The main actors who create threats in cyberspace are:
- persons or organized crime groups that exploit cyberspace vulnerabilities to obtain property or nonproperty benefits;
- terrorists or extremists who use cyberspace to conduct and coordinate terrorist attacks, communication
activities, propaganda, recruitment and training, etc. fundraising for terrorist purposes;
- state or non-state actors which initiate operations in cyberspace, with the purpose of intelligence
gathering in the governmental, military, economic fields or of ensuring the materialization of other
threats to national security.
2. Opportunities
At the same time, cyberspace, which became a new area of interaction within modern society, offers a
number of opportunities generated by its very specificity. Thus, the following opportunities which
Romania can take advantage through cyberspace of have been identified:
- Supporting policies and promoting the national interests;
- Developing and supporting the business environment;
- Improving the quality of life through the development of the information society services;
- Improving knowledge and the support for national policy decisions in the Information age through
ensuring adequate cyber capabilities and tools;
- Increasing knowledge and prediction capacity for early warning of national security risks and threats;
- Increasing technical capacity and human resource skills to achieve national security objectives.
III. Directions of action
Romania aims at ensuring of normality and reducing the risks in cyberspace
seizing opportunities by improving knowledge, capabilities and mechanisms
decision. In this regard, efforts will focus on the following directions:
1. Establishing the conceptual, organizing and actional framework required for ensuring cyber security:
- constituting and operationalizing a national cyber security system;
- completing and harmonizing the national legal framework in the field, including setting up and appling
minimum security requirements for national cyber infrastructures;
- developing cooperation between the public and private sector, including through stimulating reciprocal
information exchange concerning threats, vulnerabilities and risks, as well as cyber incidents and
attacks.
2. Developing national risk management and reaction capabilities in the field of cyber security, based on
a national programme and including the following aspects:
- consolidating, at the level of competent authorities, the potential of understanding, preventing and
countering threats and minimizing risks associated with making use of the cyberspace;
- ensuring tools for developing public-private cooperation in the field of cyber security, including for the
purpose of creating efficient early warning, alert and response mechanisms concerning cyber incidents;
- stimulating research, development and innovation capabilities in the field of cyber security<
- increasing the resilience level of cyber infrastructures;
- developing CERT-type entities in both the public and private sector.
3. Promoting and consolidating the security culture in the cyber field
- Development of awareness raising programs at the levels of the population, public administration and
private sector concerning threats, vulnerabilities and risks specific to the use of cyberspace;
- Development of educational programs, within the compulsory education cycles, concerning the safe
use of the internet and computing equipment;
- Appropriate professional training to people working in cyber security and the widespread promotion of
professional certifications field;