 Freedom and openness  The laws, norms and EU's core values apply as much in the cyberspace as in the physical world:  Developing cyber security capacity building  Fostering international cooperation in cyberspace issues To respond to EU cyber strategy, to address cyber security in a comprehensive manner, the activity should be spread over three sub-key pillars - NIS network and information security – law enforcement – defense, sub-pillars that already operate in various institutions in Romania horizontally and vertically as in the following scheme: Source: European Commission Strategy http://ec.europa.eu/digital-agenda/en/news/eu-cybersecurity-plan-protect-open-internetand-online-freedom-and-opportunity-cyber-security In its Pillar III "Security and Trust", the Digital Agenda for Europe defines a series of cyber security initiatives at European level to ensure cyber security incident response capabilities and the protection of personal data. In this context, the responsibility of the national cyber infrastructure protection, whose compromise would undermine national security or prejudice the Romanian state, is equal to all institutions and companies that own such facilities, primarily the state institutions constituting the Cyber Security Operations Council in accordance with the Cyber Security Strategy of Romania. In order to achieve a strengthened network and information security policy, cooperation is needed between EU governments, public institutions and private companies to improve the exchange of information and to ensure that security issues will be effectively addressed and solved. ENISA will provide the exchange and collaboration. A real-time response to threats is required, implementing and improving the CERT network in Europe, including the European institutions. At the national level it is necessary to develop the operational capabilities of CERT-RO as required by law, to monitor and implement the principles provided by EC, as well as to draft amendments for improving business expertise of CERT-RO. In fighting against cyber-attacks on the information systems, Member States must amend the existing criminal law on attacks against information systems. The main purpose is to provide greater authority to the European legislation on cybercrime. The initiative will improve the security of citizens and businesses, and it is expected to have a positive effect on companies, as information systems repair costs are very high. At the national level, it will provide points of contact for complaints and information gathering on Page 46 of 172

Select target paragraph3