National strategic framework for cyberspace security
acting as the coordination point in
the response to large-scale cyber
events.
Activation of all appropriate
cooperation mechanisms at the
national and international level,
making the national CERT the main
interface of other public and private
CERTs operating both domestically
and outside national borders,
including the European CERT.
Development of a communication
platform to facilitate, both at the
technical and at the functional
level, communications among all
CERTs, so as to ensure timely and
effective interaction between all
stakeholders involved in preventing
and countering malicious cyber
activity.
Development and attainment of
the full operational capability of the
Public Administration’s Computer
Emergency Response Team (CERTPA), which represents the evolution
of the CERT developed with the
Public System of Connectivity (SPC)
established by the Presidential
Decree of the 1st April 2008. The
CERT-PA is the designated first
point of contact for all Public
Administrations, which will report
to the national CERT in accordance
with specific unitary models and
procedures. The CERT-PA works in
coordination with the other Public
Administrations’ CERTs at the
European level through exchanges of
information and agreed procedures.
The CERT of the Armed Forces
follows the technical, functional
and procedural developments
and guidelines of the NATO
Computer
Incident
Response
Capability (NCIRC), and it will
be fully integrated in the military
operational planning.
Ensure effectiveness of cyber
security countermeasures by means
of organisational and regulatory
proposals that adapt to the rapid
progress of information technology.
Establishment
of
security
standards and requirements for
products and systems implementing
security protocols. Introduction of
processes to certify the compliance
to these security standards and,
where appropriate, implementation
of new procedures for the
procurement of ICT products on
the national territory. These
standards and procedures should
always guarantee international
interoperability, especially with
NATO and UE countries.
24
Establishment and adoption of
technical norms to guarantee the
security of information (integrity,