14. The staff in IT departments do not have sufficient level of information
and experience in the field of cyber security,
15. There is limited number of staff who would be competent in investigation
and prosecution of crimes that have emerged as a result of cyber security
violations,
16. The auditing steps about cyber security are not included sufficiently in
the internal audit procedures of organizations,
17. Cyber security is not considered as an indispensable component of the
information systems which are procured or developed, thus cyber security
is not taken into account at sufficient level during procurement of
products and services in the area of information and communication
technologies in public organizations,
18. There is not enough national manufacturing in terms of hardware and
software.
National Cyber Security Strategy and 2013-2014 Action Plan
14/47