CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012
affected users, the sensitivity level of the information that is concentrated, stored, transmitted
or processed on these infrastructures, etc.
check the criteria with the development of scenarios that consider the disruption of operation
of selected infrastructure, within the bounds of regular exercises.
Action 7 - Phase A – Identification and assessment of the critical information infrastructures in
the republic of Cyprus, to better target activities and actions for their protection, with the
contribution of both the public and private sectors.
3.7
Threat Landscape Analysis
Section 2.4 mentioned the general threats that can manifest in cyberspace. It is important to note that
available information on the specific mix of threats that appear in Cyprus and which can rise in the
future is limited. The protection of information infrastructures can be achieved through general
measures only (to some extent), but the strategic response to threats in cyberspace will be greatly
improved if the main threats that are actually present and manifest in Cyprus become known. This will
not only allow better targeting of response measures, but also better targeting of the most prevalent
threats if the necessary protective controls are put in place gradually through a feasible implementation
programme for the provisions of this Strategy.
A comprehensive threat landscape and attack analysis is therefore necessary (including attacks that are
widespread in Cyprus and other European countries), so that the improved targeting of response
methods can be achieved, as discussed above. This analysis will be combined with the most prevalent
threats that are discussed in European and other international reports for a more complete and
comprehensive review.
Action 8 - Phase B – Comprehensive survey to record current threats and attacks in cyberspace
that have been published in Cyprus, as well as monitoring new threats that appear in the
European and international space.
3.8
National Cybersecurity Framework
The easiest and most effective method to achieve an acceptable level of security in all critical
information infrastructures in the Republic of Cyprus is to develop a National Cybersecurity Framework,
which will be used as the basis for the protection of critical information infrastructures, and for
information assurance. This framework must be developed based on international security standards
and include the following (among others):
21