also take into account the increasing demand for specialized ICT systems in the future.
All the teams, after the unification of responsibilities and response procedures, as
well as determination of the constituency, would create a national computer security
incident response system, which, in addition to cooperation, would also cover joint
conferences, training and exercises.
3.6.3. Development of an early warning system and implementation and
maintenance of preventive solutions
The ICT Security Department of the Internal Security Agency together with
the CERT Poland, which is part of the Research and Academic Computer Network
(NASK), has implemented an early warning system against threats from the Internet
– ARAKIS-GOV. Development of the system will be implemented in accordance with
the specific project.
At the same time, bearing in mind the progress taking place in ICT technologies
and the related trend of emergence of increasingly sophisticated threats, taking
initiatives to promote the creation of more and more modern solutions supporting the
ICT security is assumed during the implementation of the Policy.
The aim should be to use the widest possible range of different types of security
systems to ensure the security of critical ICT resources.
3.6.4. Testing the level of security and the continuity of actions
As a part of testing the level of security and ensuring continues implementation of
processes of CRP, the PCS should organize and coordinate periodic tests of both the
level of technical, organizational protection and procedural solutions (e.g. procedures
of continuity of actions or supra-departmental cooperation). The results of exercises
will be used for evaluation of the current resistance of cyberspace to attacks, while the
conclusions will form the basis for the preparation of recommendations for further
preventive measures.
3.6.5. Development of security teams
The CERT-type teams are competency centres offering substantive help at the stage
of creating appropriate structures and procedures. In addition, they are also used to
solve problems during their operation in various organizational units of government
administration or of entrepreneurs. Each institution, within own personal resources
and technical means available, may establish its own local incident response team
whose operation is coordinated in accordance with point 4.2.
Moreover, the tasks of Computer Security Incident Response Teams should
include maintaining internal informational sites. The sites will be the main sources of
information about the ICT security for people involved in ICT security in government
administration institutions, as well as other persons interested in this subject.
Page 16 of 24
Ministry of Administration and Digitisation, Internal Security Agency