Glossary of cybersecurity implementation of a coherent and uniform methodology for managing ICT incidents. The CERT-SPC is primary point of contact for all Local Units of Security (ULS) established for each network domain connected with the SPC. non-authorized activities carried out against computer networks and IT systems. CNE – Computer Network Exploitation Operations carried out in cyberspace in order to extract information from targeted ICT networks or computer systems. They are intelligence gathering activities, or actions preparing the execution of a cyber attack. CNA – Computer Network Attack Activities that are conducted in and through the cyberspace in order to manipulate, obstruct, deny, downgrade or destroy information stored in the ICT networks or in the computer systems, or the ICT networks or in the computer systems themselves. CNO – Computer Network Operation This term generally encompasses Computer Network Attack (CNA), Computer Network Defence (CND) and Computer Network Exploitation (CNE). CNAIPIC – National Anti-crime Computer Centre for the Protection of Critical Infrastructure The CNAIPIC, established by Law no. 155/2005 and with a Decree of the Minister of the Interior of 9th February 2008, is set within the Service of Postal Police and Communications, which is responsible for the security and the integrity of IT communications of the Ministry of the Interior, National Authority of Public Security. The Centre, as provided for by law, is responsible for ensuring prevention and repression of cyber crimes against critical infrastructures or ICT assets of national relevance, even through partnership agreements with the structures concerned. CPS – Cyber Physical System ICT networks and computer systems supporting, managing and supervising physical assets such as civil infrastructures, aerospace, transports, health care, energy and production processes. CSBM – Confidence and Security Building Measures Measures aimed at preventing or resolving hostilities among States, and at avoiding their worsening by developing mutual confidence. Such measures can have formal or informal, bilateral or multilateral, military or political nature. DoS – Denial of Service Attack aimed at making a computerized system or resource unavailable to legitimate users by saturating and overloading server’s network connections. CND – Computer Network Defence Actions taken by using computer networks for protecting, monitoring, analyzing, detecting, and hindering 41

Select target paragraph3