Main aim No. 2: Increased resilience An upgrading of the resilience of information systems. Greater capacity in the fields of assessment, preparedness and response as key factors in increased resilience. Monitoring and response capacity must be increased so as to respond to abnormal situations on the Internet. Nevertheless, full regard must be given to appropriate considerations of personal data integrity. It must be possible for key entities to exchange information about possible threats quickly. Therefore it is important to establish one or more collaborative forums on which information on cyber security threats can be shared in a clearly defined manner without infringement of competition or personal data considerations. This could require mediation through a public body to ensure that it is possible to share information on cyber-threats quickly without revealing the identity of the target. The pace of development in the field of cyber security is very rapid. For this reason it is important that all entities involved are active in international collaboration, each in its respective area. Close collaboration between stakeholders in Iceland, with efficient exchange of information, will make it possible to respond jointly to rapid change. Active participation in international collaboration is also necessary to maintain flexibility, skills and contacts and be able to work with other national and supranational authorities when a crisis on the Internet looms. It is also vital that Iceland presents a single coordinated strategy in cyber security matters when the country takes part in international collaboration. Increased resilience in information systems will depend on reliable design. Reliable design must be a crucial consideration in the purchase and development of software, particularly in the case of key elements in IT infrastructure. This applies at the national, corporate and individual level. 7. A collaborative forum A forum must be established where representatives of government and private enterprises can work together on cyber security issues. 8. Security yardsticks Choice of appropriate yardsticks (standards and others) for cyber security. 9. International collaboration Iceland’s involvement in cyber security abroad must be increased and coordinated. 10. Reliability of primary data systems Telecommunications systems and the primary data transmission networks must offer support, with a defined degree of reliability, the Internet and IT networks of key elements in Iceland’s infrastructure, both as regards connections within the country and their interface with other countries. 11. Public administration Cyber security in the field of public administration must be upgraded by means of increased training, coordination and collaboration. 12. Analysis Principal cyber security threats must be analysed and key elements in the Icelandic infrastructure identified. 13. Protection of the infrastructure The capacity of the cyber security team to raise the level of protection and assist important elements in the national infrastructure must be increased, and an active response mechanism must be in place on a round-the-clock basis every day of the year. Particular emphasis should be placed on telecoms, utilities and financial companies and the systems necessary for international aviation. 10

Select target paragraph3