Telecommunications systems and the primary data transmission networks must be reliable. IT and IT
security in public administration must be enhanced, for example regarding coordination, education
and awareness-raising.
The main basis of Iceland’s security and defence lies in the country’s collaboration with NATO, active
collaboration with other Nordic countries and the Defence Agreement with the United States. It also
includes the IT infrastructures mentioned above. The protection of the infrastructures on which
these activities rely in Iceland is therefore one of the most important aspects of Iceland’s national
defence. In view of this, the agreement signed recently with NATO’s Cyber Defence Management
Board will lead to increased collaboration in this field. As an indication of the importance attached by
NATO to cyber security, it was decided that cyber-attacks could be classified under Article 5 of the
NATO Treaty.
Increased collaboration with other international organisations such as the United Nations, the
Council of Europe, the European Union and the Organisation for Security and Cooperation in Europe
can also promote cyber security in Iceland.
A great deal can be gained from taking the initiative and forging ahead in this area. Building up cyber
security is a challenge that no single entity in our society can undertake. To ensure optimum results it
is necessary to approach the task in a comprehensive manner, involving as many IT users as possible.
Both government institutions and private companies in addition to individuals should be included in
this process.. It is important to begin this work immediately and create a common forum for
development and collaboration, e.g. regarding security standards, coordination, identification of
cyber security threats and the organisation of responses. Last but not least it is important to be
aware of the fact that this will be an on-going process subject to continual review as it progresses,
with new challenges calling for new solutions.
The strategy envisages the development of cyber security along the same lines as other aspects of
civil protection and security.In the event of a catastrophe or cyber-threat, the emphasis will be on
the rapid exchange of information between the parties concerned in order to minimise and mitigate
damage, after which work will proceed on the next steps to be taken; assessment and recovery
measures will follow the same pattern as is described in the civil defence programme. Furthermore,
the event will be analysed in order to learn as much as possible from it. If the event is caused by
human agents, then it must also be guaranteed that an efficient police investigation can go ahead.
Review of the strategy and action plan
This strategy shall be examined and reviewed as necessary, at minimum every four years. Measures
based on the strategy shall be designed to cover shorter periods and shall be reviewed at least once
a year. Procedure in implementing the strategy shall be in the spirit of public administration.
6