3.5. Principles of education, training and awarenessraising in the field of security As a part of execution of the Policy, the Council of Ministers recognizes the need to begin work on the implementation of educational activities. It is assumed that the actions in this area will be conducted among the current and future users of CRP. They are designed to reinforce the impact of the two previous measures, strengthen them among the users, and create the possibility of passing to the next stage of implementation of the Policy. 3.5.1. Training of plenipotentiaries for cyberspace security In order to improve qualifications there is a need to develop a training system for plenipotentiaries for cyberspace security. The project of trainings should place emphasis on the issue of responding to incidents relating to the cyberspace security. 3.5.2. Introduction of ICT security topics as a permanent element of higher education One of the fundamental aspects of ensuring security of CRP is highly qualified personnel working in the public and private sectors, responsible for maintenance of ICT systems with particular emphasis on resources crucial for the safety of the state. In order to ensure a continuous supply of well-trained professionals in the field of ICT security it is necessary to involve higher education institutions in achieving the objectives of the Policy. The issues relating to the cyberspace security should become a permanent element of education. This applies in particular to technical higher education institutions teaching computer scientists. The situation where designers, computer programmers focus exclusively on functionality, forgetting the principles of creating a secure code, and system administrators give priority to the availability of resources of users forgetting the need to protect the processed information from intruders should be prevented from happening. For this purpose it is necessary to take into account the issues of ICT safety among the outcomes of education specified in the National Qualification Framework for Higher Education.2 3.5.3. Education of clerical staff in government administration The Council of Ministers notices the need for education of government administration employees having access to and using CRP, in the scope of issues concerning the security of ICT systems – according to their positions and risks associated with them. 2 Regulation of the Minister of Science and Higher Education of 2 November 2011 on the National Qualification Framework for Higher Education, OJ No. 253, item 1520. Ministry of Administration and Digitisation, Internal Security Agency Page 13 of 24

Select target paragraph3