Part Three The Strategy A chain is only as “strong as its weakest link. National and EU cross-border interoperability, ICT standards based on industry best practices and Green ICT. Unfortunately, within the realm of cyber security, weakest link could, more often than not, be traced to the human factor. The behavioural and educational aspect of cyber security cannot thus be discounted. Interoperability is one means of broadening and strenghtening collaboration, establishing intelligence and improving situational awareness32, all of which are essential for effective cyber security33. With respect to the notion of nationally and EU recognised interoperability, which also effectively promotes the use of safe secure standards, Digital Malta states as one of its objectives, Government’s commitment to revise and revamp the current National Interoperability Framework including related policies34. The implementation of internationally recognised information security standard35 controls within the public sector36 and potentially within the private sector should contribute to cyber security on the local scenario. The applicability of such controls may serve as a good initial basis. ” of ICT products and services for Government as well as in other areas of application. However consideration of industry led standards and guidance that put in place a series of measures specifically aimed to address cyber threats37 are also to be encouraged for use. This could form an integral part of what is proposed in Measure 4 (i). Additionally, the use of cloud computing services within the public sector needs to be seen to in the light of EU legal requirements pertaining to security of network and information systems39 as well as those pertaining to the Data Protection Regulation (EU) 2016/679 and other Directives. In particular, special consideration needs to be given by operators and users of emerging technologies. In such areas, related standards and security controls, may still be in the very early stages of maturity and may thus pose cyber security vulnerability challenges for interoperability which need to be carefully assessed. iv. Consolidate support to the private sector on cyber security Measure 4 (i) outlines how cyber security can be facilitated in the private sector. Apart from potential public sector driven incentives, private sector participation in awareness and advice programmes as well as cyber related exercises to specific sectors may additionally help. iii. Promote robust levels of cyber security in online public services Such measure may alleviate concerns expressed within Euro barometer findings with respect to Maltese accessing online services38. The applicability of interoperable and secure standards, as referred to in Measure 4 (ii), may potentially contribute for the attainment of such measure.It also calls for an emphasis to ensure security and privacy in the design For example, ways may potentially be sought with business service providers (e.g. lawyers, insurers) of how they can potentially develop services to incentivise and help businesses manage and reduce risks40. 23 MALTA CYBER SECURITY STRATEGY 2016

Select target paragraph3