Part Three The Strategy 1. Goal: Establish a governance framework operational nature. This entails ensuring consolidation of a top level National CSIRT10. It also implies close communication and coordination of the CSIRT with the proposed strategy implementation function, given that it would need to be involved on: The governance framework covers the necessary key functions and corresponding roles and responsibilities, as well as policies and processes necessary9 to constitute a robust foundation for an effective national cyber security strategy. • Real-time information sharing and response to calls • Longer term planning11. Communication and coordination, as the need arises, with other CSIRTS existing in Malta would also be necessary. i. Establish the necessary key coordination structures It is envisaged that the following functions (involving multiple stakeholders) shall be required to ensure sustainability of the National Cyber Security Strategy: a. The structure12 and responsibilities of these functions is subject to further reference and alignment to the relevant European Union legal requirements13 as well as to further consultation. At the strategic level: i. A function for the articulation and periodic review of the National Cyber Security Strategy. The creation of this function is required in the short term. This body would need to work in close cooperation with the strategy implementation function(s) referred to below ii. Foster the coordination to protect national critical information infrastructure Measures of preparedness, response and recovery, including cooperation and ongoing coordination mechanisms are particularly necessary to protect national critical information infrastructure. It is thus necessary to ensure that such national coordination between all stakeholders concerned14 is fostered. ii. A strategy implementation function to oversee implementation of the strategy and monitor cyber security operations. Such function needs to have the necessary funding, resources and mandate to: iii. Ensure clear delineation and communication of roles and responsibilities • take a leading, active role in the implementation of the National Cyber security strategy, keeping in view of policy and planning developments within the realm of Malta’s digital economy and society as well as further cyber security related developments on a national, EU and international perspective Cyber related roles and responsibilities - such as those identified above and potentially those arising from the proposed measures, as well as those resulting from relevant EU legal requirements15, need to be clearly delineated and agreed upon accordingly. Communication of their establishment further ensures the effective coordination that may be necessary between the effected stakeholders themselves. • ensure security preparedness of the public and private sector of their ICT, in line with established security requirements. This implies driving for effective engagement and ongoing high level coordination across Malta’s public and private sector. iv. Ensure the conduct of a national cyber risk assessment exercise b. At the operational level, function(s) for the national coordination of cyber detection and response. Computer Security Incident Response Teams (CSIRTs) tend to be of such technical and A National Cyber Risk Assessment exercise shall need to identify the major national cyber threats and risks, assess respective impacts and 17 MALTA CYBER SECURITY STRATEGY 2016

Select target paragraph3