ENSURING CYBERSECURITY ON A NATIONAL LEVEL: STRENGTHENING RESILIENCE AGAINST CYBER THREATS Cooperation between the relevant entities, including on setting a national strategic framework, is essential to ensuring cyber security at the national level. In 2022, new developments on several important projects in this area took place. Project BIVOJ The mission of the BIVOJ project (Bezpečný/Save, Inovativní/Innovative, pro Veřejnou správu /for Public administration, Odolný/Resistant, Jednotný/Unified) is to ensure central administration and management of security for information-sharing and communication systems and services in the Czech public sector. The project aims to facilitate improved monitoring, communication and application of safety standards. As a result, the public sector as a whole will become more resilient, thus increasing the overall level of cybersecurity. The project consists of several interconnected components, which are currently coordinated by the NÚKIB in cooperation with other institutions, e.g. Military Intelligence and the Ministry of the Interior. Coordinated Vulnerability Disclosure Coordinated Vulnerability Disclosure is a formalized process of voluntary discovery of vulnerabilities in information and communication technology (ICT) products by third parties (so-called discoverers), including notifying the owner or administrator of the ICT product of the discovered vulnerability for the purpose of security patching. At present, there is neither a formalised and comprehensive national approach toward coordinated vulnerability disclosure nor a specific legal regulation in the Czech Republic. Therefore, in the course of 2022, the NÚKIB designed a national framework enabling responsible and coordinated discovery of vulnerabilities for the use of public authorities as well as the private sector. In the autumn of 2022, several meetings and consultations were held with representatives of the private and public sectors to identify relevant legal and technical aspects of coordinated vulnerability disclosure. In December 2022, a national policy draft on coordinated vulnerability disclosure was then submitted for approval. 5G Network Security Measures In February 2022, the NÚKIB, together with the Ministry of Industry and Trade, the Ministry of Foreign Affairs, the Security Information Service, the Office for Foreign Relations and Information, and the Military Intelligence, issued the Recommendation titled Doporučení pro hodnocení důvěryhodnosti dodavatelů technologií do 5G sítí v České republice. The Recommendation provides guidance namely for information and communication systems for the Czech critical infrastructure with regard to supplier trustworthiness. The recommendation represents the 31

Select target paragraph3