National strategic framework for cyberspace security acting as the coordination point in the response to large-scale cyber events. Activation of all appropriate cooperation mechanisms at the national and international level, making the national CERT the main interface of other public and private CERTs operating both domestically and outside national borders, including the European CERT. Development of a communication platform to facilitate, both at the technical and at the functional level, communications among all CERTs, so as to ensure timely and effective interaction between all stakeholders involved in preventing and countering malicious cyber activity. Development and attainment of the full operational capability of the Public Administration’s Computer Emergency Response Team (CERTPA), which represents the evolution of the CERT developed with the Public System of Connectivity (SPC) established by the Presidential Decree of the 1st April 2008. The CERT-PA is the designated first point of contact for all Public Administrations, which will report to the national CERT in accordance with specific unitary models and procedures. The CERT-PA works in coordination with the other Public Administrations’ CERTs at the European level through exchanges of information and agreed procedures. The CERT of the Armed Forces follows the technical, functional and procedural developments and guidelines of the NATO Computer Incident Response Capability (NCIRC), and it will be fully integrated in the military operational planning. Ensure effectiveness of cyber security countermeasures by means of organisational and regulatory proposals that adapt to the rapid progress of information technology. Establishment of security standards and requirements for products and systems implementing security protocols. Introduction of processes to certify the compliance to these security standards and, where appropriate, implementation of new procedures for the procurement of ICT products on the national territory. These standards and procedures should always guarantee international interoperability, especially with NATO and UE countries. 24 Establishment and adoption of technical norms to guarantee the security of information (integrity,

Select target paragraph3