4.3. Information exchange mechanism An efficient system of coordination will ensure the exchange of information gained from the international cooperation between the governmental, military and civilian teams, in accordance with applicable law, and in particular in accordance with the Act of 29 August 1997 on the protection of personal data (OJ of 2002, No. 101, item 926, as amended) and the Act of 5 August 2010 on the protection of classified information (OJ No. 182, item 1228). This system will, among other things, identify alternative channels for the exchange of information and introduce periodic tests of effectiveness of the information exchange processes. 4.4. Methods and forms of cooperation As a part of implementation of the Policy, forms of cooperation between the authorities responsible for the security of cyberspace and responsible for combating computer crime of criminal nature should be developed. These forms of cooperation will have both a working form, in order to minimize delays of computer incident response, as well as a formalized form – serving the elimination of jurisdiction problems. 4.5. Cooperation with entrepreneurs It is essential to activate entrepreneurs whose protection from the cyberspace threats is important from the point of view of the proper functioning of the State. This group should include entrepreneurs active in particular in the following sectors: 1) supply in energy, energy resources and fuel, 2) communications, 3) ICT networks, 4) finances, 5) transport. The Policy assumes taking up actions activating the cooperation between entrepreneurs managing their own ICT infrastructure, falling within the ICT infrastructure of CRP of a similar nature, and thus exposed to similar types of vulnerabilities and methods of attacks. One of the forms of cooperation will be the creation of bodies appointed for the internal exchange of information and experiences and the cooperation with the public administration in the field of security of ICT infrastructure of CRP. Ministry of Administration and Digitisation, Internal Security Agency Page 19 of 24

Select target paragraph3