system will also be open to civil society's initiatives. This applies primarily to initiatives for improvements and assistance in raising awareness among various target groups by professional associations (Slovenian associations and the Slovenian sections of international associations in the field of information and communication technologies and cyber security). 7 The areas of strategy implementation Strategy implementation will focus on preventing security incidents, responding to security incidents and increasing awareness of the target groups about the importance of cyber security. 7.1 Prevention The prevention of security incidents ranges from the technical design of information system components to providing national and international legal frameworks and regulations that contribute to the development of safer applications and infrastructure. Furthermore, it should be ensured that the design of programmes and ICT infrastructure include the safety and protection of individuals' privacy, and that the standards ensuring safe and smooth operation of the systems, including the use of encryption solutions, are observed. Risks are assessed, which serves as a basis for the preparation and implementation of measures to mitigate unacceptable risks, and an analysis of the implemented measures. The use of open-source technologies that ensure interoperability and allow best possible control, and which are not partially of fully closed because of patent rights, is encouraged. 7.2 Response Prevention alone is insufficient for achieving a high level of cyber security. As security incidents can never be fully eliminated, it is necessary to provide for appropriate mechanisms to respond to them. It is furthermore important to take account of the experience obtained from the prevention phase, as well as from the past security incident response events. Experience may come from domestic and foreign institutions responsible for cyber security assurance, and therefore their best possible interconnectivity is very important. Based on the experience and analysis of incidents and risks, the response measures are constantly updated and improved. Active cooperation is also observed in the preparation of standard cyber crisis response procedures at the international or global level. 7.3 Awareness raising People are those who develop, build and use ICT. Awareness raising and education may help to eliminate the risks and build a culture of safe technology use. In the awareness-raising phase, the experience derived from prevention and response phases must be utilised so that users are acquainted with actual risks and effective methods of avoiding them. The methods and contents of awareness raising (programmes) are adjusted to various target groups to the greatest possible extent. For children and adolescents, cyber security topics are included in the curriculum at different levels of education. Adjusted awareness-raising programmes for the remaining population and business entities are developed. The use of encryption solutions, as one of the cornerstones of cyber security assurance, is encouraged. 10 Cyber Security Strategy

Select target paragraph3