system will also be open to civil society's initiatives. This applies primarily to initiatives for
improvements and assistance in raising awareness among various target groups by professional
associations (Slovenian associations and the Slovenian sections of international associations in the
field of information and communication technologies and cyber security).
7
The areas of strategy implementation
Strategy implementation will focus on preventing security incidents, responding to security incidents
and increasing awareness of the target groups about the importance of cyber security.
7.1 Prevention
The prevention of security incidents ranges from the technical design of information system
components to providing national and international legal frameworks and regulations that contribute
to the development of safer applications and infrastructure. Furthermore, it should be ensured that
the design of programmes and ICT infrastructure include the safety and protection of individuals'
privacy, and that the standards ensuring safe and smooth operation of the systems, including the use
of encryption solutions, are observed. Risks are assessed, which serves as a basis for the preparation
and implementation of measures to mitigate unacceptable risks, and an analysis of the implemented
measures. The use of open-source technologies that ensure interoperability and allow best possible
control, and which are not partially of fully closed because of patent rights, is encouraged.
7.2 Response
Prevention alone is insufficient for achieving a high level of cyber security. As security incidents can
never be fully eliminated, it is necessary to provide for appropriate mechanisms to respond to them.
It is furthermore important to take account of the experience obtained from the prevention phase,
as well as from the past security incident response events. Experience may come from domestic and
foreign institutions responsible for cyber security assurance, and therefore their best possible
interconnectivity is very important. Based on the experience and analysis of incidents and risks, the
response measures are constantly updated and improved. Active cooperation is also observed in the
preparation of standard cyber crisis response procedures at the international or global level.
7.3 Awareness raising
People are those who develop, build and use ICT. Awareness raising and education may help to
eliminate the risks and build a culture of safe technology use. In the awareness-raising phase, the
experience derived from prevention and response phases must be utilised so that users are
acquainted with actual risks and effective methods of avoiding them. The methods and contents of
awareness raising (programmes) are adjusted to various target groups to the greatest possible
extent. For children and adolescents, cyber security topics are included in the curriculum at different
levels of education. Adjusted awareness-raising programmes for the remaining population and
business entities are developed. The use of encryption solutions, as one of the cornerstones of cyber
security assurance, is encouraged.
10
Cyber Security Strategy