ANNEX 1
PUBLIC STAKEHOLDERS’ ROLES AND
MANDATES
The Prime Minister’s Decree of
the 24th January 2013 outlined the
institutional architecture devoted to cyber
protection and ICT security, one in which
the various stakeholders involved, both
from the private and the public sectors,
act in an integrated and consistent way so
as to mitigate cyberspace vulnerabilities,
identify threats, prevent risks and enhance
the national capability to counter crisis
situations.
At the top of such architecture is
the Prime Minister, who adopts the
present National Cybersecurity Strategic
Framework and the National Plan, and
who ensures its practical implementation
through the adoption of specific
directives. The Prime Minister is supported
in this endeavor by the Committee for the
Security of the Republic (CISR), which
may propose the adoption of legislative
initiatives, approves the guidelines to
foster public-private partnerships, the
policies for enhancing info-sharing
arrangements and the endorsement
of best practices, and approves other
measures to strengthen cybersecurity. The
Committee for the Security of the Republic
at Working Level (the so called “Technical
CISR”) is in charge of the verification of
the timely and correct implementation of
the National Plan for cybersecurity, which
complements the National Cybersecurity
Strategic Framework.
Supporting the political level is the
national intelligence community, that
gathers intelligence, produces all-source
analysis, evaluations and forecasts
about the cyber threat, contributes
to the promotion of cybersecurity
awareness and education, and provides
relevant information and alerts to the
Cybersecurity Unit and to other public
and private stakeholders.
The Cybersecurity Unit is established
within the Prime Minister Military
Advisor’s Office with the mandate of
coordinating the various institutions
that compose the national cybersecurity
architecture, preventing and preparing
for situations of crisis, and for early
warning. Notwithstanding the primary
responsibility of each Administration for
the ownership, custody, protection and
data processing of their database and
digital archives, the Cybersecurity Unit:
27