1. T  he main prerequisites and assumptions of the Cyberspace Protection Policy of the Republic of Poland In the face of globalization, the cyberspace security has become one of the key strategic objectives in the area of security of each country. At a time of free movement of people, goods, information and capital – the security of a democratic country depends on the development of mechanisms which allow preventing and combating threats to the cyberspace security. Due to the increase in threats to the ICT systems, from which the total separation is not possible, and the fact that the responsibility for ICT security is distributed, it is necessary to coordinate actions which will allow for a fast and effective response to attacks directed against ICT systems and services offered by them. The ICT systems operated by the government administration, the legislative authorities, the judiciary, local government, as well as the strategic systems from the point of view of the security of the State as well as entrepreneurs and natural persons are covered by this “Cyberspace Protection Policy of the Republic of Poland,” hereinafter referred to as the Policy. By this Policy, the Government of the Republic of Poland accepts that by its representatives it takes an active role in ensuring the security of information assets of the State, its citizens, and it executes its constitutional duties. A part of the Policy includes the support for social initiatives aimed at implementing the tasks coinciding with this document. The Government of the Republic of Poland, in fulfilling the constitutional obligations implemented by cyberspace, consults organized groups of society, in particular the representatives of telecommunications entrepreneurs and purveyors providing services by electronic means, to agree on an acceptable level of security of execution of obligations in question. Accepting the status of the Policy for this document, it should be noted that under the current system of governmental strategic documents a Policy is in the group of strategic documents detailing the courses of action identified in the strategies, development programmes and other programme documents, which do not specify new priorities and activities. They set the vision of development for a given sector and the way for its implementation, based on the provisions of the relevant documents. The Policy does not cover with its task area the classified ICT systems. It should be emphasized that the area of protection of classified information has its own regulations and appropriate protective mechanisms. It has the organizational structures dedicated to the protection of classified information produced, processed and stored in separate ICT systems. The main legislative act is the Act of 5 August 2010 on the protection of classified information (OJ No. 182, item 1228). Page 4 of 24 Ministry of Administration and Digitisation, Internal Security Agency

Select target paragraph3