QATAR NATIONAL CYBER SECURITY STRATEGY 2.3 Existing Capabilities to Meet the Threats and Challenges Qatar recognizes the importance of cyber security and has worked diligently over the last several years to develop and implement cyber security protection measures across the country. These measures have made it possible for government, businesses, institutions, and individuals to respond to the threats and challenges in cyberspace, thereby providing a strong foundation for achieving cyber security objectives. Among these efforts: §§Qatar has developed strategies and implemented policies to safeguard CII that is important to national security and economic prosperity, such as that used for power generation, oil and gas production, financial transactions, healthcare, and government operations. The National Information Assurance Policy and the National ICS Security Standard provide important guidance on security controls and practices to protect CII and improve Internet security. In addition, as part of the National Information Assurance Framework, Qatar published Anti-Spam Guidelines in 2013 to reduce the impact of unsolicited electronic messages (or spam) on entities and individuals. §§To improve the security of financial transactions, the Qatar Central Bank (QCB) issued Banking Supervision Rules, which identifies the cyber security controls that banks must follow, such as reporting cyber incidents and attacks to QCB and the Qatar Computer Emergency Response Team (Q-CERT). §§Qatar has established Information Risk Expert Committees (IREC) in the finance, energy, and government sectors. These public-private partnerships deal with a variety of cyber security issues, including threats, vulnerabilities, and consequences; preparedness activities; and mitigation strategies. The IRECs facilitate the exchange of information within each sector and with other stakeholders to enhance CII resilience. §§Qatar has made progress in developing a domestic legal framework that provides national governance for cyber security, combats cyber crime, protects individuals’ privacy, and promotes CII resilience. The enactment of Decree Law No. 16 of 2010 on the Promulgation of the Electronic Commerce and Transactions Law established penalties for crimes, including unlawful access to information systems, identity theft, and intercepting information or illegally interfering with an information system. In 2013, Qatar established the National Cyber Security Committee (Committee) to provide an overarching governance structure to oversee collaborative efforts to address cyber security. §§Qatar’s investment in developing technical and operational expertise includes the establishment of Q-CERT, a trusted authority that promotes a strengthened cyber environment for the Qatari government and all critical sectors. Q-CERT seeks to proactively prevent and detect cyber threats before they cause significant harm. 6

Select target paragraph3