evsjv‡`k †M‡RU, AwZwi³, gvP© 11, 2014 9709 Action 3: Critical Information Infrastructure Protection This Action focuses on defining a process for tracking and fixing vulnerabilities; improving attack attribution and prevention capabilities. Vulnerabilities are weaknesses that allow a threat or attack to break a system’s confidentiality, integrity and availability defenses. Most of cyber attacks result from poor technical designs or the exploitation of known but unfixed vulnerabilities. The impact of the exploitation of vulnerability depends on the value and criticality of information. Critical information infrastructures inevitably store valuable information. The National Cybersecurity Strategy identifies the following major actions and initiatives to reduce threats and related vulnerabilities in Bangladesh: • Create a process for national vulnerability assessments to help understand the potential consequences of threats and vulnerabilities; • Designate important systems as critical information infrastructure and enforce an accreditation regime around them. For example, no system will connect to critical infrastructure without a penetration test and other assurance activities; • Enhance law enforcement capabilities in the investigation, prevention and prosecution of cybercrimes; • Require the use of evaluated software products; • Prioritize national cybersecurity research and development activities; • Assess and secure emerging systems; and • Participate in international efforts to improve the security of Internet protocols and routing technologies. Priority 3: Organisational Structures This Priority Area requires the building of organizational structures and strategies to help prevent, detect and respond to attacks against critical infrastructure. The National Cybersecurity Strategy identifies the actions below as essential for creating appropriate national and regional organizational structures and policies on cybercrime:

Select target paragraph3