senior experts. All the groups are co-chaired by a governmental official and a private expert. The working groups are a great example of how to involve the private sector into governmental decision-making. The National Cyber Security Forum is another body of the Council, giving the opportunity for business CEOs, academic and NGOs’ leaders to meet with governmental decision makers. Through the Forum, the non-state sector could become an active partner with the government during the legislative process. Moreover, national and international companies hold great knowledge and experience in the field of cyber security, which should be shared. Operating under the Ministry of Interior, the National Security Authority promotes the protection of classified information and electronic systems that handle sensitive data. In accordance with Hungarian information security law – mentioned Act L of 2013 – from 1 July 2013 to the summer of 2015, the Authority was also responsible for the vulnerability assessments of governmental systems according to the National Electronic 36 Information Security Authority requests. The Hungarian information security law created its assessment and supervision agency, the National Electronic Information Security Authority, which operates under the supervision of the Ministry of Interior. The dedicated main task of the Authority is to handle and control the data of central and local government agencies regarding their cyber security policies and declared security institutional level stipulated by confidentiality, integrity and availability. Reflecting the intensive progression in cyber security matters, the first reform of Act L of 2013 took place in July 2015, two years after its adoption. Under the renewed system, the Ministry of Interior became responsible for the Hungarian cyber security direction and regulation. In accordance with the legislative amendment, to make the cyber defence system more united and centralised, GovCERT-Hungary became the main agency authorised to get involved in central governmental incident management. As another new element, in some cases, Act L of 2013 provides a basis for business sector companies (with a valid national security certificate) to take part in incident handling processes. The core operational cyber security capabilities and cyber incident management are centralised to the governmental computer emergency response team in Hungary, GovCERT-Hungary, which is part of the newly established National Cyber Defence Institute and supervised by the Ministry of Interior. GovCERT-Hungary provides services for the whole Hungarian governmental administration – especially for the government 37 backbone system and for critical infrastructures – and the municipalities. GovCERT-Hungary started to operate on 1 July 2013. It has nearly 4,000 institutions as partners, and contributes to the protection of critical infrastructure with the National Directorate General for Disaster Management. GovCERT-Hungary has growing capabilities in the following fields: information exchange, sharing, publishing, information security awareness campaigns, training, technology watch, security consultancy, cyber incident response, coordination, resolution, basic malware analysis, manual analysis of system and firewall 38 logs, source code validation, forensic examinations, and network traffic evaluation. It is tasked with liaising with the private sector for the purposes of promoting information exchanges and raising awareness in the field of information and network security in the private sector. As a national contact point, GovCERT-Hungary builds 39 active cooperation within the international CSIRT and CIIP community. GovCERT-Hungary participates in 36 In 2011, the Cyber Defence Management Authority (CDMA) was established within the Authority to be a national coordination and contact point to the NATO CDMA. It’s operated within the National Security Agency until July 2015. 37 GovCERT-Hungary. <http://www.cert-hungary.hu/en/node/17>. 38 ibid. 39 GovCERT-Hungary. <http://www.cert-hungary.hu/en/node/6>. 9

Select target paragraph3