a) to pursue democratic principles in measures designed to protect Slovak digital
space;
b) to lay down legislation on access to personal data in such a way that no person
could have a right to misuse such data in the scope extending beyond the purpose
of its processing.
3.2.2
Building of awareness and competence in information security
Analyses have shown that many security incidents are caused by insufficient expertise
and knowledge of information system administrators, users, as well as information security
managers. On that account, the issue of their qualification and education needs to be
addressed. Qualification does not entail only education but, above all, experience in a
given field and expertise obtained.
In the light of potential threats, it is necessary to achieve the required level of security
awareness (i.e. understanding the need and nature of information security) among all its
users in order to safeguard the digital space and, subsequently, translate security awareness
into a competence (recognising and assuming one’s own responsibility for information
security when working with ICT). The strategy identifies the following key tasks to
achieve and retain the necessary level of security awareness and competence:
a) to raise an awareness – using the Internet, mass media and methodology materials
– among citizens, commercial and non-commercial organisations and public
institutions of the risks related to the use of ICT and of means available to protect
against threats;
b) to strengthen education activities (making the information security basics part of
informatics classes at schools);
c) to introduce programmes on enhancing security awareness and competence of ICT
users, with special requirements for information security.
3.2.3
Creation of secure environment
The role of the state is to create good conditions for cooperation among all involved
stakeholders. It includes, in particular, laying down a legal framework, drafting strategic
documents and methodology materials, determining competences, obligations and
responsibility. Another important task is to create uniform information security standards and
coordinate their issuing. The entire public administration, the academic and private sector,
including individuals, should be involved in the preparation of conceptual documents. It is in
the state’s interest to have the entire digital space protected, through suitable forms of
cooperation between owners and users. The strategy defines the following key tasks that lead
to creating a secure environment:
a) to coordinate the protection of Slovak digital space and ensure national security;
b) to create8 a sufficient information security legislative framework in Slovakia,
taking into account human rights and freedoms and Slovakia’s international
commitments (especially towards the EU);
8
analysis of the existing legislation and possible amendments or updates to it
10