CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012 2. STRATEGIC CONTEXT 2.1 European Policy Security matters form an important pillar of the Digital Agenda for Europe, and this specific European policy covers a number of important topics related to network and information security. The position of the European Commission regarding these issues is covered in detail in the strategy document for Network and Information Security (NIS). In addition to this, and as part of the application of European policy in this area, the European Network and Information Security Agency (ENISA) was created and has been operational since 2004. This organisation is headquartered in Herakleion, Crete and it develops pan-European and international actions in the area of network and information security, helping the application of European policy, the dissemination of information and best practices, the harmonisation and coordination of common actions, the organisation and execution of European and international cyber exercises and also international cooperation and coordination. The renewal of ENISA’s operations (in time), with expanded terms of mandate, is the subject of intensive consultations during this period at the Council of Ministers level, and also in the European Parliament, given that everyone recognises the necessity of such an organisation to exist and operate in Europe. The new European Regulatory Framework for Electronic Communications (with a May 2011 date of entry into force on a pan-European level), places special emphasis on the area of security, mainly in topics relating to: (a) the security and integrity of networks and services, as well as the application of regulatory measures and cooperation mechanisms on a national and pan-European level, together with national notification mechanisms for security breach incidents, contained in the Framework Directive (2002/21/EC, as amended), and (b) the security of personal data, the processing of such data and related security breaches, the protection of data contained within customer terminal equipment, and the use of automated calling systems and communication without human intervention, contained in the Directive on Privacy and Electronic Communications (2002/58/EC, as amended). Additionally, cybersecurity matters have recently been placed high on the agenda of the Telecommunications Ministerial1 Council of the European Union. The Council, during its recent meetings, has examined policy and the actions to follow, including the preparation of new Directives in the area of security and especially for Critical Information Infrastructure Protection (CIIP). The Council has also requested the cooperation between Member States, the European Commission and third countries for: (a) the identification and securing of parts of critical infrastructure that could, if damaged or destroyed, have severe negative effects on member states, and (b) the exchange of information and best practices, while (c) urging member states to encourage effective cooperation between public and private sector entities, both within the member states themselves and with third 1 The finalisation of the new European Strategy for Internet Security will form part of the activities of the Telecommunications Ministerial Council under the Cyprus Presidency of the Council. 8

Select target paragraph3