1. Introduction
T
he modernization of society through information
and communication technologies, its digitalization
and the development of innovative services is an
undeniable fact that has become a natural part of
our lives. Nevertheless, the development that comes
with expansion of opportunities must be balanced by
responsibility for the risks that emerge simultaneously
as a forfeit for the benefits of the digital society.
Cybersecurity is a state in which information systems
and services are resilient to current threats and
vulnerabilities, and ready to detect and handle
cybersecurity incidents, recover data and processes,
and minimize consequences. Nonetheless,
cybersecurity is not an issue concerning only particular
organizations and entities that protect their assets by
taking appropriate measures.
Informatization of the public sector, automation
of manufacturing and other processes that were
performed manually in the past, constant development
and easy availability of technologies, their ease of
use in a wide range of common activities create a
space in which, apart from undeniable advantages,
threats arise, targeting critical and sensitive systems
and services of the state. They can result in a breach
of citizen‘s trust in the government, cause extensive
financial and economic damages, and potentially
cause injuries or a loss of life.
The information and cybersecurity governance
system, the goal of which is to ensure a high degree
of resilience of systems and services as well as
effective detection and response capabilities, is a
strategic security interest of the Slovak Republic.
A comprehensive concept of information and
cybersecurity governance, strategic direction based
on clear principles and exactly defined strategic
objectives are the basis for a well-developed system
that can flexibly respond to current threats and ensure
a high level of cybersecurity at national level. This is the
concept of the National Cybersecurity Strategy for the
years 2021 - 2025.
The history shows that the National Cybersecurity
Strategy for the years 2021-2025 (hereinafter referred
to as the „National Strategy“) is not the first strategic
document created at the national level. In 2007, a
strategy of information security was created together
with an action plan, and subsequently the Cyber
Security Concept of the Slovak Republic for 20152020 (hereinafter referred to as the „Concept“) was
introduced, which was the first comprehensive
plan defining the cybersecurity principles, rules
and objectives. The measures framing the Concept
focused on creating an institutional framework
for governance, adopting appropriate legislation,
developing basic mechanisms for cyberspace
governance, developing an education system, creating
a risk management culture, active international
collaboration and supporting science and research.
Along with the Concept, the Action Plan for the
Implementation of the Cyber Security Concept of the
Slovak Republic for 2015-2020 (hereinafter referred
to as the „Action Plan“) was created, defining specific
tasks related to individual measures, entities in charge
and responsibilities of participating bodies, as well as
the time frame for the task completion. Within the time
period defined for the Concept and the Action Plan, it
was possible to create a stable institutional framework
for cybersecurity governance, adopt a historically first
comprehensive legislation in the field of cybersecurity
and to create specialized entities for cybersecurity
incident handling.
Cyber threats as well as cybersecurity are constantly
evolving. New targets and vectors of cyberattacks
are constantly emerging, and are becoming more
widespread, more frequent and more sophisticated.
Some states and non-state actors resort more and
more to pursuing their goals through unfair cyber
activities. These can take several forms, including
critical infrastructure attacks, cyber espionage,
intellectual property theft, cybercrime, and
cyberattacks as part of hybrid threats. Cyberspace
is increasingly becoming an area of strategic
confrontation among states, reflecting a dynamic
geopolitical environment and efforts to change the
current international order. Technological innovations,
including cybersecurity innovations, are becoming an
instrument of confrontation and growing tensions in
the political, economic and security fields.
The good news is that the strategic direction of
the cybersecurity system can build upon the solid
foundations laid by the Concept and developed by its
Action Plan, even though some of the goals have not
yet been achieved.
The new strategy expands on the previously carried
out activities and its ambition is to respond in a
modern way to current and future security threats,
define the principles of the cybersecurity system and
to determine strategic objectives, the achievement
of which will ensure a higher level of security in the
cyberspace of the Slovak Republic. The National
Strategy is intended for all entities that participate
in building the cybersecurity system of the Slovak
Republic and is a key document from which the basic
direction of the Slovak Republic in this area comes
from.
The vision of the National Strategy is to strengthen
and create an open, free and secure cyberspace for
everybody.
The National Cybersecurity Strategy 2021 -2025
|
5