safeguard such data. Master data shall include, but is not limited to, civil registry records, national identification data, business registration data, taxpayer records, land records, and social security data; | |
| (z) | Nonbusiness-related transactionrefers to all other government transactions not falling under Section 4(c) of R.A. No. 11032 or the "Ease of Doing Business and Efficient Government Service Delivery Act of 2018"; | |
| (aa) | Once-Only principlerefers to the approach ensuring that citizens and business entities only need to submit certain information and documents once when applying for government and public services. This entails government agencies re-using and sharing data with each other; | |
| (bb) | Open Datarefers to data that can be freely used, reused and redistributed by anyone, subject to proper attribution and sharing; | |
| (cc) | Personal datarefers to all types of information pertaining to an individual including personal information, sensitive personal information, and privileged information, as defined under R.A. No. 10173 or the Data Privacy Act (DPA) and its IRR; | |
| (dd) | Personal informationrefers to any information whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual; | |
| (ee) | Personal Information Controller (PIC)refers to any natural or juridical person who controls the collection, holding, processing or use of personal data, including a person or organization who instructs another person or organization to collect, hold, process, use, transfer or disclose personal data on his or her behalf. The term excludes: | |
(1) | A person or organization who performs such functions as instructed by another person or organization; and | |
(2) | An individual who collects, holds, processes or uses personal data in connection with the individual's personal, family or household affairs. | |
| (ff) | Personal information processor(PIP) refers to any natural or juridical person qualified to act as such under the DPA to whom a PIC may outsource the processing of personal data; | |
| (gg) | Public Key Infrastructure (PKI)refers to the framework of policies, technologies, and procedures used to create, manage, distribute, use, store, and revoke digital certificates and public-key encryption. PKI enables secure electronic transactions, authentication, confidentiality, integrity, and non-repudiation of data and communications across digital networks; | |
| (hh) | Privacy-by-Defaultrefers to the principle according to which the PIC and PIP ensures that only data necessary for each specific purpose of processing is processed by default, without the intervention of the data subject; | |
| (ii) | Privacy-by-Designrefers to an approach to the development and implementation of projects, programs, and processes that integrate into the design or structure safeguards that are necessary to protect and promote privacy into the design or structure of a processing activity or a data processing system; | |
| (jj) | Privacy Engineeringrefers to the integration of privacy concerns into engineering practices for systems and software engineering life cycle processes; | |
| (kk) | Privacy Impact Assessment (PIA)refers to the process undertaken and used to evaluate and manage impacts on privacy of a particular program, project, process, measure, system or technology product of a PIC or PIP. It takes into account the nature of the personal data to be protected, the personal data flow, the risks to privacy and cybersecurity posed by the processing, current data privacy best practices, the cost of cybersecurity implementation, and, where applicable, the size of the organization, its resources, and the complexity of its operations; | |
| (ll) | Underserved areasrefer to areas that have unreliable and inadequate ICT services, as may be defined by the Department of Information and Communications Technology (DICT); | |
| (mm) | Unserved areasrefer to areas that do not have data transmission industry participants and ICT services, as may be defined by the DICT; | |
| (nn) | Vulnerability Assessment and Penetration Testing (VAPT)refers to a comprehensive cybersecurity evaluation process used to identify, analyze, and address weaknesses or vulnerabilities in an organization's information systems, networks, applications, and infrastructure. |
| (a) | Policy Formulation, Strategic Governance and Implementation. | |
(1) | adopt national policies and processes that promote innovation, support start-ups, and facilitate the entry and adoption of technologies consistent with the objectives of the Act and this IRR; | |
(2) | mandate and guide the adoption of policies and processes necessary for the implementation of the Act and this IRR, including the formulation of a strategic and phased whole-of-government E-Government roadmap with clearly defined milestones, roles, and responsibilities; | |
(3) | pursuant to Section 10 of the Act, conduct a mandatory PIA, in accordance with relevant issuance of the National Privacy Commission (NPC), on the proposed systems for processing personal data included in the EGMP before its publication; | |
(4) | ensure that all E-Government Programs comply with data privacy laws, and, when necessary, formally seek and incorporate guidance and assistance from the NPC on matters concerning the security and protection of personal data; | |
(5) | on its own, or through other public or private entities, conduct research, surveys, and related studies to inform the formulation of E-Governance policies and plans, and the design of programs and projects, ensuring these are impartial, objective, and evidence-based; and | |
(6) | prescribe the necessary measures, obligations, and standards to ensure the cybersecurity and resilience of CII that are essential for the operation and maintenance of critical government institutions. | |
| (b) | ICT Infrastructure, Systems, and Standards Oversight | |
(1) | establish the EGov UPMO in accordance with Section 7 of the Act; | |
(2) | oversee and guide the operation of ICT infrastructure, systems, and facilities in accordance with applicable laws and rules, including on cybersecurity; | |
(3) | guide, monitor, and support government agencies in ensuring the quality, cybersecurity, reliability, and interoperability of ICT infrastructure and services in accordance with applicable standards and best practices, and provide necessary training, certification, and advisory support; and | |
(4) | engage technical and standards organizations and consult industry experts on matters requiring specialized engineering, enterprise architecture, and cybersecurity other technical expertise. | |
| (c) | Inter-Agency Coordination and Public-Private Collaboration | |
(1) | coordinate and collaborate with government agencies and the private sector, including through partnerships and joint ventures, to promote innovation and technology transfer and in furtherance of the objectives of the Act and this IRR; and | |
(2) | receive grants and donations for the implementation of the Act subject to pertinent provisions of R.A. No. 3019 or the "Anti-Graft and Corrupt Practices Act", R.A. No. 6713 or the "Code of Conduct and Ethical Standards for Public Officials and Employees" and other relevant laws. | |
| (d) | ICT Human Resource Development and Competency Standards | |
(1) | in coordination with the Civil Service Commission (CSC), mandate compliance by Covered Entities with minimum qualification and competency standards for all government ICT positions and require regular reporting on the status of compliance; and | |
(2) | through the Academy, develop, in accordance with applicable civil service laws and rules, consistent with the compensation and position classification system of the government, the competency and qualification standards for all government ICT positions. | |
| (e) | Inclusive and Accessible E- Government | |
(1) | ensure, as far as practicable, that E-Government Programs and platforms are inclusive and accessible to persons with disabilities. | |
| (f) | Monitoring, Compliance and Performance Assessment | |
(1) | develop Performance Score Cards on the compliance of Covered Entities; and | |
(2) | monitor implementation of E-Government programs and ISSPs to ensure alignment with the EGMP and its integrated framework. |
| (a) | oversee, monitor, and provide technical guidance on the planning, execution, timeliness, performance and resource utilization of all government ICT projects and programs; |
| (b) | ensure that the entire portfolio of E-Government Programs is aligned with the EGMP, the Philippine Government Interoperability Framework (PGIF), and other relevant national ICT plans, policies, and frameworks; |
| (c) | prescribe and require compliance with internationally recognized best practices and standards in project, program, and portfolio management including but not limited to risk management, quality assurance, benefits realization, and change management; and |
| (d) | coordinate with the Academy to ensure the systematic development and regular delivery of courses, including multimodal training and certification programs, and to implement capacity-building initiatives that enhance the skills, knowledge, and technical expertise of EGov UPMO and other DICT units responsible for the development and implementation of the Act. |
The Academy Act shall provide guidelines on the minimum qualifications for such certifications and competency standards for EGov UPMO personnel in accordance with Section 44 of this IRR.
SECTION 10.Transition of Existing DICT Offices to the EGov UPMO.- During the transition period, the DICT shall designate qualified existing personnel and an existing office with substantially similar or related functions to perform, on an interim basis, the functions of the EGov UPMO. Such qualified existing personnel may be designated based on competencies despite lacking the required certifications, provided they secure the necessary certifications within one (1) year from the date of assumption to the position. The DICT Secretary, may, for justifiable reasons and subject to existing laws, rules, and regulations, extend the period for compliance. This arrangement shall be without prejudice to any subsequent reorganization, reconstitution, or reappointment in accordance with the final guidelines to be issued. The DICT shall allocate to the EGov UPMO the funds necessary to carry out this purpose.SECTION11.Interagency Agreements for Implementation of E-Government Programs.-The DICT may enter into service agreements, memoranda of agreement, or other similar inter-agency arrangements with Covered Entities. Such arrangements may be undertaken through agency-to-agency procurement, inter-agency cooperation, or similar mechanisms, where the DICT is mandated by law or possesses the requisite technical capability, infrastructure, or institutional competence to deliver the required ICT systems, platforms, or services, consistent with the R.A. No. 12009 or the "New Government Procurement Act" (NGPA), and applicable issuances of the DBM and the Commission on Audit (COA).
SECTION 12.Collection of Fees.- In accordance with Section 33 of the Act, the DICT may collect reasonable fees from authorized sources for services directly related to the implementation, operation, and sustainability of the E-Government Programs, such as issuance of certifications or technical clearances expressly permitted by law, access to shared or common digital platforms, interoperability and data-exchange services, API access, hosting and cloud computing services, and cybersecurity services related to E-Government Programs and government CII. All fees collected shall accrue to the E-Government Interoperability Fund and shall be subject to existing budgeting, accounting, and auditing rules and regulations.Fees, reimbursements, cost-sharing amounts, or fund transfers arising from services rendered or service agreements entered into under Section 11 shall be reasonable and sufficient to defray the minimum costs of providing the service and shall consider, among others, the available budget of the Covered Entity, operational and maintenance costs, cost recovery, cybersecurity requirements, system enhancements, cloud subscriptions, software licenses, and such other expenses necessary for the effective implementation of the E-Government Programs.
The DICT shall issue and publish guidelines for determining the fees, including any subsequent revisions thereto, through appropriate issuances and posting on its official website, and shall, where applicable, coordinate with the DBM, DOF, COA, and other concerned agencies prior to implementation, in accordance with existing laws, rules, and regulations. The Schedule of Fees shall be reviewed periodically and adjusted as necessary.
SECTION 13. Performance Scorecards, Compliance Certification,and Public Disclosure. -
| (a) | PerformanceScorecards.The DICT shall develop, maintain, and periodically update a standardized E-Govemance Performance Scorecard to assess the level of compliance of Covered Entities with the requirements of the Act, this IRR, and related DICT issuances. The Performance Scorecard shall be aligned with the EGMP, E-Government Development Index (EGDI), and applicable standards, and may include, among others, indicators on: | |
(1) | compliance with prescribed ICT, interoperability, cybersecurity, and data privacy standards; | |
(2) | implementation status of required E-Government Programs; | |
(3) | quality, accessibility, and availability of digital public services; | |
(4) | institutional readiness, including governance, human capital, and ICT planning; and | |
(5) | timeliness and accuracy of required reports and submissions to the DICT. | |
The Performance Scorecards shall only be advisory in nature. | ||
| (b) | Certification of Compliance.Based on validated submissions from Covered Entities, and audits, assessments or monitoring activities, the DICT may issue the following certifications: | |
(1) | Certificate of Compliance, indicating that a Covered Entity has substantially complied with applicable requirements, standards, and timelines under the Act, this IRR, and relevant DICT issuances; or, | |
(2) | Certificate of Non-Compliance, indicating material gaps, deficiencies, or failures to comply with required standards, obligations, and corrective actions and compliance timelines, when necessary. Prior to issuance of such Certificate of Non-Compliance, DICT shall provide the Covered Entity a written notice of findings and a period of not less than fifteen (15) working days upon receipt of notice to respond with corrective actions or clarifications. | |
| (c) | Publication and Transparency.Subject to applicable laws on data privacy, confidentiality, and national security, the DICT may publish Performance Scorecards and any certifications issued to Covered Entities under this Section through official government websites, dashboards, or reports, for purposes of transparency, benchmarking, and public accountability. |
THE E-GOVERNMENT MASTER PLAN, PROGRAMS AND SYSTEMS
SECTION14.E-Government Master Plan (EGMP).- The DICT shall formulate and promote an EGMP or its equivalent that will serve as a blueprint for the development and enhancement of all electronic government service processes and workforce to achieve digital transformation in the bureaucracy, taking into consideration the Philippine Development Plan. The EGMP shall serve as the sole and overarching national roadmap for the development, harmonization, and enhancement of all electronic government programs, systems, platforms, and digital services.
An Integrated Framework shall also be developed to provide the government enterprise architecture and operationalize the blueprint through programs and projects relating to E-Government, to fully realize the vision, goals, and objectives of the EGMP. The Integrated Framework shall also set forth the guidelines for the government Enterprise Architecture, and implementation roadmap to ensure coherence, efficiency, and alignment of all government ICT systems and platforms.
The EGMP and its integrated framework shall include core governance principles for the responsible deployment of emerging technologies, by mandating adherence to principles of transparency, accountability, and robustness in all E-Government programs. To ensure effective implementation of E-Governance, a whole-of-government approach shall be adopted in the formulation and promotion of the EGMP. This approach shall facilitate engagement primarily with government agencies, instrumentalities, GOCCs, LGUs, Regional Development Councils, ICT Councils, technical and standards organizations, and other relevant stakeholders to ensure the full and effective implementation of the country's E-Governance Agenda.
The DICT shall formulate, adopt, and publish the EGMP and its Integrated Framework within ninety (90) days from the effectivity of this IRR, and shall review and update the same every three (3) years or earlier as the need arises, in anticipation of disruptions, emergencies, crises, and new and emerging technologies.
SECTION15.E-Government Programs.- The DICT, in coordination with relevant government agencies, shall develop the following programs and systems that will be regularly updated in consultation with stakeholders and ensure that such programs and systems are compliant with standards imposed by relevant laws, rules, and regulations relating to data privacy and cybersecurity. All E-Government Programs, platforms, and digital systems shall be designed, enhanced, and implemented strictly in accordance with the EGMP and shall comply with the PGIF. No E-Government Program shall introduce an independent framework, architecture, roadmap, or standards regime inconsistent with, or supplementary to, the EGMP or PGIF.Covered Entities, with frontline services, shall be required to establish and maintain an information system dedicated to the delivery of their respective frontline services. Such systems shall enable citizens to access, request, and track frontline transactions electronically and shall conform to the minimum standards set by the DICT.
Covered Entities that already operate existing information systems or digital platforms for frontline services shall, within one hundred eighty (180) days from the effectivity of the rule prescribing minimum standards, file an application for integration with the DICT to connect to the eGovPH SuperApp.Covered Entities that do not yet have an operational information system for frontline delivery shall, within the same one hundred eighty (180) day period, include the development and deployment of such a system as a priority project in their respective ISSPs, to be submitted to and approved by the DICT and DBM. The ISSP shall outline the implementation timeline, funding requirements, and institutional arrangements necessary for integration into the eGovPH SuperApp.
Pending the development of a full information system, Covered Entities shall at least maintain an official website capable of publishing public information, downloadable forms, and clear instructions for accessing frontline services. This website shall comply with DICT's web, accessibility, and cybersecurity standards, and shall serve as the initial entry point for future integration into the eGovPH SuperApp.The DICT shall monitor and evaluate agency compliance with these requirements and may issue technical advisories, compliance directives, or non-compliance notices as necessary. The DICT shall periodically review and update the minimum standards to reflect emerging technologies, evolving interoperability needs, and international best practices.
SECTION 15.2.Electronic Local Government Unit (eLGU) System.- Within one (1) year from the effectivity of this IRR, the DICT and Department of the Interior and Local Government (DILG) shall develop, adopt, and publish a Local Government Digital Service Standard (LGDSS) that shall define the minimum set of digital public services which all LGU systems or portals must provide. The LGDSS shall serve as a uniform benchmark to ensure consistency, accessibility, interoperability, and efficiency in the delivery of local digital services across all levels of local governance. At a minimum, the LGDSS shall cover business and investment-related services, such as the processing of business permits, clearances, and licenses; revenue and taxation services, including assessment and payment of real property tax, business tax, and other local fees; civil registry services, including applications and issuances related to birth, marriage, and death certificates; citizen request and feedback mechanisms; and other frontline services as may be determined by the DICT, the DILG - Bureau of Local Government Development, and the Department of Finance (DOF) - Bureau of Local Government Finance (BLGF), consistent with the LGU's Citizen's Charter, the EODBA, and other applicable laws, rules and regulations.LGUs that opt to develop, maintain or utilize their own eLGU systems or portals must demonstrate full compliance with the LGDSS as a prerequisite for certification and recognition by the DICT. Such LGU-utilized systems shall undergo technical validation by the DICT to ensure full interoperability and API-based integration with the national CFDSP, compliance with applicable data privacy, cybersecurity, and interoperability standards prescribed under the EGMP, and adherence to user-centered design and accessibility standards consistent with international best practices. For systems involving revenue generation, the validation shall be conducted in coordination with the BLGF to ensure compliance with fiscal policies.
Only those LGUs certified as fully compliant with the LGDSS and integrated with the eGovPH SuperApp shall be deemed compliant with the requirements of the Act and this IRR. LGUs that fail to establish or integrate compliant systems within the prescribed period shall be required to fully adopt the DICT-provided eLGU system, for which the DICT shall provide the necessary software, infrastructure, and technical assistance to ensure continuity of digital services to the unserved or underserved municipalities.
The DICT shall periodically review and update the LGDSS at least once every two (2) years from the effectivity of this IRR, or as necessary to reflect technological advancements, user feedback, and evolving digital governance priorities.
SECTION 15.3.Government Digital Payment System for Collection and Disbursement.- An electronic payment facility and gateway that will enable citizens and businesses to remit and receive payments electronically to or from government agencies shall be created. It shall render services through various delivery channels, which include debit instructions (ATM accounts), credit instructions (credit cards), and mobile wallets (mobile applications/SMS). For this purpose, the government may, in accordance with applicable laws and rules, engage the services of, and interconnect with, public and private payment systems and facilities, among others, consistent with the National Retail Payment System Framework of the Bangko Sentral ng Pilipinas (BSP).
These systems should interface smoothly with the current monitoring and accounting systems of the National Treasury.
Covered Entities are hereby encouraged to adopt and utilize the Government Digital Payment System currently known as "eGovPay" as established by the DICT for the electronic collection and disbursement of government payments. Covered Entities that have previously implemented or currently maintain their own digital or electronic payment platforms may continue to operate such systems; Provided, That they shall ensure full technical interoperability and secure interconnection with E-Government Programs, platforms, and services, including those under the EGMP. For purposes of alignment and integration, all Covered Entities shall coordinate with the DICT to facilitate system interconnection, integration, and compliance with standards.
The technical standards, implementation protocols, and operational guidelines governing the Government Digital Payment System shall be jointly formulated and issued by the DICT, the Bureau of the Treasury (BTr), the DOF-BLGF and the COA, consistent with their respective mandates, and shall be promulgated within one hundred twenty (120) days from the effectivity of this IRR to ensure uniform adoption, transactional integrity, audit compliance, transparent monitoring, real-time reconciliation, and seamless interconnectivity with government treasury systems, accounting platforms, and the whole-of-government digital payment ecosystem.
SECTION 15.4.Government Public Key Infrastructure (PKI) Program.- The DICT shall encourage and promote the use of Government PKI digital certificates that allow paperless transactions and remote approval by signatories in the government to reduce red tape and enforce ease of doing business. The adoption of PKI aims to strengthen E-Government cybersecurity through its implementation in all government offices and supply of digital certificates to the citizens. The Government PKI Program known as the Philippine National PKI (PNPKI) shall serve as the official Government PKI system that issues PKI digital certificates to ensure the security of digital data and transactions by providing:
(a) | Authentication- to verify the identity of users and prevent unauthorized access to information and systems; |
(b) | Confidentiality- to ensure that electronic data and communications are accessible only to authorized parties; |
(c) | Integrity- to ensure that electronic data and messages remain complete, accurate and unaltered during transmission and storage; and |
(d) | Non-repudiation- ensure that parties to an electronic transaction cannot deny their participation or actions. |
Covered Entities are encouraged to adopt and utilize the national HCMIS established pursuant to this IRR, subject to system readiness and capacity of the concerned agency. The DICT and CSC may utilize, co-develop, and enhance the existing HCMIS of the CSC provided it complies with the minimum standards defined under the Act and this IRR. The CSC and the DICT shall jointly issue and promulgate the minimum technical, data governance, cybersecurity, and operational standards for system implementation and integration within ninety (90) days from the effectivity of this IRR. Compliance with these standards shall be mandatory for all HCMIS implementations across government, without prejudice to enhanced system features adopted by agencies consistent with their mandates.
SECTION 15.6.Integrated Financial Management Information System (IFMIS).- To ensure fiscal discipline, fund allocation efficiency, and operational efficiency in the delivery of public services, an IFMIS shall be jointly developed by the DBM, DOF, COA, and DICT. This shall harmonize all existing financial systems in government to enable real-time, online accounting monitoring, and control of obligations and disbursements and directly link these to cash management for a more effective financial control and accountability. This shall facilitate the generation and monitoring of vital information on all aspects of government financial transactions to support timely and informed decisions across the bureaucracy.
Covered Entities are encouraged to adopt and utilize the IFMIS established pursuant to the law and this IRR, subject to system readiness and capacity of the concerned agency. The DICT and CSC may utilize, co-develop, and enhance the existing IFMIS of the DBM provided it complies with the minimum standards defined under the law and this IRR. The DBM, DOF, COA, and DICT shall jointly develop and promulgate the minimum technical, cybersecurity, data governance, and operational standards for IFMIS implementation within ninety (90) days from the effectivity of this IRR.
SECTION 15.7.Integrated Government Network (IGN).- Covered Entities that maintain existing internal or legacy networks, or those operating networks pursuant to their respective charters with fiscal and administrative authority, may continue to independently develop, operate, and maintain such networks; Provided, That they ensure continuing interoperability with the IGN, comply with national cybersecurity and information security standards, and submit network interoperability compliance reports to the DICT for policy and Enterprise Architecture alignment.Covered Entities are encouraged to adopt and utilize the IGN once operational.
The DICT shall issue the guidelines for the operation, use, management, resiliency, incident response, and administration of the IGN, including the governance of the Government Internet Protocol Exchange (G/IPX) Facility, within one hundred twenty (120) days from the effectivity of this IRR.For purposes of this IRR, the IGN will cover the following:
(a) | the orderly turnover, integration, and transition of the existing Government Internet Protocol Exchange (G/IPX) facilities into the IGN architecture, including the mandatory connection, interconnection, or peering of all relevant government agencies and government networks to the designated G/IPX, consistent with the interoperability and unified traffic exchange framework for government networks; |
(b) | the establishment and operationalization of a Network Information Center (NIC) within the DICT to administer, manage, allocate, secure, and maintain all government IP resources; |
(c) | the acquisition, administration, and management of IP address blocks, internet number resources, and related allocations from APNIC and other authorized global numbering registries; |
(d) | the mandatory adoption and phased migration to the latest Internet Protocol versions, secure DNS and domain name administration standards for the .gov.ph domain, and the deployment of modern cryptographic protocols, including but not limited to TLS and SSL, to strengthen network resiliency and cybersecurity posture across all government entities; and |
(e) | formal and sustained coordination, engagement, and collaboration with internet governance bodies such as The Internet Corporation for Assigned Names and Numbers, Internet Assigned Numbers Authority, Asia Pacific Network Information Centre, and other international organizations to ensure alignment with internationally recognized norms, protocols, and best practices in resource management and interoperability. |
The DICT shall promulgate supplemental technical guidelines, certification requirements, implementation schedules, interoperability specifications, compliance mechanisms, and other necessary regulatory issuances to fully operationalize the IGN and to ensure secure, efficient, scalable, future-proof, and standards-aligned interconnection across all government networks and platforms, consistent with evolving global internet governance principles and emerging technologies. The operation of the IGN and the NIC shall be subject to periodic independent technical, cybersecurity, and information security audits, in accordance with standards prescribed by the DICT.
SECTION 15.8.Online Public Service Portal.- Complementing the CFDSP, an Online Public Service Portal shall be made accessible through digital platforms such as the internet and other ICTs to citizens of the Philippines; foreign nationals who have been lawfully admitted to the country; and businesses organized and existing or operating under the laws and rules of the Philippines for purposes consistent with efficient delivery of public services. The Online Public Service Portal shall serve as a help desk where citizens can request for information and assistance on government frontline services, service procedures, and report commendations, appreciation, complaints, and feedback.(a) | Domain 1 - establishes the overall principles and key standards that would enable systems to communicate with one another through the linkage of JCT systems and services among government agencies. It shall include the Technical Standards Catalogue, which shall constitute a structured collection of standards, specifications, and guidelines for interoperability requirements. |
(b) | Domain 2 - establishes the common methodology, definition, and structure for data and information, along with shared services for its management throughout its lifecycle. |
(c) | Additional Domains - additional domain(s) that form part of the government interoperability may be developed or issued in the future for government wide application to ensure proper consolidation, coherence, and continuous updating of the framework and its technical standards. |
SECTION 16.National E-Government Development Index (EGDI).- The DICT, in coordination with other government agencies, shall establish a national EGDI to serve as the unified metric for assessing and monitoring the progress of E-Government development in the country. The EGDI shall provide a framework for internal assessment and external benchmarking against global standards.
The EGDI shall be the composite measure, consistent with international best practices, of the three important dimensions of E-Government, namely: online service index, telecommunication infrastructure index, and human capital index, and shall adopt globally competitive indicators, definitions, and statistical standards.(a) | must contain direct and easily identifiable links to: (i) description of the mission, statutory authority, and the organizational structure of the agency; and (ii) frequently asked questions (FAQs) with the corresponding answers, and other common matters of public concern; and (iii) portals of relevant and applicable E-Government Programs for public service delivery; |
(b) | must provide access to public information via an API; |
(c) | subject to compliance with the DPA, must include up-to-date government directory containing the contact information, such. as emails and telephone numbers, of the offices and officials of the Covered Entity; |
(d) | must comply with the Philippine Web Accessibility policy, or any relevant issuance from the DICT; |
(e) | must provide a real-time citizen feedback mechanism integrated into all E-Government platforms to allow users to rate services, provide comments, and report issues directly. Data from this mechanism shall be publicly aggregated and published quarterly to ensure transparency and guide service improvements; |
(f) | must include procurement-related notices and monitoring platforms, in compliance with NGPA, and |
(g) | must provide information on website owner contact, hosting provider, and agency CISO/CSIRT contact to the NCERT for coordination in case of a cybersecurity incident. |
(a) | ensure adherence to requirements of the Act, this IRR and all other laws including relevant DICT issuances on standards for all ICT infrastructure, systems, equipment, designs, and technologies; |
(b) | ensure compliance with the standards and protocols for cybersecurity, resiliency, data privacy and confidentiality, as prescribed in relevant laws, rules, and regulations; |
(c) | ensure prompt and effective communication of ICT standards promulgated by the DICT to all concerned agency officials; |
(d) | support national and local government efforts and, where appropriate, collaborate to develop, maintain, and promote an integrated system for delivering government information and services to the public; |
(e) | ensure the establishment and implementation of policies and standards on cybersecurity, freedom of information, and open data within their organization following its mandate and technological needs or risks; |
(f) | comply with the re-engineering and streamlining requirements of the ARTA as provided under the EODBA; and |
(g) | ensure continued availability of government information and services to all individuals and entities, including those without internet access, through accessible alternative delivery channels, whether electronic or manual. |
(a) | adopt policies, procedures, standards, and guidelines that are in accordance with law and as directed by the President of the Philippines; |
(b) | develop performance measures that demonstrate how ICT advances agency objectives, statutory mandates, and strategic goals aligned with key stakeholders, including citizens, businesses, and other governments; |
(c) | guide policies and programs, collect and analyze relevant data including on customer service, productivity, and the adoption of innovative information technology in accordance with industry best practices; |
(d) | as appropriate, work collectively in linking their performance goals to key groups and use information technology in delivering government information and services to those groups; |
(e) | take necessary measures to prevent algorithmic bias or discrimination, particularly in the use and deployment of emerging technologies, that could compromise the inclusivity and equity of access to government services; |
(f) | maintain and update their websites and e-bulletin boards in accordance with the standards set by the DICT; |
(g) | submit EA, ISSPs and ICT plans, and such other mandatory plans and reports within the timelines prescribed in this IRR and other relevant issuances; |
(h) | update ISSPs and ICT plans annually, integrate them into budget planning, and be accountable for their implementation; |
(i) | regularly undertake cost compliance analysis, time and motion studies, undergo evaluation and improvement of their transaction systems and procedures and re-engineer the same if deemed necessary to reduce bureaucratic red tape and process time; and, |
(j) | support the development of a digital competency framework to undertake a competency assessment of personnel and provide them with appropriate learning and development programs to strengthen their digital competency. |
(a) | establish and implement policies and standards on information security, freedom of information, and open data within their organization following its mandate and commensurate with its risk profile and the magnitude of the potential harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of information collected, stored, processed or maintained by or on behalf of the agency; and information systems used or operated by an agency, its contractor, or by other organizations on its behalf; |
(b) | ensure that all E-Government Programs comply with the data subject rights, security and data protection requirements of the DPA, and shall formally seek and incorporate guidance and assistance from the NPC on matters concerning information security and protection of personal data; |
(c) | comply with the Minimum Information Security Standards (MISS) set by the DICT, and submit proof of compliance thereof in accordance with Section 38 of this IRR; |
(d) | periodically test and evaluate information security controls and techniques to ensure that they are effectively implemented; |
(e) | integrate information security management processes with agency strategic and operational planning processes; |
(f) | adopt the Privacy-by-Design, Privacy Engineering, and Privacy-by-Default principles by implementing the measures in developing, implementing, and deploying systems, processes, software applications, and services throughout the personal data processing lifecycle, in accordance with the relevant guidelines issued by the NPC; and, |
(g) | allocate resources necessary to implement cybersecurity and data protection measures set in this Act, IRR, and other relevant issuances of the DICT. |
(a) | Planning and requirements gathering | |
(1) | Determine the lawful basis for processing personal data, and ensure that the purpose, scope, and manner of processing are compatible with the declared and specified purpose; | |
(2) | Apply the general data privacy principles of transparency, legitimate purpose, and proportionality in collecting personal data. Agencies should only collect data that is adequate, relevant, suitable, necessary, and not excessive in relation to a declared and specified purpose, and retain it only for a specified period to fulfill that purpose or as required by law; and | |
(3) | Conduct a (PIA) to identify and evaluate the potential risks and effects that the proposed data processing system may have on the data subjects, and to identify ways in which any adverse effects can be mitigated. | |
(b) | Designing and development | |
(1) | Minimize the processing of personal data by implementing architectures, practices, and techniques that reduce the use, collection, and retention of personal data to what is necessary in relation to the specified purpose; | |
(2) | Implement appropriate information security measures to maintain the confidentiality, integrity, and availability of personal data; | |
(3) | Implement measures within the system for data subjects to exercise their rights under the DPA, such as but not limited to: data access and download tools to request access to their personal data within the system; correction and rectification interfaces that allow users to rectify incorrect personal data; deletion or erasure options, to allow users to delete data within the system; and provide opt-in and opt-out mechanisms for specific processing of personal data; | |
(4) | Maintain traceability in the data processing system involving access or changes made to personal data; | |
(5) | Adopt secure software development practices that integrate privacy considerations throughout the systems life cycle processes; | |
(6) | Establish data retention policies that define how long personal data can be stored, (e.g., use of temporal data), where collected data is regularly deleted after usage; and | |
(7) | Implement secure disposal procedures and practices to ensure personal data is permanently deleted when it is no longer needed. | |
(c) | Testing and evaluation | |
(1) | Perform data privacy and information security testing to verify the effectiveness of the security and privacy controls and settings of the data processing system before deployment; | |
(2) | Test the usability of the privacy interfaces, such as the accessibility of privacy notices that are clear and understandable and testing the mechanism on how data subjects can easily exercise their privacy rights through the system; | |
(3) | Conduct code reviews and vulnerability scans to identify and address any information security flaws and weaknesses that can lead to unauthorized access and data breaches; and | |
(4) | Conduct a privacy architecture review to ensure that technologies, architectures, and protocols used in the data processing system support data privacy objectives and requirements of the DPA, and issuances of the NPC. | |
(d) | Deployment and integration | |
(1) | Provide data subjects with clear and concise privacy notices regarding the collection and processing of their personal data, including their rights and how to exercise them. For example, users should be informed about the data that an application or a data processing system will be processing. Avoid deceptive design patterns to ensure transparency and trust. This approach not only delivers clear privacy notices but also enhances the overall trustworthiness of data processing systems; | |
(2) | Obtain the proper consent of data subjects, when consent is the lawful basis for processing, before collecting and processing their personal data; and | |
(3) | Ensure that the default settings of the data processing system provide the maximum privacy protection without manual intervention from data subjects. Some examples include, but are not limited to the following: the security settings of a system should be enabled by default; online forms only require essential information by default and leaving optional fields unrequired; opt-in consent mechanism by default with unchecked consent boxes; default user profiles should be private rather than public; location tracking should be disabled by default; and payment details should not be saved by default. | |
(e) | Operation and maintenance | |
(1) | Regularly monitor the data processing system for any information security incidents and data breaches, and implement policies and procedures for incident response and breach notification; | |
(2) | Conduct periodic audits and PIAs at least once a year to assess the continued effectiveness of the privacy controls and address any gaps or new risks; a new PIA must be conducted in case of the following: (i) a major update or enhancement to an existing system is made; {ii) a new vendor or third party processor is engaged; and (iii) changes in the nature, scope, extent, or purpose of processing; | |
(3) | Promptly address any vulnerabilities and update the privacy controls of the data processing system based on the latest risks and information security standards; | |
(4) | Uphold the requests of data subjects in exercising their rights (e.g., right to access, rectify, object, etc.) in accordance with the DPA, and the NPC's issuance on Data Subjects' Rights; and | |
(5) | Train personnel on the secure processing in the application or data processing system, as well as managing information security incidents as stipulated in the DPA, and the NPC's issuance on managing information security incidents. |
(a) | serve as the primary accountable official for institutional digital transformation, managing operational ICT risks, system integrity, data governance, interoperability compliance, and alignment of ICT procurements with national standards and audit requirements, within the Covered Entity; |
(b) | advise agencies on how to leverage ICTs to optimize the delivery of secured public services and achieve efficient and cost-effective operations; |
(c) | securely develop, maintain, and manage the agency's information systems; |
(d) | manage and supervise the implementation of !CT-related projects, systems, and processes; |
(e) | ensure that the ICT systems and business processes are interoperable by design, enabling seamless integration and data exchange across the whole government digital ecosystem in accordance with national £-Governance standards; |
(f) | formulate and implement processes in relation to the adoption of ICT-based solutions, including emerging technologies as provided in the EGMP; |
(g) | facilitate the secure, automated, and proactive exchange of authorized datasets among government agencies in accordance with E-Governance standards; |
(h) | manage operational risks related to ICT, in coordination with the agency's management, CERT, and stakeholders, and a government CII's CISO, and integrate risk management into the planning process; |
(i) | ensure that the ICT programs and operations are consistent with national policies and prevailing industry standards; |
(j) | accelerate the adoption of open data, blockchain, and emerging technologies, while benchmarking against ICT industry best practices in ICT programs and operations; |
(k) | oversee the development, implementation, and maintenance of all organizational, physical, and technical security measures for government information systems to ensure full compliance with the DPA and relevant issuances of the NPC; |
(l) | ensure the rigorous operational implementation of the Privacy-by-Design, Privacy-by-Default principles, and Privacy Engineering throughout the entire systems life cycle processes, in coordination with the agency's designated Data Protection Officer (DPO); |
(m) | ensure that E-Government Programs are accessible and inclusive to persons with disabilities, as far as practicable, in adherence to digital inclusion principles and relevant accessibility laws; and |
(n) | Coordinate with the EGov UPMO the status of implementation of their ICT programs and projects. |
(a) | strategic and policy support in the implementation of ICT strategies, enforcement of technical standards and policies, and policy advocacy on issues related to ICT; |
(b) | operational and technical support in managing ICT systems and resources through shared knowledge and services; and |
(c) | human capital and professional support in managing the ICT workforce. |
(a) | identify, assess, evaluate, and manage the risks represented by the processing of personal data; | |
(b) | assist the DICT in preparing the records of its processing activities, and in maintaining its privacy management program; | |
(c) | facilitate compliance by the DICT with the DPA, and other applicable issuances of the NPC, by determining: | |
(1) | its adherence to the principles of transparency, legitimate purpose and proportionality; | |
(2) | its existing organizational, physical and technical security measures relative to its data processing systems; and | |
(3) | the extent by which it upholds the rights of data subjects. | |
(d) | aid the DICT in addressing privacy risks by allowing it to establish a control framework. |
(a) | data inventory identifying: | |
(1) | the amount and type of personal data held; | |
(2) | list of all information repositories holding personal data, including location; | |
(3) | type of media used for storing the personal data; | |
(4) | risks associated with the processing of personal data; and | |
(5) | processing operations for the entire personal data life cycle, from collection to disposal or destruction; | |
(b) | a systematic description of the personal data being processed or to be processed, including the purposes for such processing, anticipated purposes, and their corresponding lawful bases; | |
(c) | an assessment of the general data privacy principles in relation to the processing; | |
(d) | a holistic assessment of the risks to the rights and freedoms of a data subject; and | |
(e) | an assessment of risks to the confidentiality, integrity, and availability of personal data against any accidental or unlawful destruction, alteration, and disclosure, as well as against any other unlawful processing. |
(a) | Nature of the personal data to be protected; |
(b) | Risks represented by the processing, the size of the organization, and the volume of personal data being processed; |
(c) | Current data privacy best practices in a specific industry; |
(d) | Cost of information security implementation; and |
(e) | Purpose and extent of data sharing or outsourcing agreements and their attendant risks. |
(a) | provide standardized risk assessment and information security documentation templates necessary for the compliance of Covered Entities; |
(b) | issue a certificate of compliance to government agencies based on the requirements as defined in this Section and other future related issuances; |
(c) | in collaboration with the NPC, Cybercrirne Investigation and Coordinating Center (CICC), other relevant government agencies, the academe, private sector, and civil society, provide the proper guidance, assistance, and training on cybersecurity standards and/or requirements to all Covered Entities. |
(a) | Definition of government CII ; |
(b) | Criteria for classifying government CII ; |
(c) | Process for designating government CII; |
(d) | Process for designating government CII; |
(e) | Mandatory establishment of a dedicated in-house Agency CERT/ CSIRT or engagement of a private Agency CERT/ CSIRT, to be headed by a CISO, for all government CIIs; |
(f) | Mandatory notification and reporting of major (or material) information security incidents affecting their institutions by government errs to their Sectoral CERT or their government regulator, if a Sectoral CERT is not available, within 24 hours from discovery; and escalation of the incident report to NCERT, if the Sectoral CERT or government regulator requires assistance in incident response; |
(g) | Implementation of VAPT and annual Risk and Security Assessment by all government errs; Provided, That, VAPT engagements for Government err shall be performed by DICT-accredited providers that meet the DICT Trusted Assessment Provider (D-TAP) criteria and that VAPT reports shall be submitted to the NCERT and to the D-TAP registry, or D-TAP's equivalent; and |
(h) | Other cybersecurity standards, measures, protocols, and guidelines for the protection of government CII. |
Nothing in this IRR prevents a government CII from implementing additional standards, or other standards higher or more stringent than the minimum set by the DICT, as it deems necessary.
SECTION40.Public Service Continuity Plan (PSCP).- Consistent with the existing issuances of the National Disaster Risk Reduction and Management Council (NDRRMC) and the CSC, all ICT systems and infrastructure covered in the priority programs of the EGMP and ISSPs shall be included as part of the Public Service Continuity Plan (PSCP) of all government agencies and instrumentalities, to ensure the continuous delivery of essential agency functions, notwithstanding any emergency or disruption.(a) | Personal data backup, restoration, and remedial time; |
(b) | Periodic review and testing of the business continuity plan which takes into account disaster recovery, privacy, business impact assessment, crisis communications plan, and telecommuting policy, among others; and |
(c) | Contact information and other business-critical matters (e.g., electrical supply, building facilities, ICT assets). |
(a) | serve as the National Center of Excellence for ICT Education; |
(b) | conduct trainings on E-Governance in furtherance of the Act and this IRR; |
(c) | promote ICT education to enhance the nation's workforce capacity, guided by up-to-date data on domestic and global skills supply and demand; |
(d) | promote and conduct quality ICT education for the capacity development of all citizens; |
(e) | support the strategic goals of the National ICT Development Agenda through data collection and globally competitive ICT skills development programs; |
(f) | implement programs and activities that will equip citizens with globally competitive skills and foster inclusive economic growth; |
(g) | establish partnerships with persons, entities, and institutions for the development and updating of resources, curriculum, modules, and pedagogical approaches; |
(h) | promote gender parity through technology education; |
(i) | ensure continuous learning and professional development for educators in current ICT trends; |
(j) | promote internships, immersion, apprenticeships, and other enterprise-based trainings for learners with industry partners, both private and public; |
(k) | establish and implement a scholarship system for qualified individuals in training and programs under the Academy or other activities approved by the DICT Secretary; |
(l) | facilitate the screening, admission, and monitoring of scholars within the scholarship system under Section 43(k); |
(m) | undertake academic research and development related to ICT; |
(n) | regularly assess the state of the country in terms of comparative ICT skills and performance and propose responsive policies to address concerns; |
(o) | develop curricula and courses for learners and students to upskill ICT proficiency and competency, and to ensure that such curricula and courses are aligned with its relevant competency frameworks through consultations and collaborations with the Commission on Higher Education (CHED), Department of Education (DepEd), Technical Education and Skills Development Authority (TESDA), State Universities and Colleges (SUCs), and Local Universities and Colleges (LUCs); |
(p) | exercise such powers as may be necessary or incidental to the effective and efficient performance of its functions. |
(a) | allocation from DICTs budget under the annual General Appropriations Act; |
(b) | fees and dues collected by the Academy; and |
(c) | grants and donations made specifically to the Academy for its operations, in accordance with applicable laws and rules. |
(a) | research collaborations; |
(b) | resource sharing; |
(c) | module and training development; |
(d) | faculty exchange and standards development; |
(e) | training collaborations; |
(f) | internships and apprenticeships; |
(g) | recognition or accreditation of partner establishments and institutions and courses offered that comply with the competency standards and guidelines for government ICT workers; and |
(h) | other similar or relevant matters. |
(a) | Status of the implementation of their respective E-Government initiatives based on their approved ICT Plan; |
(b) | Compliance by the Covered Entity with the Act and this IRR; and |
(c) | Performance in delivering programs and services through the E-Government to their constituencies. |
(a) | Chairperson of the Senate Committee on Science and Technology; |
(b) | Chairperson of the House of Representatives Committee on Information and Communications Technology or its equivalent; and |
(c) | three (3) members each from the Senate and the House of Representatives. The minority in the Senate and the House of Representatives shall each have at least one (1) seat in the JCOCEG. |
(SGD.)HENRY R. AGUDA |
Secretary |
Department of Information |
and Communications Technology |