– the number of handled incidents. 3. Result measures – measure the effects achieved through the actions included in a task or under a task, carried out by the appropriate expenditure, at the level of task/subtask/action. Measure the results of undertaken actions. Result measures – measure direct effects of undertaken actions in the short or medium term. Sample result measures: – shortening the time of handling an incident, – the average response time to an incident. 4. Impact measures – measure the long-term consequences of implementation of a task. They can measure the direct effects of the implementation of a task which become apparent after a long period of time. Sometimes, the impact measures refer to the values which are only partially the result of the implementation of a task (the results are also affected by other external factors). Sample impact measure: – the increase of the sense of security on the Internet in Poland (research of CBOS – Public Opinion Research Centre). The degree of implementation will be assessed in percentage, while 100% means the implementation of all the tasks under specific projects developed on the basis of the Policy. Within one year from the entry into force of the Policy, each involved entity, referred to in point 1.4. paragraph 1 of this document, shall estimate (in %) to what extent the principles of the Policy have been already achieved. 6.1. Expected effects of the Policy The following long-term effects of actions resulting from the implementation of this Policy and specific projects developed on its basis are expected: – a higher level of security of CRP and a higher level of resistance of the state to attacks in CRP, – a policy concerning the cyberspace security consistent for all the involved agents, – lower effectiveness of terrorist attacks in CRP and lower costs of removing the results of cyberterrorist attacks, – effective system of coordination and exchange of information between public and private entities responsible for ensuring the security of cyberspace and those administering the resources constituting the critical ICT infrastructure of the state, – greater competence of actors involved in the ICT infrastructure security of the State functioning in cyberspace, Ministry of Administration and Digitisation, Internal Security Agency Page 23 of 24

Select target paragraph3