ANNEX 1 PUBLIC STAKEHOLDERS’ ROLES AND MANDATES The Prime Minister’s Decree of the 24th January 2013 outlined the institutional architecture devoted to cyber protection and ICT security, one in which the various stakeholders involved, both from the private and the public sectors, act in an integrated and consistent way so as to mitigate cyberspace vulnerabilities, identify threats, prevent risks and enhance the national capability to counter crisis situations. At the top of such architecture is the Prime Minister, who adopts the present National Cybersecurity Strategic Framework and the National Plan, and who ensures its practical implementation through the adoption of specific directives. The Prime Minister is supported in this endeavor by the Committee for the Security of the Republic (CISR), which may propose the adoption of legislative initiatives, approves the guidelines to foster public-private partnerships, the policies for enhancing info-sharing arrangements and the endorsement of best practices, and approves other measures to strengthen cybersecurity. The Committee for the Security of the Republic at Working Level (the so called “Technical CISR”) is in charge of the verification of the timely and correct implementation of the National Plan for cybersecurity, which complements the National Cybersecurity Strategic Framework. Supporting the political level is the national intelligence community, that gathers intelligence, produces all-source analysis, evaluations and forecasts about the cyber threat, contributes to the promotion of cybersecurity awareness and education, and provides relevant information and alerts to the Cybersecurity Unit and to other public and private stakeholders. The Cybersecurity Unit is established within the Prime Minister Military Advisor’s Office with the mandate of coordinating the various institutions that compose the national cybersecurity architecture, preventing and preparing for situations of crisis, and for early warning. Notwithstanding the primary responsibility of each Administration for the ownership, custody, protection and data processing of their database and digital archives, the Cybersecurity Unit: 27

Select target paragraph3