From a practical and operational perspective, compared to the 2010 approach, the strategy now needs to focus on: making it a requirement that Cyber Security becomes a mandatory, legally binding and enforceable target for the Lebanon’s information system infrastructure at large; enhancing the Cyber Defense capabilities of our Country against the many different malicious Cyber Crimes and Cyber Attacks; and outlining the structure of a centralized body placed under the authority of the Presidency of the Council of Ministers, which will be responsible for implementing the components of this strategy. In 2018, the Lebanese Parliament ratified Law number 81, “Law of electronic transactions”, which contains a chapter on the preservation of electronic evidence. Some universities in Lebanon have restructured their curricula and opened Master’s degree programs in Cyber Security and digital forensics. Lebanon has also cooperated with other ICT-advanced countries and International Organizations in the field of Cyber Security. A digital transformation strategy on the State level is being developed under the supervision of OMSAR. In 2018 and 2019, under the framework of the CyberSouth project which was organized by the Council of Europe, the Ministry of Justice trained around 20 judges on how to face Cyber Criminality. Though it is in the right direction, this effort is not sufficient and the Ministry of Justice needs to address the subject on the highest level. The Ministry of Telecommunications is playing a major role in the deployment of a decently effective infrastructure in an intensive collaboration with private operators and OGERO, and regularly addresses Cyber Security issues with national stakeholders. It has established coordinating efforts with ITU (International Telecommunication Union) to improve the Cyber Security index in Lebanon. Banque du Liban (BDL) has developed and implemented, in a continuous improvement approach, a mature, standard-based, advanced and innovative Cyber Security Program that permits BDL to anticipate and defeat Cyber Attacks. This program is composed of two main pillars, and follows continuously the latest Worldwide IT Security Best Practices and Standards:  The Security Governance & Compliance Part: the first pillar contains the Definition & Update of BDL IT Security Roadmap, elaboration and follow-up of IT Security Policies, proactive risk assessment & management, and the launching and evaluation of the Security Awareness program.  The Defense-in-Depth Security Approach: is composed of multi-layered, multitechnology security solutions, covering the Network & Endpoint Security June 2019 LEBANON NATIONAL CYBER SECURITY STRATEGY 12

Select target paragraph3