legislation (drafting an act on information security), organisation and staffing; due attention
should also be given to funding. A national institution for information security of nonclassified segment of the NICI (a National Information Security Authority of the Slovak
Republic (NISA)) is recommended to be formed in the final stage. A more detailed approach
to safeguarding information security in Slovakia will be included in an action plan to NSIS, to
be prepared by the end of 2008.
3.4
Current priorities for information security in Slovakia
The current priorities in information security are driven by an unfavourable situation
in this field in Slovakia, and by Slovakia falling considerably behind countries advanced in
terms of information society development. The unfavourable situation is mainly caused by
poor implementation of objectives specified in strategic documents, absence of a state concept
of information security and interoperability framework in Slovakia, legislation, competences,
awareness, support from competent bodies and other factors.
3.4.1
CSIRT.SK
The aim of this task is to prepare a proposal on how to ensure organisational, personal,
material, technical and financial resources for a contact point for security incidents, and
subsequent formation of a specialised organisation to combat computer crime and ensure
mutual cooperation, exchange of information and experience at the domestic level with links
to a Europe-wide environment. The institution will perform the tasks specified in Section
3.2.4 (the first 4 tasks in particular). It will also participate in performing tasks specified in
Section 3.2.6, action plan tasks, etc. This fact is also appreciated by international
organisations concerned with IT security, which have pointed out that there is no contact
point available in Slovakia in the case of international IT security incidents. Given the lack of
expert capacities in the field of information security, CSIRT.SK is expected to also utilise
personnel capacities of non-state organisations. Since this situation will only be provisional,
CSIRT.SK will have limited powers. It will later be necessary to consider enhancing its
executive powers laid down by the law.
3.4.2
Coordination of standardisation activities
Standards are a means to achieve international interoperability of all solutions and the
necessary level of information society. Slovakia has no access to international standards
under preparation, the publication of standards is not coordinated; equally, there is no
overview of relevant international norms and no funds for their introduction into STN. Slovak
representatives participate in international standardisation organisations only sporadically.
Problems also stem from fragmented competences, dual publication of standards and their
mutual incompatibility. A solution could be to better allocate competences and coordinate
preparation and publication of norms and standards in key organisations including MF SR,
MoH, MoC, the NSA, the Geodesy, Cartography and Cadastre Authority of the Slovak
Republic, and the SOSMT. Participation of Slovak representatives in international
standardisation organisations is necessary when transposing approved standards. On that
account, an overview of standardisation activities in the field of information security needs be
prepared with respect to:
a) powers of Slovak authorities in issuing of standards;
14