14. Response Response contingency plans to deal with cyber security threats must be developed and tested by means of exercises. The focus must be on protecting important elements in the national infrastructure. Main aim No. 3: Strengthened legislation Icelandic legislation should reflect the international demands and obligations the country undertakes regarding cyber security and the protection of personal data. Furthermore, legislation must also support innovation and the development of security related services, e.g. hosting. Good legislation is a crucial factor for developing cyber security. Its importance is clear in many contexts: • Iceland is a member of international agreements under which it is obliged to meet certain requirements in its domestic legislation. This applies to the Budapest Convention on Cybercrime of 2001. • As the Internet is international, it is important that Iceland’s legislation should be compatible with that of its neighbours as far as possible. Legislation must ensure personal data safety and serve as a basis to create an attractive environment for IT companies to operate and develop in. • Legislation must not contain loopholes that might attract criminal organisations. • The European Union’s strategy on cyber security must be taken into account in Iceland’s legislation. • The use of cloud technology entails various legal implications and challenges. Attention must be given to what other countries, and the EU, are doing in this area and what legal interpretations they follow. • The reporting of cyber security incidents must be made obligatory. It would be desirable to have this obligation expressed in such a way that entities see it as being in their interest, as well as being obligatory, to report these incidents. For example steps must be taken to avoid the impression that reporting might damage the image or competitive position of a company and that competitors might gain an advantage by staying silent. The arrangement already in place regarding traffic accidents could be used as a frame of reference for this, as appropriate. 15. Strengthened legislation A review of Icelandic legislation should be made to ensure that it conforms to the country’s international obligations and makes it possible to tackle cyber security threats in the same way as is done in other Nordic countries. At the same time, it must be ensured that cyber security threats can be appropriately tackled in the same way as other threats. 11

Select target paragraph3