The measures planned for the first period will call for a special effort to establish the broad collaboration needed between the government and stakeholders According to the plan these measures will be reviewed annually; in subsequent periods procedure will be harmonised with normal standards of other strategy applications. The strategy is intended to form the basis of collaboration and development in cyber security. The strategy itself will not change the responsibilities and duties of those involved in cyber security even though proposals may be made for measures that may involve changes in these areas. To implement the strategy, a collaborative forum, the ‘Cyber Security Forum’ will be set up in the first half of 2015. The forum is the venue for planning individual measures in detail with cost estimates. As many of these measures involve coordination in the work of various entities, special funding is not needed to begin this development. Nevertheless to ensure the effort will have sufficient capacity, about ISK 20 million will probably be needed to pay for coordination, reports and educational/training/awareness-raising work. It is envisaged that enterprises (companies) will provide the funds to meet part of the costs of some of the projects. Proposals for projects requiring public funding will be submitted to the Cyber Security Council, which will make proposals on priority ranking of projects, following consultation with stakeholders. At the end of each period, the Cyber Security Council will compile a report based on summaries submitted by those responsible for all the measures, give an account of the results of the work and submit proposals, following consultation with stakeholders, on a plan of action for the next three years. The aim is that the work of the Cyber Security Council will be transparent: minutes of meetings and other materials will be published except where publication would be contrary to law, e.g. in view of personal data protection considerations. 8

Select target paragraph3