INTRODUCTION 1 1. Introduction The National Cyber Security Strategy was launched by the Norwegian government in January 2019. The strategy sets out goals for five prioritised areas. The strategy is backed by this two-part list of measures, where part 1 describes key measures that support the strategy, and part 2 lists ten basic measures that both public and private companies are recommended to implement. The measures listed in part 2 of this document are provided to increase companies’ own ability to protect themselves against and handle cyber incidents. 1.1. Report and follow-up on the list of measures The Norwegian Ministry of Justice and Public Security (JD) and the Norwegian Ministry of Defence (FD) have overall responsibility for following up on the strategy. Each ministry must ensure that the strategy’s priorities and the list of measures are followed up in their own sector. In this regard, ministries must work closely with government agencies and sector stakeholders so that planned cyber security measures are coordinated with other ministries as necessary. Each ministry should actively involve affected stakeholders in the private sector in the preparation of measures. Ministries must establish whether measures initiated in their own sector sufficiently contribute to achieving the goals from the strategy. In connection with follow-up by the ministries, it is expected that the importance of cyber security is communicated to the government agencies. It would be beneficial to make this an integral part of the governing of subordinate agencies. This list of measures is published separately and is to be revised as necessary. It is presumed that measures which affect the business community will be implemented in close collaboration with the business community’s own bodies. It is presumed that measures which affect consumers will be implemented in collaboration with consumer organisations. Prior to implementing new measures, an evaluation of how the measure in question will affect privacy should always be conducted and, if necessary, privacy protection authorities should be involved in the planning and implementation. To track the status in following up the strategy’s priorities, JD and FD will monitor the development in the area of cyber security by requesting status updates from ministries concerning their work to follow up on the strategy. Status reports will be collected approximately two years after the launch of the strategy. Follow-up on the strategy will also be carried out by the use of an interministerial group, and through a public-private partnership forum. These groups will, for example, track development regarding security challenges and trends, and continuously determine whether this triggers a need to revise (fully or in part) the contents of the national strategy and, correspondingly, the list of measures. List of measures – National Cyber Security Strategy for Norway | 7

Select target paragraph3