ENDNOTES
Union, Brussels , 24 February 2016 (Doc 5797/2/16)
27.
Reference is made to ‘Report of the Expert-level consultation meeting with member states on countering hybrid threats held on 19
February 2016’ Permanent Representation of Malta to the European Union.
28.
Refers to CII operators, CI operators, Digital Service providers and other potential stakeholders
29.
The preparation for the GDPR calls for a review and assessment of number of organisational, procedural, communication steps
that need to be undertaken to ensure conformance.
30.
The latter aim may serve as good business opportunity, especially for export-oriented sectors, to strenghten their market share
overseas.
31.
For example Austria and the UK
32.
One of the action items of the EU Cyber Security Strategy specifically calls for work on further development of globally interoperable
standards and their promotion for their wider use by industry. Reference is made to EU Cyber Security Strategy: Roadmap
Development – Council of the EU, Brussels, 7/10/2015.
33.
This may imply, amongst others, the improvement of interoperability of national and international systems. Reference is made to
measure 5 as part of law enforcement legislation and policy related implementation of the Information Management Strategy
(Working Party on Information Exchange and Data Protection – Council of the EU)
34.
Public consultation preliminary results on information and communication technologies published by the European Commission in
early 2016, reveals cyber security as being one of the areas requiring common standards if completion of a single digital market is
to be achieved.
35.
Such as ISO 27001
36.
Reference is made to Measure 1.7
37.
Such as the UK’s Cyber Essentials Scheme, http://www.itgovernance.co.uk/cyber-essentials-scheme.aspx#.VaYNvLlBut8
38.
The overall confidence to use the Internet for online services (e.g. banking, public services) has decreased from 74% in 2012 to
73% to 2013 across the EU. A proportional increase is noted in 2014 in the level of concern expressed by EU respondents in
having access to online services, through the Internet, as a result of cyber attacks. In Malta’s case, the findings indicate an increase
from 44% in 2013 to 61% in 2014. This could be potentially attributed to an increase in the proportion of the Maltese respondents,
from 7% in 2013 to 10% in 2014 who complain of related incidents.
39.
Reference is particularly made to the NIS Directive, referred to in Note 1.
40.
Potential areas that can be seen to also relate to cyber insurance, due diligence to third party with which businesses may seek
strategic relationships,etc
41.
Including in roles such as those pertaing to law enforcement, prosecution services, the judiciary.
42.
Including educating staff to understand what is harmful to an organisation and what can be done to prevent mistakes which may
lead to data breaches.
43.
For example apart from use of visual methods, rewards, social engagement and direct feedback during everyday working life;
gamification may present one promising method. (Purcelli, op. cit, p.27). Other possiblities include cybercrime simulation
workshops as another complementary means to induce awareness on the various forms of cybercrime, who is the likely target,
what needs to be done to avoid falling a victim, and what action needs to be taken and to whom to refer to, in case of fallling a
victim.
44.
Reference is made to the European Strategy for a Better Internet for Children - Communication from the Commission to the
European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions, Brussels
2.2.2013, COM (2012) 196 final.
45.
Such as effective password management
46.
The increased focus on environmental concerns and measures within schools in recent years may serve as a potential model for a
heightened awareness on cyber security and safety concerns and measures amongst the younger generation, which may in turn
expand further within their home environments.
47.
With special reference to secondary and tertiary level education
48.
Such as through special events, apart from teaching through games, particularly to the younger generation. Estonia for example
organises ‘Cyber olympics’ and specialised summer schools
49.
A measure that is particularly required within the public sector as a domain having a wider extensive use of ICT and sensitive data,
relative to other sectors
50.
In particular, CII operators, CI operators, Digital Service providers and other potential stakeholders
51.
Puricelli, op.cit. This may be complemented by related policies, best practices and processes (including those on proper data
handling) applied within the context itself.
52.
So as to augment and enhance needed cyber security knowledge and expertise within the sector
53.
A similar approach has been taken by the Netherlands and Austria
35
MALTA CYBER SECURITY STRATEGY 2016