NATIONAL CYBER SECURITY STRATEGY GREEN PAPER 4 PROPOSED STRATEGY 1.2 FOSTER THE COORDINATION TO PROTECT NATIONAL CRITICAL INFORMATION INFRASTRUCTURE Measures of preparedness, response and recovery, including cooperation and ongoing coordination mechanisms are particularly necessary to protect national critical information infrastructure. It is thus necessary to ensure that such national coordination between all stakeholders concerned 7 is fostered. “THE PUBLIC SECTOR AND KEY MARKET OPERATORS NEED TO IDENTIFY CYBER RISKS AND ASSESS IMPACTS OF POTENTIAL INCIDENTS.” 1.3 ENSURE CLEAR DELINEATION AND COMMUNICATION OF ROLES AND RESPONSIBILITIES Cyber related roles and responsibilities - such as those identified above and potentially those arising from the proposed measures need to be clearly delineated and agreed upon accordingly. Communication of their establishment further ensures the effective coordination that may be necessary between the effected stakeholders themselves. 1.4 ENSURE THE ESTABLISHMENT OF A NATIONAL CYBER RISK ASSESSMENT PLAN AND PROCESSES THAT ARE REGULARLY VALIDATED AND TESTED The Public Sector and key market operators8 need to identify cyber risks and assess impacts of potential incidents. This calls for the need to develop a national cyber risk assessment exercise as the basis to assess, prioritise and take measures to ensure cyber security. Such an assessment plan entails coordination between all stakeholders involved and it needs to be updated on a regular basis, so as to ensure its currency with: • The cyber threat vector landscape • Evolution in the adoption of existing and emerging ICT. The cooperation and communication processes needed to ensure prevention, detection, response, repair and recovery (including communication), that are modulated according to the alert level are to be ensured. Such processes also refer to national incident cyber handling procedures and business continuity plans to ensure resilience. Furthermore, it is understood that the above plans and processes need to be subject to a schedule of regular testing and validation exercises9 with the resulting outcome (including lessons learnt) used as a basis for any related updates. The emphasis made to the Public Sector and key market operators1O through such measures should not however construe that other organisations need not adopt similar activities. 16 MALTA | NATIONAL CYBER SECURITY STRATEGY GREEN PAPER

Select target paragraph3