recommendations and good practices in the field of security, which will be prepared by the Task force for the protection of government portals in cooperation with the Governmental Computer Security Incident Response Team CERT.GOV.PL. 3.3. Principles of legislative actions The basic elements of the execution of the Policy, planned for immediate implementation, are legislative actions. The Council of Ministers, understanding a high priority of these actions, notices the need for their initiation by the minister responsible for informatization in order to create regulations which give grounds for further actions in the implementation of the provisions of the Policy. It is necessary to review the existing regulations with a view to the preparation of solutions aimed at increasing the sense of security, not only of government institutions, but of all the users of cyberspace. 3.4. Principles of procedural and organizational actions An important step in the implementation of the Policy will be the procedural and organizational actions. Their aim is to optimize the functioning of CRP through the implementation of best practices and standards in this area. At this stage it is necessary to use both the legal tools developed in the first stage and the “soft”1 mechanisms of regulations. Performance of this stage will take place thanks to the creation of separate specific projects. 3.4.1. Management of the cyberspace security of the Republic of Poland As a part of the management of the cyberspace security of the RP, as well as to improve the process of implementation of the Policy objectives and to ensure effectiveness of the State authorities in the field of security of CRP, it is necessary for the Prime Minister to appoint a team responsible for the preparation of recommendations concerning the implementation and coordination of any actions related to its security (hereinafter referred to as the Team). The Team may be organized with the use of the existing potential of the Task force for the protection of government portals, appointed by the Chairman of the Committee of the Council of Ministers for the Digitization by the Decision No. 1/2012 of 24 January 2012. It is recommended that the Team, within 30 days from the date of appointment, prepared and presented an action plan to ensure the security of cyberspace of the Republic of Poland. The primary task of the Team shall be recommending actions aimed at coordination 1 A soft regulation means, for example, codes of good practice, guidelines, recommendations, code of ethics, etiquette, best practices or standards, etc. Ministry of Administration and Digitisation, Internal Security Agency Page 11 of 24

Select target paragraph3