CYBERSECURITY STRATEGY OF THE REPUBLIC OF POLAND
CYBERSECURITY STRATEGY OF THE REPUBLIC OF POLAND
2. Strategic context of cybersecurity in the Republic of Poland
T
he Cybersecurity Strategy of the Republic of Poland for 2019–2024 is a continuation and
extension of actions taken by the government administration to increase the level of cybersecurity in the Republic of Poland. As part of actions taken to date, the Act of 5 July 2018 on the
national cybersecurity system (Journal of Laws of the Republic of Poland, item 1560)2 entered into
force and the government beforehand also adopted the following documents:
•
•
in 2013, the Policy for the Protection of Cyberspace of the Republic of Poland,
in 2017, the National Framework of Cybersecurity Policy of the Republic of Poland for
2017–2022.
The Cybersecurity Strategy of the Republic of Poland for 2019–2024 supersedes the National Framework of Cybersecurity of the Republic of Poland for 2017–2022 adopted under Resolution no.
52/2017 of the Council of Ministers of 27 April 2017 regarding the National Framework of Cybersecurity of the Republic of Poland 2017–2022.
The purpose of this document is to define strategic objectives and relevant political and regulatory
measures to achieve a high level of cybersecurity, principally a resilience to cyber threats of information systems used by operators of essential services , critical infrastructure operators, digital
service providers and the public administration, as well as to increase information protection in
the information systems by means of standardised safeguards. The achievement of the strategic
objectives shall also contribute to increasing the national security, improving the effectiveness of
law enforcement agencies and judicial authorities in detecting and combating cybercrime, events
of a hybrid nature (including events of a terrorist nature) and cyberespionage.
3. Scope of the Cybersecurity
Strategy of the
Republic of Poland for 2019–2024
The Strategy takes into account, in particular5:
1.
2.
3.
4.
cybersecurity objectives and priorities;
entities involved in the implementation and deployment of the Strategy;
measures used to achieve the objectives of the Strategy;
specification of means for readiness, response and restoration, including principles
of public-private cooperation;
5. risk assessment approach;
6. activities related to educational, information and training programmes regarding
cybersecurity;
7. activities related to research and development plans regarding cybersecurity.
Furthermore, the Strategy takes into account international cooperation regarding cybersecurity.
Introduced by way of a resolution of the Council of Ministers, the Cybersecurity Strategy of the
Republic of Poland for 2019–2024 directly affects entities of the government administration and,
indirectly, after the adoption of applicable general law on the initiative of the Council of Ministers,
other public authorities, businesses and citizens.
The Cybersecurity Strategy of the Republic of Poland for 2019–2024 is aligned with ongoing operations related to ICT systems used by critical infrastructure operators. It also takes into account
the need to enable the Armed Forces of the Republic of Poland - in domestic, alliance and coalition contexts - to conduct military operations in the event of cyber threat which requires defensive operations.
By implementing the Cybersecurity Strategy of the Republic of Poland for 2019–2024, the government will fully guarantee the right to privacy and hold the position that free and open Internet is
an important element of the functioning of a modern society.
2
The Act of 5 July 2018 on the national cybersecurity system implements Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union (Official Journal of the EU L 194, 19.07.2016, p. 1).
3
Applies to operators of essential services referred to in Article 5 of the Act of 5 July 2018 on the national cybersecurity system.
4
Applies to digital service providers referred to in Article 17 of the Act of 5 July 2018 on the national cybersecurity system.
8
5
Article 69(2) of the Act 5 July 2018 on the national cybersecurity system.
9