Introduction
A task force to address strategy on cyber security in Iceland was appointed by the Ministry of the
Interior in June 2013. Its main task is to formulate government strategy on cyber security and the
protection of IT infrastructure elements that are relevant to national security, i.e. the IT systems of
key institutions in Icelandic society. Most of these systems are in turn linked to other IT systems in
one way or another via the Internet.
Demarcation of the strategy
The strategy is intended to address the protection of important elements of the infrastructure in
Iceland and the responses called for in view of the growing cyber-threats which pose a hazard to the
government, the economy and the ordinary citizen. The Internet has already become an integral part
of the daily life of almost all people in Iceland and will continue to do so to an ever-greater degree. In
this environment, security is of paramount importance; hence, the strategy covers all use of the
Internet and Information Technology.
The social aims of the strategy are as follows:
•
To enhance the security of individuals and groups in society by increasing cyber
security.
•
To promote the integrated functioning of important elements of the infrastructure of
society by increasing the resilience of cyber systems to cope with hazards.
•
To establish closer collaboration and coordination on cyber security between
Icelandic and international authorities.
Efficient collaboration must be established between Icelandic and international authorities, with a
demarcation of the division of responsibilities and tasks between them in the field of cyber security.
In drawing up the strategy, attention was given to various other strategies in this field, both in
Iceland and in the other Nordic countries and also those of international organisations of which
Iceland is a member.
The task force consists of: Sigurður Emil Pálsson, a specialist at the Ministry of the Interior
(Chairman); Guðbjörg Sigurðardóttir, Head of Department in charge of the Information Society
Project at the Ministry of the Interior; Páll Heiðar Halldórsson and Ottó V. Winther, specialists at the
Ministry of the Interior, Jón F. Bjartmarz, Detective Chief Superintendent and Ágúst Finnsson (from
January 2014), specialist, at the Office of the National Commissioner of the Icelandic Police, Hrafnkell
V. Gíslason, Director of the Post and Telecom Administration, Stefán Snorri Stefánsson, Head of the
National CERT - CERT-ÍS at the Post and Telecom Administration, Jónas Haraldsson, specialist at the
Ministry of Foreign Affairs and Þorsteinn Arnalds (from May 2014), specialist at the Data Protection
Authority (Persónuvernd).
The task force focused on reviewing the general foundations and recommendations on which
strategies in this area have been based. The strategies of some of the other Nordic countries were
examined and discussions were held with domestic and foreign parties, consultants and government
officials on various aspects of information security. The task force also discussed the threats and
opportunities that have been defined and the experience gained from the plans of action already
been put into practice in other Nordic countries.
A well-attended consultative meeting with stakeholders was held on 2 June 2014. Those present
included about 80 representatives of some 60 institutions and enterprises. Another similar meeting,
4