CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012
2. STRATEGIC CONTEXT
2.1
European Policy
Security matters form an important pillar of the Digital Agenda for Europe, and this specific European
policy covers a number of important topics related to network and information security. The position of
the European Commission regarding these issues is covered in detail in the strategy document for
Network and Information Security (NIS). In addition to this, and as part of the application of European
policy in this area, the European Network and Information Security Agency (ENISA) was created and has
been operational since 2004. This organisation is headquartered in Herakleion, Crete and it develops
pan-European and international actions in the area of network and information security, helping the
application of European policy, the dissemination of information and best practices, the harmonisation
and coordination of common actions, the organisation and execution of European and international
cyber exercises and also international cooperation and coordination. The renewal of ENISA’s operations
(in time), with expanded terms of mandate, is the subject of intensive consultations during this period at
the Council of Ministers level, and also in the European Parliament, given that everyone recognises the
necessity of such an organisation to exist and operate in Europe.
The new European Regulatory Framework for Electronic Communications (with a May 2011 date of
entry into force on a pan-European level), places special emphasis on the area of security, mainly in
topics relating to: (a) the security and integrity of networks and services, as well as the application of
regulatory measures and cooperation mechanisms on a national and pan-European level, together with
national notification mechanisms for security breach incidents, contained in the Framework Directive
(2002/21/EC, as amended), and (b) the security of personal data, the processing of such data and
related security breaches, the protection of data contained within customer terminal equipment, and
the use of automated calling systems and communication without human intervention, contained in the
Directive on Privacy and Electronic Communications (2002/58/EC, as amended).
Additionally, cybersecurity matters have recently been placed high on the agenda of the
Telecommunications Ministerial1 Council of the European Union. The Council, during its recent
meetings, has examined policy and the actions to follow, including the preparation of new Directives in
the area of security and especially for Critical Information Infrastructure Protection (CIIP).
The Council has also requested the cooperation between Member States, the European Commission and
third countries for: (a) the identification and securing of parts of critical infrastructure that could, if
damaged or destroyed, have severe negative effects on member states, and (b) the exchange of
information and best practices, while (c) urging member states to encourage effective cooperation
between public and private sector entities, both within the member states themselves and with third
1
The finalisation of the new European Strategy for Internet Security will form part of the activities of the
Telecommunications Ministerial Council under the Cyprus Presidency of the Council.
8