3. The main lines of action The Policy will be implemented through the following actions, in accordance with the priorities resulting from the order shown. 3.1. Risk Assessment The assessment of risk associated with the functioning of cyberspace is a key element of the process of cyberspace security, determining and justifying the actions undertaken to reduce it to an acceptable level. In order to achieve an acceptable level of security, it is assumed that each government administration unit, referred to in point 1.4 (points 1-4), shall, no later than January 31 each year, submit to the minister responsible for informatization the report summarizing the results of the risk assessment (in accordance with the model developed by the minister responsible for informatization). The report should contain general information on types of risks, threats and vulnerabilities diagnosed in each of the sectors which an individual institution is operating in and is responsible for. The report should also present information on how to deal with risk. Minister responsible for informatization in collaboration with the involved institutions will determine the uniform methodology for performing risk analyses. There is a necessity for the use of this methodology to be eventually mandatory for the institutions of government administration. It is recommended that the Governmental Computer Security Incident Response Team CERT.GOV.PL presented to the minister responsible for informatization, in order to unify the approach, complied directories containing the specification of the risks and possible vulnerabilities affecting the security of cyberspace. 3.2. The security of government administration portals The main place for exchanging information between the government administration units and a citizen, in e-society, are websites. They should comply with the fundamental safety requirements, that is, ensure adequate availability, integrity and confidentiality of data. Each organizational unit should independently assess the risk (referred to in point 3.1) for its portals. It is assumed that on this basis the appropriate (depending on the type of site and the results of the risk assessment) organizational and technical solutions will be implemented so as to ensure an adequate level of security. Due to the different types of parties and their different priorities, these solutions will differ from each other. It is proposed that the government administration units running Internet portals, in addition to complying with the minimum requirements, implement also the relevant Page 10 of 24 Ministry of Administration and Digitisation, Internal Security Agency

Select target paragraph3