Part Three The Strategy 4. Goal: Secure Cyberspace Such alignment may also call for particular consideration, in terms of support, to organisations having limited or constrained resources (including human and financial). On the other hand, it is understood that legislation and regulation cannot necessarily cover all aspects of cyber security; particularly considering potential financial and human resource constraints for robust cyber security. i. Establish regulation and voluntary selfcommitment for guaranteeing cyber security The current scenario analysis of cyber security in Malta indicates areas of regulation and policy particularly within the local regulated industry sectors. Focus appears to be mainly on policy frameworks covering the licensing approaches which seek to mitigate risk. Voluntary self commitment is, thus, also key to cyber security. The notion of the applicability of a European security trust mark, applied also in a number of EU states 31may encourage voluntary self commitment and may therefore be one item to explore the possibility of its use locally. Local national strategy may already serve as a potential opportunity for further consideration in fostering self commitment, such as: “ Interoperability is one means of broadening and strenghtening collaboration, establishing intelligence and improving situational awareness, all of which are essential for effective cyber security. • e-Commerce Malta which highlights three pillars as its basis: i. Engendering trust in ecommerce ” ii. Transforming micro-enterprises iii. Taking Small to Medium sized Enterprises and industry to the next level; which specifically also refers to an audit-kit – through a Specialist advisory service (Measure 2) and the European trust-mark (Measure 9) Whilst legislation may help, Maltese regulatory authorities may also need to address further emerging technology such as cloud computing applicability, through regulation within their respective sectors. • Digital Malta which refers to the Forum for the transformation of industries through ICT that aims to raise awareness about how ICT can help industries transform themselves and to discuss items such as self-regulation. The formulation of regulation pertaining to cyber security would need to take into consideration, among others, the latest EU data protection legislation29 as well as of legal requirements pertaining to network and information security, where applicable. Other potential opportunities which may be explored include financial incentives, such as in the form of grant schemes, as a means to entice the applicability of necessary cyber security related measures. Regulation within sectors may also include conformance to internationally recognised security standards or industry led cyber security related standards or practices, with the aim of bolstering cyber security as well as establishing centres of excellence within the sectors themselves. ii. Stimulate use of interoperable and secure standards on the basis of good practice Digital Malta, through Action 42 – Standards and Good Practice, states Government’s intention to collaborate with stakeholders to support and promote 22 MALTA CYBER SECURITY STRATEGY 2016

Select target paragraph3