3.1 Building an Institutional Framework for Cyber Security Administration The Concept proposes the structure of cyber security administration as shown in Figure no. 1. Government of the Slovak Republic, Security Council of the Slovak Republic, Committee for Cyber Security National CERT/CSIRT Ministry of Finance Ministry of the Interior Other central state authorities Information systems of public administration Information systems of critical infrastructure Other information systems (outside ISPA and CI), communication systems, networks, etc. Government CERT/CSIRT CERT/CSIRT XY Sector oriented authority for cyber security cyber security Special units for resolving incidents CERT – Computer emergency response team CSIRT – Computer Security Incident Response Team Figure no. 1 Proposed framework structure for managing cyber security Cyber security at a national level belongs to the scope of powers of the relevant central state administration body, with competences and powers defined in general by the Competence Act and specifically by a special law (Cyber Security Act). The scope and method of the exercise of public authority in the area of cyber security by relevant central state administration bodies and other state bodies in the framework of specific material areas of administration of the state’s socioeconomic environment (hereinafter referred to as “material areas”) will be defined by a special law (Cyber Security Act). Complex provision for cyber security within individual material areas must be performed by the exercise of public authority and exercise of special activities. The Concept foresees that a National Incident Resolution Unit and several incident resolution units in material areas of special importance (hereinafter referred to as the “units”) will be formed. To use human capacities rationally and use the technological equipment of the unit efficiently, the Concept foresees the formation of common units for other material areas; the National Incident Resolution Unit can hold the authority in certain material areas. The competences and authority of the National Incident Resolution Unit and of the units will be defined by the Cyber Security Act. The Concept proposes the following framework definition of the powers and competences of public administration bodies in the area of cyber security at a central level: Central state administration body for cyber security – the authority of an existing non-sectoral central state administration body18 extended by another segment of state administration. The Concept recommends that the lawmaker entrusts this authority to the National Security Authority. 11 18 I.e. a state body whose powers do not relate to a specific material area of administration of the state’s socio-economic environment. E.g.: Office of Government of the SR, National Security Authority.

Select target paragraph3