Telecommunications systems and the primary data transmission networks must be reliable. IT and IT security in public administration must be enhanced, for example regarding coordination, education and awareness-raising. The main basis of Iceland’s security and defence lies in the country’s collaboration with NATO, active collaboration with other Nordic countries and the Defence Agreement with the United States. It also includes the IT infrastructures mentioned above. The protection of the infrastructures on which these activities rely in Iceland is therefore one of the most important aspects of Iceland’s national defence. In view of this, the agreement signed recently with NATO’s Cyber Defence Management Board will lead to increased collaboration in this field. As an indication of the importance attached by NATO to cyber security, it was decided that cyber-attacks could be classified under Article 5 of the NATO Treaty. Increased collaboration with other international organisations such as the United Nations, the Council of Europe, the European Union and the Organisation for Security and Cooperation in Europe can also promote cyber security in Iceland. A great deal can be gained from taking the initiative and forging ahead in this area. Building up cyber security is a challenge that no single entity in our society can undertake. To ensure optimum results it is necessary to approach the task in a comprehensive manner, involving as many IT users as possible. Both government institutions and private companies in addition to individuals should be included in this process.. It is important to begin this work immediately and create a common forum for development and collaboration, e.g. regarding security standards, coordination, identification of cyber security threats and the organisation of responses. Last but not least it is important to be aware of the fact that this will be an on-going process subject to continual review as it progresses, with new challenges calling for new solutions. The strategy envisages the development of cyber security along the same lines as other aspects of civil protection and security.In the event of a catastrophe or cyber-threat, the emphasis will be on the rapid exchange of information between the parties concerned in order to minimise and mitigate damage, after which work will proceed on the next steps to be taken; assessment and recovery measures will follow the same pattern as is described in the civil defence programme. Furthermore, the event will be analysed in order to learn as much as possible from it. If the event is caused by human agents, then it must also be guaranteed that an efficient police investigation can go ahead. Review of the strategy and action plan This strategy shall be examined and reviewed as necessary, at minimum every four years. Measures based on the strategy shall be designed to cover shorter periods and shall be reviewed at least once a year. Procedure in implementing the strategy shall be in the spirit of public administration. 6

Select target paragraph3