The measures planned for the first period will call for a special effort to establish the broad
collaboration needed between the government and stakeholders According to the plan these
measures will be reviewed annually; in subsequent periods procedure will be harmonised with
normal standards of other strategy applications. The strategy is intended to form the basis of
collaboration and development in cyber security. The strategy itself will not change the
responsibilities and duties of those involved in cyber security even though proposals may be made
for measures that may involve changes in these areas.
To implement the strategy, a collaborative forum, the ‘Cyber Security Forum’ will be set up in the
first half of 2015. The forum is the venue for planning individual measures in detail with cost
estimates. As many of these measures involve coordination in the work of various entities, special
funding is not needed to begin this development. Nevertheless to ensure the effort will have
sufficient capacity, about ISK 20 million will probably be needed to pay for coordination, reports and
educational/training/awareness-raising work. It is envisaged that enterprises (companies) will
provide the funds to meet part of the costs of some of the projects. Proposals for projects requiring
public funding will be submitted to the Cyber Security Council, which will make proposals on priority
ranking of projects, following consultation with stakeholders.
At the end of each period, the Cyber Security Council will compile a report based on summaries
submitted by those responsible for all the measures, give an account of the results of the work and
submit proposals, following consultation with stakeholders, on a plan of action for the next three
years.
The aim is that the work of the Cyber Security Council will be transparent: minutes of meetings and
other materials will be published except where publication would be contrary to law, e.g. in view of
personal data protection considerations.
8