3. Concepts, Definitions and Terms
For the purposes of this strategy, terms and expressions have the following meanings:
- cyber infrastructure - information technology and communications infrastructure, consisting of
systems, applications related electronic communications networks and services;
- cyberspace - virtual environment generated by cyber infrastructure, including content information
processed, stored or transmitted, as well as actions taken by users in this;
- cybersecurity - normality resulting from the application of a set of proactive and reactive measures that
ensure the confidentiality, integrity, availability, authenticity and non-repudiation in electronic
information, resources and public or private services, in cyberspace.
Proactive and reactive measures may include political, concepts, standards and guidelines for security,
risk management, and training awareness activities, implement engineering solutions to protect cyber
infrastructure, management identity and management consequence;
- cyber defense - actions taken in cyberspace to protect, monitor, detect, counter aggression and ensure
appropriate response against specific cyber threats to national defense infrastructure;
- operations in computer networks - complex process of planning, coordination, synchronization,
harmonization and development of actions in cyberspace protection, control and using computers
network to obtain superiority information, while neutralizing enemy capabilities;
- cyber threat - circumstance or event which constitutes a potential danger to cyber security;
- cyber attack - hostile action in cyberspace held to affect cybernetics security;
- cyber incident - event occurred in the cyberspace, whose consequences affect cyber security;
- cyber terrorism - premeditated activities carried out in cyberspace by individuals, politically motivated
groups or organizations, ideological or religious which may cause damage materials or victims, likely to
cause panic or terror;
- cyber espionage - actions taken in cyberspace in order to obtain unauthorized confidential information
in the interests of state or non-state entities;
- cybercrime - all facts under criminal law or other special laws which constitute a social threat and
are committed with guilt, through cyber infrastructure;
- vulnerability in cyberspace - weakness in the design and implementation cyber infrastructures and
associated security measures which can be exploited by threat;
- security risk in cyberspace - the likelihood that a threat will materialize, exploiting a specific cyber
infrastructure vulnerability;
- risk management - a complex , continuous and flexible identification, evaluation and counteracting
cyber security risks process, based on the use of techniques and complex tools for preventing losses of
any nature;
- identity management - methods for validating the identity of persons when they accessing any cyber
infrastructure;
- cyber infrastructure resilience - the ability cyber infrastructure components to withstand a cyber
incident or attack and return to normality;
- CERT-type entities - specialized structures within the meaning of art. 2 letter a) the Government
Decision no. 494/2011 on the establishment of the National Response to Security Incidents Cybernetics
- CERT-RO.
4. Principles
Ensuring cybersecurity should be the outcome of an approach based on risk assessment, resource
prioritization, implementing and monitoring the efficiency of the security measures identified through
the application of risk management and compliance and respecting the following principles:
- Coordination - activities are carried out in a unitary, based on convergent action plans for cyber
security in accordance with the duties and responsibilities of each entity;