b) existing Slovak standards;
c) international standardisation organisations;
d) international standards that Slovakia should adopt;
e) de facto standards11,
f) Slovakia’s capacities for competent standardisation activity;
g) Slovak representation in international standardisation organisations and initiatives.
Based on this overview, a proposal could be made on the allocation of competences in
standardisation activities and coordination of updates to existing and/or publication of new
norms and standards, as well as a mechanism to control the compliance with the existing
norms and standards.
3.4.3
Knowledge building and dissemination
Knowledge building and dissemination is a precondition for improving employees’
qualification and level of expertise in information security. This mainly involves production
of knowledge, which is a result of a creative, scientific and technical research. Knowledge
dissemination, i.e. reproduction, is related to education and training in educational
institutions. Knowledge of information security can be categorised as follows:
a) general basic knowledge – on a level of a user who needs to know what to do and
what not to do, but does not need to understand causes in detail;
b) general IT knowledge – on a level of an IT specialist, but not an information
security expert, who knows the system, is able to implement and maintain its
security mechanisms based on recommendations (security policies) and transform
security requirements into system operating rules;
c) specialised security knowledge – on a level of an information security expert who
can analyse the system and its security environment, perform a risk analysis and
propose measures to eliminate risks, or comprehensively assess system security
(auditor); The expert is familiar with the existing situation and trends in threats and
security solutions, managerial and legal aspects of information security, and is
capable of producing conceptual materials;
d) application security knowledge – on a level of an expert in a different field
(lawyers and investigators in particular) who, when performing his/her tasks, needs
to understand the nature of security problems and is able to cooperate with
specialists at all levels;
e) innovative knowledge – on a level of a research specialist in information security
(or some of its sub-fields) enabling him/her to find fundamentally new solutions.
Along with IT and expert training, language skills are equally necessary; in Slovakia,
due attention should be given to education in all aforementioned categories.
3.4.4
International cooperation
11
generally accepted technical norms which, formally, do not have the status of a standard (e.g. PKCS in the
case of electronic signature and cryptology)
15