Page 43 2) The NCA distinct from the NCC and vested with some degree of independence, shall execute functions to facilitate establishment of the measures identified in the national policy approved by the NCC as well as verification of compliance, risk auditing and security appraisal; assist the NCC in all its functional activities and help industry to test its emergency plan; work with industry to set objectives, define directives for the security of ICT infrastructure and services and contribute to the application of international standards on cyber security as well as on accreditation and certification of ICT infrastructure, services and suppliers. Article III – 1 – 17: Computer emergency response team (CERT) 1) Each Member State shall establish a national CERT to take charge of its information infrastructure protection actions and serve as a base for national coordination to respond to ICT security threats at regional and global levels. 2) Members States shall ensure that their national CERTs are capable of providing reactive and proactive services, communicating timely information on recent relevant threats and, whenever necessary, bringing their assistance to bear for response to incidents. 3) Member States shall ensure that the CERT so established by virtue of this Article executes the following minimum services: i) Reactive services: early warning and precaution notice, incidents processing, incidents analysis, incident response facility, incidents response coordination, incident response on the web, vulnerability treatment, vulnerability analysis, vulnerability response and vulnerability response coordination; ii) Proactive services: public notice, technological surveillance, security audit and assessment, security installations and maintenance, security tools development, intrusion detection services and security information dissemination, etc; and iii) Artifacts treatment: artifacts analysis, response to artifacts, coordination of response to artifacts, risk analysis, continuation and resumption of activities after disaster, security consultation and sensitization campaign, education/training and product appraisal or certification. AU Draft0 010111

Select target paragraph3