The tasks defined for the forthcoming period are based on the current state of play in information security in Slovakia compared to the situation in other EU Member States and other advanced countries of the world. They are proposed in accordance with key EU/EC documents, directives and recommendations, and strategic priorities defined under this document. The following tasks have been defined: 1. To prepare a proposal for organisational, personnel, material, technical and financial arrangement for the formation of a specialised unit (CSIRT.SK) to address computer security incidents in the Slovak Republic. CSIRT.SK will: - collect knowledge of existing threats and possible solutions, and publish them; - serve as an early warning centre; - assist in addressing security incidents; - collect information on security incidents and their effects in Slovakia; - cooperate with similar institutions abroad; - systematically assist in building similar units in state and private organisations in Slovakia; - bring together experts on information security and train new experts by engaging them in its operations. Linkage between this task and other action plan tasks and key National Strategy tasks will be described in more detail in a “Draft action plan for 2008-2013”. 2. To prepare a legislative basis for the drafting of an act on information security in the Slovak public administration and draft an update to decree of the Ministry of Transport, Posts and Telecommunications No. 1706/M-2006 on standards for public administration information systems, i.e. to revise its Part Five, “Security Standards”. 3. To prepare a proposal of an information security training system. The aim of this task is to find out what individual NICI users should know about information security, how to teach them that, and prepare a specific solution for lay users/IT specialists in the state administration. This task involves: a) preparation of a feasibility study to analyse the following: - how experts on information security, IT specialists and lay users are trained in the world; - the current situation in information security trainings in Slovakia; - training needs (who needs to know what, to what extent); - who and under what conditions could provide necessary trainings; b) preparation of a proposal for a training system for IT specialists from state authorities: - two target groups (basic training for lay users, lifelong learning for IT specialists to update their knowledge); 17

Select target paragraph3