a) to analyse qualification needs in Slovakia with respect to information security,
possibilities of curricular and extra-curricular education and training, and
introduce a training system;
b) to promote research and development aimed at possible and existing problems in
information security (in particular, intensified cooperation of the state, the private
sector and academia);
c) to use the results of international cooperation to support economic competitiveness
(providing information about problems, solutions, trends, legislation and
standards, international initiatives in information security).
3.3
Information security management structure
3.3.1
Existing management structure
Slovakia has currently a 3-tier information security management structure in place,
based on Act No. 575/2001 Coll. on organisation of the activities of the Government and
organisation of the central public administration, as amended, and on amendments to certain
acts (the Transfer of Powers Act). The Government of the Slovak Republic, which discusses
and approves strategic and conceptual materials, is the supreme body. These materials are
submitted to the government by individual ministries pursuant to their powers laid down by
relevant laws. The 2nd tier includes a central government body responsible for information
security in public administration, currently the Ministry of Finance of the Slovak Republic,
and other state authorities and offices responsible for specific aspects of information security,
such as Ministry of Defence, Ministry of the Interior, Ministry of Economy, Ministry of
Culture, Ministry of Education, the National Security Authority, the Office for Personal Data
Protection, and the Slovak Office of Standards, Metrology and Testing. The 3rd tier consists
of organisational units of state authorities that perform particular tasks in the field of
information security. Department of legislation, methodology, standards and information
system security of the Information Society Section at the MF SR and directly coordinated
Committee for Information Security, chaired by a director general of the Information Society
Section, has both a specific position. Pursuant to its statute10 the Committee performs
analytical and conceptual activities and prepares strategic and technical materials on
information security.
3.3.2
Proposal for a new arrangement
The proposal for a new structure builds on the existing management structure
“government - MF SR, other central government bodies and authorities that are presently
competent for information security.” Based on an in-depth analysis of the existing security
processes, competences should be optimised (a material to be submitted to the government is
under preparation). The next step will be the setting up of a national centre for computer
security incidents, CSIRT.SK (Section 3.4.1 and Annex 4). Within the next five years, the
issue of information security in Slovakia will need to be settled in terms of applicable
10
Statute of the Committee for Information Security, IRA_MFSR_12.2007_ROM.kom.inf.bezpečnosť, Číslo :
MF/ 14462/2007 – 23
13