the case of crisis, develop regulatory framework for the information and technology sector,
educate society, as well as purposefully work with human resources necessary for the industry.
In the recent years, several planing documents for the policy “Cyber Security Strategy for the
Republic of Latvia 2014-2018”, as well as an action plan “Information Society Development
Guidelines 2014-2020” have been drafted and put into force. Complete implementation of the
measures included in the documents is an important precondition for improvement of the cyber
security of the state. While improving the national regulatory enactments regulating the
information and technology sector, and being involved in the development of international
standards, a balance between the individual rights and interests of the national security must be
ensured.
Responsible institutions have to provide a regular and timely review of the regulatory
framework for the cyber security, including the internal safety instructions of institutions,
considering current changes and rapid dynamic of cyber threats.
Strengthening of Response and Identification Capacity of Threats
Identification and understanding of the significance of cyber threats are important factors both
on the level of society and the state. The society must understand the risks that could stem from
inconsiderate, incorrect or superficial actions in the cyberspace. At the same time, the capacity of
institutions involved in the timely identification and effective and quick prevention of cyber
threats must be strengthen. These institutions have to work on development of methods and tools
by applying them to the current threat situation in the cyberspace, as well as they have to work
on reduction of the response time.
State security authorities have to strengthen the capacity for monitoring user-generated
content in order to identify and prevent activities purposefully directed against the Republic of
Latvia.
Strengthening of the Security of Information Infrastructure
State security authorities in cooperation with the Information Technology Security Incident
Response Institution of the Republic of Latvia (CERT.LV) must continue working on
improvement of the critical information infrastructure procedures, timely risk identification,
training for the holders of the critical information infrastructure and security personnel, as well
as they have to implement systematic control of the security regime within objects of the
infrastructure. They must work on inclusion of objects of the private critical information