Main Goals Develop a national coordinated incident handling procedure that will set acooperation format, contain a communication matrix, a procedure protocol and define each actor’s role. Develop a risk assessment methodology at the state level. www.GovCERT.CZ Code Tasks Responsible Entity Deadline A.2.01 Develop a unified methodology for cyber security incident handling on the basis of the Act on Cyber Security and related regulations. NSA/NCSC Q1 2016 A.2.02 Develop a communication matrix for cyber security authorities (national actors, CII, IIS). NSA/NCSC Q2 2015 A.2.03 Provide description of a safe communication interface, which will enable the NSA to receive XML messages with cyber security incident reports automatically. It will also contain an XML schema description that meets the content of the form for cyber security incident reports, mentioned in the regulation no. 316/2014 Coll., complemented by the other non-obligatory options. NSA/NCSC Q2 2015 A.2.04 Develop a protocol of procedures successfully employed in ensuring cyber security. NSA/NCSC Q2 2016 A.3.01 Choose a risk and a threat assessment methodology for the cyber security field at the state level. NSA/NCSC Q1 2018 A.3.02 Assess, on a continuous basis, cyber security risks and threats at the state level. NSA/NCSC Continuously since Q2 2018 4

Select target paragraph3