The state as an owner of information and communication systems is obliged to ensure
their adequate protection so that no damage is caused if they are attacked, or that such damage
is minimal. They mainly include systems that are part of the state critical infrastructure which
ensures the functioning of the state, services in industry, energy sector, healthcare and social
security, transport, banking, etc. The Slovak Security Strategy, approved by the National
Council of the Slovak Republic in 2005, implies that “the Slovak Republic will take measures
to reduce vulnerability of critical infrastructure components, with focus on information and
communication systems, and to minimise negative impacts of attacks against them. It will
continue its activities focused on the security and integrity of information and communication
systems, particularly systems that are essential for the safe performance of the basic functions
of the state.” The issue of information protection in critical infrastructure is also addressed by
the National Programme for the Protection and Defence of Critical Infrastructure in the
Slovak Republic, approved by government resolution No. 185/2008 of 26 March 2008. Since
the critical infrastructure involves even non-state systems and the state is a partner to citizens
and private companies in administrative as well as commercial matters, the state must, in
addition to the protection of its own systems, ensure security awareness raising among the
general public and promote reasonable security requirements for non-state systems. Tasks to
ensure sufficient protection of state ICI and ICT systems supporting the state critical
infrastructure are as follows:
a) to improve information security level in state institutions through the introduction
of an information security management system;
b) to implement and promote the use of secure ICT-based products and services;
c) to prepare framework conditions, guidelines and recommendations (stipulating
binding framework security requirements (security standards) for systems
controlled by individual state authorities, and guidelines on how to meet them;
and/or recommendations for systems not controlled by state authorities).
d) analyse the security level of that part of the NICI which represents a component of
the state critical infrastructure, or supports it; update adopted or adopt new
measures if necessary.
3.2.6
National and international cooperation
Given the global nature of information security, local solutions often prove
insufficient. Active involvement in the activities carried out by key international
organisations, such as ENISA, OECD, CERT, ISO, etc., is necessary. To that end, the
following is needed:
a) to coordinate national efforts in the protection of Slovak digital space;
b) to effectively engage in international cooperation based on an analysis of
Slovakia’s needs and options in the area of information security.
3.2.7
Enhancement of national competence
Highly qualified experts, reliable ICT-based products and credible IT services, along
with the sponsorship and helpfulness of the state and other stakeholders, are important in
order to sustain the necessary level of protection of Slovak digital space. The following is
needed in this area:
12