3. Concepts, Definitions and Terms For the purposes of this strategy, terms and expressions have the following meanings: - cyber infrastructure - information technology and communications infrastructure, consisting of systems, applications related electronic communications networks and services; - cyberspace - virtual environment generated by cyber infrastructure, including content information processed, stored or transmitted, as well as actions taken by users in this; - cybersecurity - normality resulting from the application of a set of proactive and reactive measures that ensure the confidentiality, integrity, availability, authenticity and non-repudiation in electronic information, resources and public or private services, in cyberspace. Proactive and reactive measures may include political, concepts, standards and guidelines for security, risk management, and training awareness activities, implement engineering solutions to protect cyber infrastructure, management identity and management consequence; - cyber defense - actions taken in cyberspace to protect, monitor, detect, counter aggression and ensure appropriate response against specific cyber threats to national defense infrastructure; - operations in computer networks - complex process of planning, coordination, synchronization, harmonization and development of actions in cyberspace protection, control and using computers network to obtain superiority information, while neutralizing enemy capabilities; - cyber threat - circumstance or event which constitutes a potential danger to cyber security; - cyber attack - hostile action in cyberspace held to affect cybernetics security; - cyber incident - event occurred in the cyberspace, whose consequences affect cyber security; - cyber terrorism - premeditated activities carried out in cyberspace by individuals, politically motivated groups or organizations, ideological or religious which may cause damage materials or victims, likely to cause panic or terror; - cyber espionage - actions taken in cyberspace in order to obtain unauthorized confidential information in the interests of state or non-state entities; - cybercrime - all facts under criminal law or other special laws which constitute a social threat and are committed with guilt, through cyber infrastructure; - vulnerability in cyberspace - weakness in the design and implementation cyber infrastructures and associated security measures which can be exploited by threat; - security risk in cyberspace - the likelihood that a threat will materialize, exploiting a specific cyber infrastructure vulnerability; - risk management - a complex , continuous and flexible identification, evaluation and counteracting cyber security risks process, based on the use of techniques and complex tools for preventing losses of any nature; - identity management - methods for validating the identity of persons when they accessing any cyber infrastructure; - cyber infrastructure resilience - the ability cyber infrastructure components to withstand a cyber incident or attack and return to normality; - CERT-type entities - specialized structures within the meaning of art. 2 letter a) the Government Decision no. 494/2011 on the establishment of the National Response to Security Incidents Cybernetics - CERT-RO. 4. Principles Ensuring cybersecurity should be the outcome of an approach based on risk assessment, resource prioritization, implementing and monitoring the efficiency of the security measures identified through the application of risk management and compliance and respecting the following principles: - Coordination - activities are carried out in a unitary, based on convergent action plans for cyber security in accordance with the duties and responsibilities of each entity;

Select target paragraph3