CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012 countries. The Council has also asked to be updated, together with the European Parliament, on an annual basis by member states and the European Commission regarding their actions in these matters. After the meeting of the Telecommunications Ministerial Council on the 27th of May 2011, in which these matters were discussed, the European Commission announced the actions that it expects the member states of the European Union to undertake, asking for the commitment of all those involved for the promotion of common goals. Specifically, the European Commission is requesting that member states and the Council state their strong commitment to the improvement and strengthening of national security in cyberspace to the best of their abilities, with the target of securing a high level of protection within the European Union and more effective collaboration on the international level. As such, the European Commission is planning to monitor the performance of the member states closely, as regards meeting the three basic targets that are being promoted on the European level: (a) The operation of national / governmental Computer Emergency Response Teams (CERTs) in each member state and the creation of a common and functional network of national / governmental CERTs in Europe by 2012, which will be supported by effective national cybersecurity strategies. (b) The organisation of regular national and pan-European exercises for security in cyberspace (with CERTs participating as a prerequisite), in which a pan-European cyber exercise which has been scheduled for the second half of 2012 is included. (c) The development of national contingency plans for network and information security, and incidents in cyberspace, and the contribution of all member states to the development of a European contingency plan for emergencies in cyberspace within 2012. Based on national experiences, such a plan must lay the foundation and define appropriate processes for effective communications between member states in situations where common threats and malicious attacks affect a number of member states. On a national level, the actions described in points (b) and (c) above form part of the actions that are included in this Strategy. The action referred to in point (a) above is already in progress in the Republic of Cyprus and is regulated by separate secondary legislation that is published by the Commissioner for Electronic Communications and Postal Regulation, while the correct operation of CERTs/CSIRTs in Cyprus is a basic precondition for the development of the strategic planning that is described in this document. These same points were the subject of a special Ministerial Conference that took place in Hungary in April 2011, in the context of the work plans of the Presidency of the Council and of the European Commission during the first half of 2011. All member states were represented at this conference, which was under the auspices of the Telecommunications Ministerial Council and under the area of network and information security. The conference conclusions cover the duties of the member states in detail, as described in this section. Specifically regarding the matters related to CERTs, the conference conclusions state that: 9

Select target paragraph3