NATIONAL CAPABILITY FOR ENSURING TIMELY AND EFFECTIVE RESPONSE TO CYBER INCIDENTS IS ESTABLISHED AND MAINTAINED The timely reporting of cyber security incidents plays an important role in enhancing national cyber security. Incident reporting and analysis helps authorities to determine what should be the focus of its security measures to inform national preparedness, response and recovery efforts. A national CIRT, with a direct reporting line to the Ministry with portfolio responsibility for ICT, will be established. The CIRT’s services will include incident response, handling and coordination, vulnerability response and coordination, alerts and warnings, threat analysis, security audits and assessments, forensics and risk analysis and education and training. In its initial stages the CIRT constituents will include all government agencies and critical national infrastructure operators. Additionally, the CIRT will seek to issue timely alerts on emerging threats to ensure the integrity of systems that may be at risk, as well as, build collaborative relationships with all sectors to, among other things, foster trust. The Strategy recognizes that cyber incidents may be as a result of criminal activities (cybercrimes) and as such interagency cooperation between the national CIRT and law enforcement will be encouraged to ensure information sharing is facilitated. A framework will be established to exchange information with its constituents regarding cyber breaches and possible counter and/or mitigation measures to be deployed. The CIRT, given its crucial role, will adopt policies for continuous training of its staff and upgrading of its software and hardware, in order to remain current. A RISK BASED APPROACH IS APPLIED IN ESTABLISHING IT AND INFORMATION SECURITY STANDARDS, POLICIES AND GUIDELINES FOR ICT INFRASTRUCTURE AND CYBER SECURITY GOVERNANCE Risk management is the process of identifying, assessing, and responding to risk and then determining an acceptable level of risk for the assets. This approach is applicable to both private and public sector assets. All relevant public and private organizations must take the necessary measures to protect their ICT infrastructure from threats, risks and vulnerabilities. As such the establishment of sector specific and general baseline security requirements will be established outlining the minimum security standards that all organizations in that sector should comply with. The Strategy will seek to ensure that mechanisms are developed to assess existing international best practices in the area of Information Security and adapt accordingly to suit local conditions. The adoption of minimum standards for sector specific industries should result in the reduction of the number of successful attacks. 21 National Cyber Security Strategy Government of Jamaica

Select target paragraph3