Ontech ICTM by industry

ICT Management for Government in Zambia

Asset registers, ICT policies, approvals, audit trails and data-protection records for ministries, agencies and other public bodies.

How can government ministries and agencies in Zambia manage ICT?

Public bodies in Zambia manage ICT by keeping a register of assets across headquarters and regional offices, maintaining ICT policies that staff acknowledge, controlling changes and access, protecting citizens' personal data and keeping auditable records. The Electronic Government Act, 2021 gives the Electronic Government Division a coordinating role. Ontech ICTM organises this work in one platform that can run on servers you control.

Under the Electronic Government Act, 2021, the Electronic Government Division, which operates as the Smart Zambia Institute, coordinates e-government and ICT matters in public bodies, develops and enforces standards, and may audit public bodies for compliance. The Cyber Security Act, 2025 lists the public sector as a critical sector, and the Data Protection Act, 2021 applies to the personal data public bodies hold.

Ontech ICTM helps ministries, agencies and other public bodies keep the records those duties rely on: a single asset register, approved ICT policies with staff acknowledgements, controlled approvals and changes, an audit trail, data-protection records and awareness training.

ICT challenges in government & public sector

No single asset register

ICT equipment is spread across headquarters, provincial and district offices with no consolidated record.

Policies nobody has read

ICT policies exist, but there is no record of which staff have accepted which version.

Informal approvals

ICT requests and changes are approved on paper or by email and are hard to trace later.

Citizen data obligations

Processing records, impact assessments and breach handling for citizen data are incomplete.

Audit preparation

Evidence for auditors is assembled by hand every time it is requested.

How government & public sector organisations use ICTM

Cross-office asset register

Assets at headquarters, provincial and district offices are recorded with assigned officers, locations and assignment history, and exported to PDF or CSV.

ICT policy register with acknowledgements

Policies carry version history and review sign-off, and each acknowledgement records the officer, the version accepted, the time and the IP address.

Multi-stage approvals

ICT requests and changes follow approval chains that can require any, all or a majority of approvers, add approvers when conditions such as budget thresholds are met, and allow delegation.

Audit trail and activity checks

Write actions are logged with a SHA-256 integrity hash on each entry, and scheduled checks flag brute-force attempts, mass deletions and out-of-hours activity.

Citizen data-protection records

Registers of processing, impact assessment records, a breach register and transfer records that show what is stored inside and outside Zambia.

Testing public-facing services

Scheduled vulnerability scans and web application tests of citizen-facing portals, with findings tracked against remediation deadlines.

Awareness training for officers

Mandatory courses with automatically graded quizzes and certificate IDs record which officers have completed security and data-protection training.

Regulation that applies

Summaries based on the primary legislation and regulator publications. See the linked Zambia pages for detail and sources — this is general information, not legal advice.

Electronic Government Act No. 41 of 2021

The Electronic Government Division (Smart Zambia Institute) coordinates e-government and ICT matters in public bodies (s.5(2)), develops and enforces quality assurance, security and other standards (s.6(1)(i)) and may audit public bodies for compliance (s.28).

Cyber Security Act No. 3 of 2025

Establishes the Zambia Cyber Security Agency in the Office of the President (s.3) and lists the public sector as a critical sector (s.8). Critical information infrastructure is designated by Gazette notice (s.9); its controllers must file a preliminary cyber incident report within twelve hours (s.17). The Act repealed the Cyber Security and Cyber Crimes Act, 2021 (s.73).

Data Protection Act No. 3 of 2021

Data controllers and processors must register with the Data Protection Commissioner (s.19), appoint a data protection officer (s.48), notify the Commissioner within twenty-four hours of a security breach (s.49), and process and store personal data on a server or data centre in Zambia unless an exception applies (s.70).

What ICTM covers — and what it doesn't

ICTM does not submit returns to the Electronic Government Division, the Zambia Cyber Security Agency or the Data Protection Commissioner, and it does not implement government procurement or financial-management rules. It holds the ICT records, controls and evidence those processes draw on.

Benefits

Consolidated inventory

Assets across every office sit in one register with owners and locations.

Evidence of policy acceptance

Acknowledgements show who accepted which policy version, and when.

Traceable decisions

Approvals and changes are recorded step by step in the audit trail.

Data kept in Zambia

ICTM can run on government-controlled servers, with AI features on a locally hosted language model.

Faster audit responses

Reports export to CSV, Excel or PDF from live records.

Rolling out ICTM

  1. Scope modules and roles

    Run ICTM as a hosted service or on servers you control, then set up role-based access so each team sees only the modules it needs.

  2. Build the asset register

    Record assets at headquarters and each regional office with assigned officers and locations.

  3. Publish policies

    Load ICT policies into the policy register, set review sign-off and collect staff acknowledgements.

  4. Configure approvals and change control

    Set up multi-stage approval chains for ICT requests and changes, with conditions and delegation.

  5. Protect data and train staff

    Complete the Data Protection Act self-assessment and records of processing, and enrol staff in awareness courses.

Frequently asked questions

What does the Electronic Government Act, 2021 mean for ministries' ICT?

The Act makes the Electronic Government Division, known as the Smart Zambia Institute, responsible for coordinating e-government and ICT matters in public bodies (section 5(2)). Its functions include developing, disseminating and enforcing quality assurance, security and other standards (section 6(1)(i)), and it may audit public bodies for compliance (section 28). Clear ICT records make those audits easier.

Can ICTM be hosted on government infrastructure?

Yes. ICTM can be installed on servers a public body or government data centre controls, and its AI features can run on a locally hosted language model, so records do not need to leave government infrastructure. This supports the Data Protection Act's requirement to process and store personal data on servers or data centres in Zambia (section 70).

How does ICTM show that staff have accepted ICT policies?

ICTM's policy register keeps each policy with version history and review sign-off, and records every acknowledgement: which member of staff accepted which version, when and from which IP address. When a policy is updated, the new version can be acknowledged afresh, giving auditors a clear trail. Recording an acknowledgement currently needs the governance-management permission, so grant it to officers who must acknowledge, or record acceptances on their behalf.

Is the public sector a critical sector under the Cyber Security Act, 2025?

Yes. Section 8 of the Cyber Security Act, 2025 lists the public sector among the critical sectors. The Zambia Cyber Security Agency, established in the Office of the President (section 3), designates critical information infrastructure by Gazette notice (section 9); controllers of designated infrastructure must file a preliminary incident report within twelve hours (section 17).

Can auditors see who changed what in ICTM?

Yes. ICTM records write actions in an audit trail, with a SHA-256 integrity hash on each entry, and runs scheduled checks for unusual activity such as repeated failed logins, mass deletions or out-of-hours changes. Retention periods for audit records are configurable, so align them with your records-management rules.

See how government & public sector teams use Ontech ICTM

Book a walkthrough with the Ontech team, or start a free trial and explore the platform yourself.