National strategic framework for cyberspace security PRESIDENCY OF THE COUNCIL OF MINISTERS DIS, AISE, AISI Intelligence collection finalized to strengthening national cyberspace protection and IT security. and reports originated by the two Agencies, the Police, the Armed Forces, all Public Administrations and public and private research Institutes, all-sources intelligence, and data gathered from Public Administrations and public utilities service providers; • The Department for Intelligence and Security (DIS) and the two intelligence Agencies carry out their activities in the field of cybersecurity by making use of the tools, means and procedures set forward by Law no. 124/2007, as amended as by Law no. 133/2012. To that end, following the Prime Minister’s directives for the strengthening of intelligence collection activities for the protection of physical and intangible ICT critical national infrastructure, and taking into account the general guidelines and objectives put forward by the Committee for the Security of the Republic (CISR), the General Director of DIS coordinates all intelligence collection activities to bolster national cyberspace protection and ICT security. – In full compliance with the Prime Minister’s Decree of the 24th January 2013, it provides for the transmission of relevant information and alerts regarding cybersecurity issues to the Cybersecurity Unit, to Public Administrations and to other subjects, including in the private sector, interested in the acquisition of such security information; – On the basis of what is foreseen in the Prime Minister’s Decree of the 22nd July 2011, defines the cybersecurity requirements that need to be adopted for the protection of ICT systems and infrastructures that store and process classified or secreted information, issuing the required technical homologations and • The Department for Intelligence and Security, through its various offices: – Ensures the support to the Director General’s coordinating role; – Provides analysis, assessment and previsions regarding the cyber threat, taking into account relevant information, analyses 32

Select target paragraph3