3. The main lines of action
The Policy will be implemented through the following actions, in accordance with
the priorities resulting from the order shown.
3.1. Risk Assessment
The assessment of risk associated with the functioning of cyberspace is a key
element of the process of cyberspace security, determining and justifying the actions
undertaken to reduce it to an acceptable level.
In order to achieve an acceptable level of security, it is assumed that each
government administration unit, referred to in point 1.4 (points 1-4), shall, no later
than January 31 each year, submit to the minister responsible for informatization the
report summarizing the results of the risk assessment (in accordance with the model
developed by the minister responsible for informatization). The report should contain
general information on types of risks, threats and vulnerabilities diagnosed in each of
the sectors which an individual institution is operating in and is responsible for. The
report should also present information on how to deal with risk.
Minister responsible for informatization in collaboration with the involved
institutions will determine the uniform methodology for performing risk analyses.
There is a necessity for the use of this methodology to be eventually mandatory for the
institutions of government administration.
It is recommended that the Governmental Computer Security Incident Response
Team CERT.GOV.PL presented to the minister responsible for informatization, in
order to unify the approach, complied directories containing the specification of the
risks and possible vulnerabilities affecting the security of cyberspace.
3.2. The security of government administration portals
The main place for exchanging information between the government administration
units and a citizen, in e-society, are websites. They should comply with the fundamental
safety requirements, that is, ensure adequate availability, integrity and confidentiality of
data. Each organizational unit should independently assess the risk (referred to in point
3.1) for its portals. It is assumed that on this basis the appropriate (depending on the type
of site and the results of the risk assessment) organizational and technical solutions will
be implemented so as to ensure an adequate level of security. Due to the different types of
parties and their different priorities, these solutions will differ from each other.
It is proposed that the government administration units running Internet portals,
in addition to complying with the minimum requirements, implement also the relevant
Page 10 of 24
Ministry of Administration and Digitisation, Internal Security Agency