c) to assess the existing competences and determine responsibility/define duties of state authorities in the area of information security; d) to harmonize STN (Slovak Technical Norms) with the applicable international information security standards; coordinate issuing of information security standards in Slovakia; e) to create a uniform methodology of non-classified information and information and communication systems security categorisation; f) to prepare basic ICT security requirements mandatory for the state ICI, and optional for other NICI components (mainly for e-Health, e-Government system and KRIS), compatible with international norms and standards. g) to prepare and make available methodology materials with a goal to achieve the required/basic level of information security (guidelines and best practices); to promote convergence of best-practice based security procedures applied by the state and private sector; h) to promote solutions and services based on available (open) standards in order to improve availability of security solutions to small businesses and individuals; i) to engage the commercial sector and expert public in the process of drafting and reviewing conceptual documents, norms and standards; to create room for knowledge and experience exchange. 3.2.4 Improvement of effectiveness in information security management In order to achieve and retain the required level of information security it is necessary to coordinate the protection of organisation’s assets and, at the same time, develop an effective system of its management. Improving the quality of management requires that institutions would be provided with not only the methodological assistance while solving conceptual issues, but also with the support in solution of particular urgent problems (including preparation of regulations, methodology documents and trainings, as well as advice and technical assistance). In this respect, security level should be monitored and evaluated, with respective statistics on security incidents being provided to target groups, in order to make management more effective. The following tasks should be set in order to resolve the aforementioned problems: a) threat monitoring; b) creation of an early warning system (notification of target groups about existing threats, warning of possible target groups, alarm signalling); c) help with security incidents solutions; d) identification, recording and evaluation of security incidents; e) monitoring effectiveness of measures proposed to resolve security incidents; f) coordination of security strategies of individual NICI system to ensure cooperation in NICI management. 3.2.5 Ensurance of sufficient protection of state ICI and ICI supporting the state critical infrastructure 11

Select target paragraph3