PART 1 – KEY MEASURES FOR IMPROVED CYBER SECURITY 2 Measure 1.3: Allvis NOR, mapping and vulnerability analysis “Allvis NOR” is a service NSM provides to improve cyber security among public sector companies and owners of critical infrastructure. The service primarily consists of regular mapping and vulnerability analysis of selected IP addresses that are exposed to the internet. Information about vulnerable services is then shared with system owners. The service is to be developed and upscaled so that it can detect more vulnerabilities at more companies. Responsibility: NSM Implementation: 2018-2021 Measure 1.4: DNS service for the public sector NSM currently provides a DNS service for selected companies. Using this service makes it possible to stop traffic to specific websites. The DNS service is to be developed, upscaled and made available to the public sector. Responsibility: NSM Implementation: 2018-2021 Measure 1.5: Secure email service for the ministries Email is the preferred means of digital communication among Norwegian companies in the public and private sectors, even though new technology opens up other methods for communicating electronically. The vast majority of cyber incidents targeted at nationally critical digital infrastructure start with a fraudulent email. A number of improvements to the email standard exist today. Several of these improvements are intended to limit the scope for receiving fraudulent email. A shared service for receiving emails and analysis of unwanted emails is to be established for the ministries. Responsibility: FD Implementation: 2019 Measure 2: National strategy for cyber security competence The national strategy for cyber security competence (2019) is to influence direction and content, as well as highlighting responsibility for measures in the fields of education and research. Moreover, the strategy encompasses measures intended to raise awareness among the general public, local authorities and the business community. The strategy is part of an ongoing process to develop measures for improved cyber security competence in partnership with the authorities, public and private companies, the education sector and research institutions. The current long-term plan for research and higher education sets out guidelines for stronger research input in the field of cyber security. Conditions will be established to reinforce cooperation to place more emphasis on cyber security as a part of study programmes in the fields of technology and engineering. In the national strategy for cyber security competence, particular emphasis is placed on having an adequate knowledge basis for sufficient cyber security competence. JD will ensure access to updated statistics and analyses to keep track of the cyber security competence gap. Furthermore, conditions will be established for an improved knowledge basis as regards to security culture for the general public and for companies. Priority areas in this field are planned to be accorded more than 800 million NOK. This budget does List of measures – National Cyber Security Strategy for Norway | 9

Select target paragraph3