Main aim No. 2: Increased resilience
An upgrading of the resilience of information systems. Greater capacity in the fields of assessment,
preparedness and response as key factors in increased resilience.
Monitoring and response capacity must be increased so as to respond to abnormal situations on the
Internet. Nevertheless, full regard must be given to appropriate considerations of personal data
integrity.
It must be possible for key entities to exchange information about possible threats quickly. Therefore
it is important to establish one or more collaborative forums on which information on cyber security
threats can be shared in a clearly defined manner without infringement of competition or personal
data considerations. This could require mediation through a public body to ensure that it is possible
to share information on cyber-threats quickly without revealing the identity of the target.
The pace of development in the field of cyber security is very rapid. For this reason it is important
that all entities involved are active in international collaboration, each in its respective area. Close
collaboration between stakeholders in Iceland, with efficient exchange of information, will make it
possible to respond jointly to rapid change. Active participation in international collaboration is also
necessary to maintain flexibility, skills and contacts and be able to work with other national and
supranational authorities when a crisis on the Internet looms. It is also vital that Iceland presents a
single coordinated strategy in cyber security matters when the country takes part in international
collaboration.
Increased resilience in information systems will depend on reliable design. Reliable design must be a
crucial consideration in the purchase and development of software, particularly in the case of key
elements in IT infrastructure. This applies at the national, corporate and individual level.
7. A collaborative forum
A forum must be established where representatives of government and private enterprises
can work together on cyber security issues.
8. Security yardsticks
Choice of appropriate yardsticks (standards and others) for cyber security.
9. International collaboration
Iceland’s involvement in cyber security abroad must be increased and coordinated.
10. Reliability of primary data systems
Telecommunications systems and the primary data transmission networks must offer
support, with a defined degree of reliability, the Internet and IT networks of key elements in
Iceland’s infrastructure, both as regards connections within the country and their interface
with other countries.
11. Public administration
Cyber security in the field of public administration must be upgraded by means of increased
training, coordination and collaboration.
12. Analysis
Principal cyber security threats must be analysed and key elements in the Icelandic
infrastructure identified.
13. Protection of the infrastructure
The capacity of the cyber security team to raise the level of protection and assist important
elements in the national infrastructure must be increased, and an active response
mechanism must be in place on a round-the-clock basis every day of the year. Particular
emphasis should be placed on telecoms, utilities and financial companies and the systems
necessary for international aviation.
10