Part Two Overall Direction 4. PRELUDE interconnectedness of cyber-space exposes all of its constituents to a failure of their most vulnerable elements4 . This Section sets the scene for the National Cyber Security Strategy, through a definition of what is meant by cyber-space and its security and an outline of the key principles leading to the vision expected to be attained through the strategy. Additionally effective cyber security cannot be reached by technological measures alone as modern cyber attacks could bypass all defence layers by exploiting the human factors through techniques such as social engineering5. A Cyber Security Model presented encapsulates the key dimensions that are to be addressed by means of goals and corresponding measures, proposed in Part 3, for the implementation of the Strategy. Hence, safeguards and actions hereby refer to ongoing and planned measures which may potentially be of technical, operational, legislative, educational, behavioural or disseminative nature. 5. WHAT IS MEANT BY CYBER SECURITY Above all, cyber security cannot be seen from a technological aspect only, but needs to cover the needs and expectations of the state, the economy and society, all of which are increasingly active participants in an interactive digital world. Definitions for cyber security abound; however they all essentially point to the security of the cyberspace; namely all: • Interconnected ICT hardware and software infrastructure 6. GUIDING PRINCIPLES • Data in transit and at rest on the networks Within this context, the Strategy, in its lifecycle, shall be guided by a number of principles as follows: • Connected users • Logical connections established among them Rule of Law In view of the above , the following definition of cyber security is being adopted: 3 The approach on cyber security shall respect and promote fundamental rights and freedoms as chartered within European Union and national legislation. All measures shall comply with the principles of necessity, proportionality and legality, with appropriate safeguards to ensure accountability and redress. It is the safeguards and actions that can be used to protect cyber domain from those threats that are associated with or that may harm its interdependent networks and information infrastructure. It strives to preserve the availability and integrity of the networks and infrastructure and the confidentiality of the information contained therein. Multi-stakeholder, cooperative collaborative approach Essentially, cyber security is based upon the foundations of information security, namely confidentiality, integrity and availability. However, whilst information security is business driven and results in prudent investment in safeguards and countermeasures, cyber security is threat driven where all cyber-space is at risk. The inherent and The pervasive nature of cyber-space, essentially calls for a multi-stakeholder approach towards its security – both at a national level as well as beyond Malta’s shores. Hence, on a national level, cooperation and collaboration of various stakeholders, including the 12 MALTA CYBER SECURITY STRATEGY 2016

Select target paragraph3