CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012 Action 16 - Phase A – Development of a National Contingency Plan, which will contain detailed processes and measures that will be taken when a large scale crisis affects the operations of critical information infrastructures in the Republic of Cyprus to a significant degree, with the aim of maintaining their operation at an acceptable minimum level until full restoration. 3.15 Interdependencies This Strategy places special emphasis on the interdependencies and interactions between the actions that are described, even though each one has its own specific and separate targets, for its successful completion. The strategic response to threats against network and information security must be approached in a holistic fashion and it needs to be understood that many of these actions have to be implemented in combination, with the target of maximal success of such a strategic response. Interdependencies are also evident in other levels of this response. As can be seen in section 2.3, there are a number of competent authorities handling different aspects of security, each one with its own areas of responsibility. Despite the fact that duplication needs to be avoided, all interdependencies must be recognised and the cooperation between these authorities must be ensured so that the specialised knowledge and capabilities within each authority can be leveraged to maximum effect. These interdependencies are large in number, and so it is necessary to identify and study them, as well as incorporate them into any future actions or response plans that may be developed. In addition to this, operators of critical information infrastructures must explore, as part of their activities to manage threats and risks and for the development of business continuity plans, the interdependencies that they have for the secure management of their infrastructures, at all levels. In other words, the following questions needs to be answered:   On whom does the business depend in relation to security? Who depends on the business in relation to security? It is noted that an initial depiction of the interdependencies between the actions described in this document can be found in Appendix II. Action 17 - Phase A/B – Identification and study of the interdependencies that exist for the implementation of this Strategy. These interdependencies will initially be identified as existing in the relationships between the actions themselves, the relationships between the competent authorities of the State, and the relationships between the critical infrastructure operators with their suppliers, customers and staff. These interdependencies must be recognised and accepted by all relevant stakeholders. 28

Select target paragraph3