1. T
he main prerequisites and assumptions
of the Cyberspace Protection Policy
of the Republic of Poland
In the face of globalization, the cyberspace security has become one of the key
strategic objectives in the area of security of each country. At a time of free movement
of people, goods, information and capital – the security of a democratic country
depends on the development of mechanisms which allow preventing and combating
threats to the cyberspace security.
Due to the increase in threats to the ICT systems, from which the total separation
is not possible, and the fact that the responsibility for ICT security is distributed, it is
necessary to coordinate actions which will allow for a fast and effective response to
attacks directed against ICT systems and services offered by them.
The ICT systems operated by the government administration, the legislative
authorities, the judiciary, local government, as well as the strategic systems from the
point of view of the security of the State as well as entrepreneurs and natural persons are
covered by this “Cyberspace Protection Policy of the Republic of Poland,” hereinafter
referred to as the Policy.
By this Policy, the Government of the Republic of Poland accepts that by its
representatives it takes an active role in ensuring the security of information assets of
the State, its citizens, and it executes its constitutional duties.
A part of the Policy includes the support for social initiatives aimed at implementing
the tasks coinciding with this document.
The Government of the Republic of Poland, in fulfilling the constitutional
obligations implemented by cyberspace, consults organized groups of society, in
particular the representatives of telecommunications entrepreneurs and purveyors
providing services by electronic means, to agree on an acceptable level of security of
execution of obligations in question.
Accepting the status of the Policy for this document, it should be noted that under
the current system of governmental strategic documents a Policy is in the group
of strategic documents detailing the courses of action identified in the strategies,
development programmes and other programme documents, which do not specify
new priorities and activities. They set the vision of development for a given sector and
the way for its implementation, based on the provisions of the relevant documents.
The Policy does not cover with its task area the classified ICT systems. It should be
emphasized that the area of protection of classified information has its own regulations
and appropriate protective mechanisms. It has the organizational structures dedicated
to the protection of classified information produced, processed and stored in separate
ICT systems. The main legislative act is the Act of 5 August 2010 on the protection of
classified information (OJ No. 182, item 1228).
Page 4 of 24
Ministry of Administration and Digitisation, Internal Security Agency