CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012 Action 1 - Phase A – Formulation of the framework for collaboration and information exchange with OCECPR, and between public authorities, so that OCECPR will be in a position to effectively coordinate the nation’s strategic response in the area of cybersecurity and the protection of critical information infrastructures, as well as coordinating the actions that relate to other stakeholders in the priority areas that can be addressed immediately. The way that existing activities in the area of network and information security, that fall under the responsibilities of OCECPR, are planned and executed is based on its existing organisational structure. The present structure and resources are not adequate to take on and execute all of the actions that are described in this document. As a result of this, and in tandem with pushing forward with the immediate priorities based on current urgent national and European commitments and needs of the Republic of Cyprus, OCECPR, in cooperation with the other competent authorities in the Republic, will study and submit recommendations regarding new policy for its reorganisation to the Minister of Communications and Works, so that it will be in a position to fully coordinate the very large volume of work associated with the areas of network and information security and cybersecurity. Action 2 - Phase A – OCECPR will, at the appropriate time and in cooperation with the other competent authorities, develop a report regarding new policy for its reorganisation, so that it will be in a position to fully coordinate the efforts of the Republic of Cyprus for optimum implementation, application and supervision of all of the actions and the effective response to threats that are prevalent in cyberspace today, as well as rising threats that will appear in the future. OCECPR will also coordinate the formation of a number of working groups, which will take over the implementation of the rest of the actions that are described herein. These working groups will be staffed by personnel with the necessary technical and other skills from the competent authorities of the state, as well as by experts from the private sector and representatives of critical information infrastructure operators (see also section 3.5). For the identification and assessment of potential risks, it may be the case that the members of some of the working groups might need access to classified information; that is the information that refers to vulnerabilities in critical parts of each network or system that will be deemed as important or critical. Taking into account that the relevant risk assessments must be conducted in tandem with the development of plans to respond to incidents relating to these risks, and also the development of contingency plans to mitigate the effects of related disasters, the composition of the working groups must be such that confidentiality is assured. 17

Select target paragraph3