NATIONAL CYBER SECURITY STRATEGY GREEN PAPER 4 PROPOSED STRATEGY 5.2 ENSURE RELEVANT EDUCATION AND TRAINING TO PUBLIC SECTOR STAFF AND THOSE WORKING WITHIN CRITICAL INFORMATION INFRASTRUCTURE Training and education on cyber security is one key priority within the public sector, especially given the sector’s wider extensive use of ICT and sensitive data, compared to other sectors. “IT IS HIGHLY RECOMMENDED THAT A CONCERTED STRATEGIC APPROACH IS UNDERTAKEN, POTENTIALLY THROUGH A NATIONWIDE COMMUNICATIONS STRATEGY FOR CYBER SECURITY”. In any office environment it needs to be kept in view, that technology controls are not sufficient to protect data from related cyber security threats as outlined in the Supporting Document. The controls need to go hand in hand with human resource, awareness and employee guidance programs17. The development of cyber security expertise within the public sector is another key area that merits particular attention. In the process, it also needs to be ensured that a comprehensive list of public sector professionals certified under internationally recognised certification programs in cyber security is established and maintained. Furthermore, it needs to be ensured that ICT personnel are trained so as to enable them to recognise cyber incidents, to detect anomalies in their ICT systems and to report them accordingly. 5.3 FOSTER APPLICATION OF RESEARCH AND DEVELOPMENT ON CYBER SECURITY Such a measure aims to ensure cyber security as among key research priorities. It effectively calls for encouragement and support for research in any national and EU research projects and initiatives on cyber security. Essentially, it entails participation not only from Government but also from the private sector and the academia. It also calls for an emphasis to ensure security and privacy in the design of ICT products and services for Government as well as in other areas of application. 5.4 A STRATEGIC, TARGET-ORIENTED NATIONAL AWARENESS AND ADVICE CAMPAIGN It is highly recommended that a concerted strategic approach is undertaken, potentially through a nationwide Communications strategy for cyber security18; aimed at addressing the various strata of society, business and public sector during the short, medium to long term. Such an approach may ensure: • Avoiding piecemeal, potentially one-off approaches to awareness campaigns • No duplication of effort 23 MALTA | NATIONAL CYBER SECURITY STRATEGY GREEN PAPER

Select target paragraph3