ENSURING CYBERSECURITY ON A NATIONAL
LEVEL: STRENGTHENING RESILIENCE AGAINST
CYBER THREATS
Cooperation between the relevant entities, including on setting a national strategic framework,
is essential to ensuring cyber security at the national level. In 2022, new developments on
several important projects in this area took place.
Project BIVOJ
The mission of the BIVOJ project (Bezpečný/Save, Inovativní/Innovative, pro Veřejnou správu /for
Public administration, Odolný/Resistant, Jednotný/Unified) is to ensure central administration
and management of security for information-sharing and communication systems and services
in the Czech public sector. The project aims to facilitate improved monitoring, communication
and application of safety standards. As a result, the public sector as a whole will become
more resilient, thus increasing the overall level of cybersecurity. The project consists of several
interconnected components, which are currently coordinated by the NÚKIB in cooperation with
other institutions, e.g. Military Intelligence and the Ministry of the Interior.
Coordinated Vulnerability Disclosure
Coordinated Vulnerability Disclosure is a formalized process of voluntary discovery of
vulnerabilities in information and communication technology (ICT) products by third parties
(so-called discoverers), including notifying the owner or administrator of the ICT product of
the discovered vulnerability for the purpose of security patching. At present, there is neither
a formalised and comprehensive national approach toward coordinated vulnerability
disclosure nor a specific legal regulation in the Czech Republic. Therefore, in the course of
2022, the NÚKIB designed a national framework enabling responsible and coordinated discovery
of vulnerabilities for the use of public authorities as well as the private sector. In the autumn
of 2022, several meetings and consultations were held with representatives of the private
and public sectors to identify relevant legal and technical aspects of coordinated vulnerability
disclosure. In December 2022, a national policy draft on coordinated vulnerability disclosure
was then submitted for approval.
5G Network Security Measures
In February 2022, the NÚKIB, together with the Ministry of Industry and Trade, the Ministry of
Foreign Affairs, the Security Information Service, the Office for Foreign Relations and Information,
and the Military Intelligence, issued the Recommendation titled Doporučení pro hodnocení
důvěryhodnosti dodavatelů technologií do 5G sítí v České republice. The Recommendation
provides guidance namely for information and communication systems for the Czech critical
infrastructure with regard to supplier trustworthiness. The recommendation represents the
31