NATIONAL CYBER SECURITY STRATEGY GREEN PAPER END NOTES 1. Adapted from the definition cited by the Cyber security Strategy of the European Union 2. Ross(2O15) 3. Puricelli (2O15) 4. Which could take the form of (i) a centralised approach – whereby a national authority has in-house responsibilities with all authorities reporting to it; OR (ii) a decentralised approach whereby roles and responsibilities are spread across a variety of actors who coordinate together to share information and exchange on a voluntary basis OR (iii) a semi-centralised (hybrid) approach whereby a central ministry coordinates implementation of the strategy with designated authorities having the necessary roles and responsibilities over operators and other stakeholders and who report to the central ministry on a periodic basis. 5. A top level coordinating CSIRT that acts as a key support to the strategy implementation function. Among the responsibilities of such CSIRT are: • • Monitoring incidents at a national level Providing early warning, alerts, announcements and dissemination of information to relevant stakeholders about risks and incidents • Providing dynamic risk and incident analysis and situational awareness • Establish cooperative relationships with the private sector • Facilitate cooperation through use of common or standardised practices for incident and risk handling procedures 6. European Commission (2O15), DSI Maturity Study, p.29 7. Refer to Section 9 - ‘Identification and Assessment of Stakeholders’of the Supporting document 8. Key market operators refers to providers of information society services, operators of critical information infrastructure and operators of Critical infrastructure that provide essential or critical services to critical information infrastructure. For more details, refer to the Section 9 – ‘Identification and assessment of Stakeholders’ of the Supporting document. 9. As part of Measure 3.4 – Conduct cyber defence exercises 10. ibid 11. ibid 12. European Agenda on Security: Questions and Answers, Strasbourg, 28 April 2O15 - European CommissionFact Sheet. 13. ibid 14. For example Austria and the UK 15. Such as those of NIST Cyber security Framework or potentially a similar initiative such as the UK’s Cyber Essentials Scheme, http://www.itgovernance.co.uk/cyber-essentials-scheme.aspx#.VaYNvLlBut8 32 MALTA | NATIONAL CYBER SECURITY STRATEGY GREEN PAPER

Select target paragraph3