To do List Phase Action Items Check Risk Understand external/internal environment. □ Evaluation Identify threats to your organizations. □ Raise all the risks regarding cyber security. □ Establish risk evaluation criteria and method. □ Evaluate impact of the risks. □ Identify risks to be mitigated. □ Establish evaluation criteria. □ CII Identification Identify critical IT services for your national □ security. Usable Estimate impact on critical IT services. □ Identify IT services to be protected. □ Create IT inventory list regarding the services. □ Identify CII to be protected. □ Estimate usable budget. □ Resources Estimate usable human resources (both in skills □ Estimation and numbers). □ Estimate usable IT infrastructures. □ Estimate possible external aids. □ 5

Select target paragraph3