ENDNOTES 54. For example, it may be appropriate to focus, among others, on cyber security related concerns and measures that may be taken in the applicability of cloud computing or mobile computing within office environments. 55. For example social media, TV, radio, etc 56. Apart from regular Euro barometer surveys dealing with cyber security which provide a significant insight on cyber security experiences and concerns on a domestic level. 57. Such policy is currently mainly applied by a number of organisations – European and worldwide, and also by some EU member states such as the Netherlands. Such framework could be enabled through self-regulation, promotion and encouragement by government as well as the proper framework to ensure responsible vulnerability disclosure. 58. Reference is made to the Network and Information Security - NIS - Directive 59. Reference is made to the Council Conclusions on Cyber Diplomacy (2015) and to the Global Conference on Cyberspace (2015) 60. Permanent Council Decision No. 1039 (26 April 2012) , whereby OSCE participating States, “decided to step up individual and collective efforts to address security of and in the use of ICTs in a comprehensive and cross-dimensional manner in accordance with OSCE commitments and cooperation with relevant international organisations...”. This led to the adoption of a number of Confidence Building Measures (CBMs) through Permanent Council Decision 1106 on December 3, 2013, followed by additional, complementary CBMs adopted through Permanent Council Decision No. 1202 on March 10, 2016. 61. It needs to be seen within a ‘win-win’ perspective including in those areas where business related competition plays a key role. 36 MALTA CYBER SECURITY STRATEGY 2016

Select target paragraph3