3.3 Development and Application of Basic Mechanisms Providing for the Administration
of Cyber Space
To ensure specialized tasks in order to render cyber space resistant, the Concept identifies and
proposes the application and development of the following basic mechanisms:
1. Decision-making and control mechanism – continuous cross-sectoral planning, organizing,
coordination, implementation and control of measures aimed at minimizing cyber security
threats and preventing their growth into crisis situations:
•
Preparing crisis plans for solving crisis situations,
•
Summarizing the needs and requirements necessary to solve identified threats and
confronting them with the possibilities of the state, regions, legal entities and
natural persons,
•
Designating the forces, resources and funds necessary for solving crisis situations.
2. Prevention mechanism – protective measures aimed at acting against crisis situations arising
and to minimize potential risks implied mostly for information and technical means of
communication:
•
National policy of behaviour in cyber space,
•
Specialized training of professionals in the area of information and communication
technical means as well as strengthening the security awareness of inhabitants in the
field of information and communication technologies,
•
Technical/technological support – available for the general public, corresponding to the
required protection levels, including recommendations, measures and technical measures
including adequate software, hardware and regime standards, the settings and
updates thereof,
•
Intelligence activities aimed at the collection, centralisation and evaluation of intelligence
information useful for prevention (e.g. intelligence information about cyber threats),
•
Collaboration with member states of the EU and NATO, the relevant bodies of these
organizations and with partner states in order to continuously monitor, analyse and
evaluate the security situation in cyber space, discover threats of crisis situations early and
coordinate the adoption of preventive measures to eliminate such threats.
3. Reaction mechanism – measures aimed at a qualified and efficient reaction in the event of
incidents and/or crisis situations that need to be taken in cases of ongoing attacks in order to
fence off or counterwork the attack and prevent the attacker from causing damage:
16
•
Defensive activities aimed at preventing the attacker from performing and/or continuing
in the cyber attack; this involves the activation of entities active when solving crisis
situations and if necessary, an early warning for the public, taking measures aimed at
stopping the escalation of the crisis situation and the creation of conditions for a return to
a stabilized situation,
•
Offensive activities aimed at weakening and/or eliminating the cyber and even physical
capacities of the attacker and to discourage the attacker from continuing in the attacks,
•
Intelligence activities aimed at supporting defensive and/or offensive activities (e.g.
intelligence information about the cyber capacities of the attacker).