CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012
the appropriate legal authority and defined responsibility in order to carry out its duties,
the necessary skills and capabilities to respond appropriately to the obligations of the role,
the necessary links and good working relationships with the competent or relevant authorities
of the Republic, the electronic communications providers in Cyprus, the private sector
stakeholders and international working groups and fora that are relevant to the area of
cybersecurity.
Taking into account the fact that the definition and creating of an integrated and complete
organisational structure is necessary for the optimum implementation of the strategic actions, but also
that the processes involved to accomplish this are affected by external factors related to the current
severe financial crisis that is manifesting in Cyprus, and the lengthy recruitment procedures involved,
the implementation of such an organisational structure will form part of Phase B of the strategy
activities. This will have the following benefits:
The planning and executing of the actions that have been identified as being of an urgent nature
and with immediate priority, for which the legal framework is already in place, will not be
delayed.
Existing structures will be leveraged to the maximum extent possible, with gradual upgrading of
their capabilities to the required level.
The associated financial burden will be gradual and in line with the capabilities of the Cyprus
economy.
Cypriot authorities will be in a position to fulfil their commitments both on the national and
European level, where relevant activities are being pushed forward with rapid and demanding
timelines.
The necessary time will be given for the appropriate needs assessment, in relation to the
requirements for the strategy implementation, the coordination of activities and the supervision
of incident response mechanisms and related actions.
Phase A will formulate the cooperation framework between OCECPR, as the coordinating body, and the
other competent authorities for the implementation of the high priority actions, such as developing the
plan for the protection of critical information infrastructures, the operation of the governmental
CSIRT/CERT, the assessment and improvement of the readiness levels of network infrastructures as
regards their resilience to risk and their response to security threats, the handling and notification of
security incidents on networks, systems and information, and the organisation of national exercises with
additional participation in European exercises. These activities refer to the wider responsibilities that
OCECPR has in the area of network and information security, and section 2.2 discusses the specific
actions that have been prioritised and have been included in this strategy. At this point, an agreed basis
for cooperation is required between the competent authorities, and which will be expanded and
adjusted as the strategy programme progresses.
16