NATIONAL CYBER SECURITY STRATEGY GREEN PAPER
4 PROPOSED STRATEGY
• Maximisation of cyber security related financial and human resources
• Imparting effective awareness and knowledge that is commensurate to the
target audience and to the medium used19
• A measure of the extent of national awareness and understanding of cyber
security over time.
Most measures highlighted within Goals 4 and 5 of this strategy as well as any
established national way of sharing related knowledge, experience and insight
as referred to in Measure 3.12O may potentially serve as key sources for the
establishment and maintenance of such a concerted strategic campaign.
Ultimately, the key factor in any training and awareness programmes on cyber
security is:
• Finding the right way to raise awareness
• Establishing training programmes that effectively increase security level of an
organisation and maintaining such increased level of security in the long term
• Ensuring motivation of users to learn and pay particular attention to various
signals of fake communications on a day to day basis (particularly to counter
social engineering threats).
Prior and post assessment of such programmes is one way of ensuring
their effectiveness. However, consideration should also be taken that such
programmes may not necessarily focus only on traditional modes of education
and awareness but also on experimentation of innovative ways of their conduct21.
5.5 ENCOURAGE ‘CYBER HYGIENE’ AND PERSONAL RESPONSIBILITY
Ultimately, citizens are expected to apply at least some form of basic ‘cyber
hygiene’ in using ICT, such as through careful disposition and use of personal
information on-line, installing software updates, using basic security controls such
as passwords and anti-virus software. The national awareness campaign
as highlighted earlier should help in reaching this objective.
In particular, a responsible disclosure policy that enables well-intentioned
citizens to safely inform Government, businesses or institutions about detected
vulnerabilities in their ICT systems or services may also be considered22.
24
MALTA | NATIONAL CYBER SECURITY STRATEGY GREEN PAPER