Policy Paper on Cyber Security 2015 - 2017
objective, another very important aspect in addition to the protection of these critical
systems, is the “resilience”, which will ensure continuity of business activities in cases of
force majeure or different cyber attacks. The protection and resilience capacity of critical
infrastructure and encouraging operators that own them to implement a full security
architecture (including risk management and emergencies) will ensure effectivity,
reliability and continuity of services that are provided by them.
c) Defining the legal/regulatory basis, based on which the providers of critical
infrastructures should report about serious cyber incidents. An analysis should be
conducted for every case (which is reported or not) as cyber crime, the reasons why did it
happened and actions that should be generated and reflected into laws, regulations or
procedures, in order to avoid the recurrance of the incident.
Developing and implementation of the minimum requirements on cyber security
The increase of the security in the state administration, the increase in the use of ICT systems in
the public administration and also ensuring their security is one of the priorities of this
Document.
a) Standards, guidelines and procedures based on the best international practices will be
aligned and approved in order to be implemented in the public administration.
b) It is a priority to develop and approve risk analysis procedures concerning security for the
systems that are used and electronic services that are provided by institutions. The risk
analysis will be an ongoing process and it will be conducted periodically. The
implementation of these procedures will be one of the key elements to increase the level of
cyber security.
c) Further development of procedures to coordinate investments in order to analyse security
and harmonize projects at the design stage will be assessed.
d) Important systems will be identified in the state administration and institutions will invest in
automated hardware and software as proactive and reactive ensure these systems they
administer.
e) The BCC (Business Continuity Center) and DRC (Disaster Recovery Center) will be set up
for networks / state systems.
24