QATAR NATIONAL CYBER SECURITY STRATEGY 4. ACTION PLAN FOR 2014–2018 The Action Plan provides more detail on the Qatari government’s plan to achieve Qatar’s cyber security vision. The Action Plan is organized by objective. Various stakeholders from government entities and institutions, including the Ministry of Defense, the Ministry of Information and Communications Technology, the Ministry of Interior, Public Prosecution, Qatar Foundation, sector regulators and CSOs, the Supreme Education Council, and other organizations, must work collaboratively with many others to implement these actions for the benefit of Qatar. Objective 1: Safeguard national CII. Initiative Action Assess the risk to CII §§ Develop a national CII risk management framework to guide the identification of CII assets and organizations; assessment of threats, vulnerabilities, and consequences; and development of risk profiles §§ Conduct regular risk assessments of CSOs and other organizations with CII §§ Conduct dependency and interdependency assessments to identify systemic risks that cut across critical sectors Implement cyber security controls and standards to mitigate risk to CII §§ Establish and maintain a CII cyber security standard and maturity model, including specific cyber security controls §§ Conduct regular evaluations and audits of CSOs to measure the effectiveness of cyber security programs and controls §§ Develop risk management strategies to protect the most critical services, systems, and organizations and track implementation of those strategies §§ Share information on risks and risk management strategies across sectors to enable the prioritization of mitigation actions and the investment of resources Analyze cyber security trends and threats to CII and provide timely reports to stakeholders §§ Create sector-specific or organizational security operations centers or threat intelligence centers Ensure the use of trustworthy technology products and services §§ Develop the capability to evaluate and certify ICT products and systems for use in critical sectors Continuously monitor the security of CII §§ Establish a capability to conduct continuous diagnostics and monitoring of networks to better understand risks, promote preventive measures, detect and treat infected devices, and notify affected users §§ Develop guidelines that specify security requirements for ICT and cyber security service providers 13

Select target paragraph3