14. Response
Response contingency plans to deal with cyber security threats must be developed and
tested by means of exercises. The focus must be on protecting important elements in the
national infrastructure.
Main aim No. 3: Strengthened legislation
Icelandic legislation should reflect the international demands and obligations the country
undertakes regarding cyber security and the protection of personal data. Furthermore, legislation
must also support innovation and the development of security related services, e.g. hosting.
Good legislation is a crucial factor for developing cyber security. Its importance is clear in many
contexts:
• Iceland is a member of international agreements under which it is obliged to meet certain
requirements in its domestic legislation. This applies to the Budapest Convention on
Cybercrime of 2001.
• As the Internet is international, it is important that Iceland’s legislation should be compatible
with that of its neighbours as far as possible. Legislation must ensure personal data safety
and serve as a basis to create an attractive environment for IT companies to operate and
develop in.
• Legislation must not contain loopholes that might attract criminal organisations.
• The European Union’s strategy on cyber security must be taken into account in Iceland’s
legislation.
• The use of cloud technology entails various legal implications and challenges. Attention must
be given to what other countries, and the EU, are doing in this area and what legal
interpretations they follow.
• The reporting of cyber security incidents must be made obligatory. It would be desirable to
have this obligation expressed in such a way that entities see it as being in their interest, as
well as being obligatory, to report these incidents. For example steps must be taken to avoid
the impression that reporting might damage the image or competitive position of a company
and that competitors might gain an advantage by staying silent. The arrangement already in
place regarding traffic accidents could be used as a frame of reference for this, as
appropriate.
15. Strengthened legislation
A review of Icelandic legislation should be made to ensure that it conforms to the country’s
international obligations and makes it possible to tackle cyber security threats in the same
way as is done in other Nordic countries. At the same time, it must be ensured that cyber
security threats can be appropriately tackled in the same way as other threats.
11