comprehensive incident approach, through which it is possible to learn from
partners and share mitigation techniques;
Ensure that incidents are mandatorily and promptly reported to the Nation’s
Cyber Security Authority, namely the NCISA, thus allowing an understanding
of the magnitude, scope, and severity of the threat;
Identify the root causes of attacks at the national level, reducing the incidence of
multiple and repeated exploitation on several victims and sectors;
Use relationships with other IT security incident response teams, both at the
domestic and international level, as part of an incident management protocol;
Measure Cyber Crime using reliable statistics and analysis of digital crimes to guide
responsive action. In the absence of such statistics, public authorities cannot
continuously reassess policies and implement adequate measures. In this case, the
Ministry of the Interior must implement new instruments to monitor the
evolution of Cyber Crime to guide public action;
Establish a database of cyber incidents to enable both a broad view and detailed
analysis of Cyber Threat trends to identify security solutions and/or product and
service needs. This would also benefit the cyber-insurance industry, which relies
on statistical and historical data about cyber incidents in its assessment of risk;
Promote a Secure Internet environment for Vital Operators. Each OIV should
develop and implement its security measures and security policies in line with this
Strategy, in order to operate their security operation center for monitoring and
reacting efficiently to security incidents, with the support of behavioral analytics
techniques, intelligent correlation, and filtering of security alerts;
Encourage hardware and software vendors to develop and sell products, for
which security controls are enabled by default;
Once the Lebanese cyber environment and Cyber Hygiene comply with basic
standards of security at the level of the single technological product/item and the
single user (Stakeholders), the NCISA shall produce new standards with the main
objective to obtain a full Security by Design for every ICT device connected to
Lebanon’s assigned public IP address space;
Ensure that service providers comply with laws and regulations. The challenge
here is to make a drastic change in the security controls built into the software and
hardware already enabled by the manufacturer before the product is launched on
the market. The user must be able to benefit from maximum security on a
commercially viable product or service, while remaining in the context of a freely
accessible and open Internet;
June 2019
LEBANON NATIONAL CYBER SECURITY STRATEGY
36