CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012         Governance and risk management Vulnerability assessment Regular penetration testing Management of physical spaces, hardware and software Appropriate staff authorisation Physical security and environmental management Making use of CERTs for incident management (see section 3.9) Continuous monitoring of electronic communications for malicious attacks to determine incidents in progress. This Framework must be adopted by all operators of critical information infrastructures, and must also be examined for adoption by all government departments and other important organisations in Cyprus. To achieve this target, the National Cybersecurity Framework will be developed in such a way so that it can be promoted within the remainder of the private sector, for the optimum protection of all those that use electronic communications services. Action 9 - Phase B – Development of a National Cybersecurity Framework which will promote the protection of critical information infrastructures in the Republic of Cyprus, as well as governmental departments and services. It should be noted that the specific targets that will be set for the protection levels for these technologies and systems will be determined based on appropriate risk analysis and balancing these levels with the associated cost of implementing specific controls to respond to threats in cyberspace. A usual method used is to keep the related annual costs below the annual estimated cost of damages or losses if these threats were to manifest on information and communications networks and systems. 3.9 Incident Response Ensuring the full functionality of Computer Emergency Response Teams (CERTs/CSIRTs) within Cyprus is an integral and vital part of this Strategy, and also of meeting our commitments as a nation. The main functions of a CERT are the prevention of serious incidents related to network and information security, as well as the immediate and appropriate response to such incidents when they occur. It is emphasised that for the correct operation of a CERT/CSIRT, the following are required: (a) necessary infrastructure and (b) staffing with appropriately trained (to a very high level) personnel. A basic prerequisite for such services to operate effectively is strong support from the State. The cooperation between CERTs/CSIRTs that operate in each member state lies within the framework of European cooperation in the area of information security. Given the target of integrating Cypriot 22

Select target paragraph3