● regulated at the legislative level the issue of full involvement of the private sector
and civil society in the implementation of measures to curb destructive activities in
cyberspace;
● effective mechanisms have been developed to involve private sector cybersecurity
professionals in deterring and countering aggression against Ukraine in cyberspace.
On the basis of cyber resilience
The state, in cooperation with the private sector, academia and the public, will ensure the
achievement of national cyber preparedness and cyber defense (goal R.1). This requires:
● develop a National Cyber Contingency Plan, which will identify mechanisms for
responding, with subsequent recovery, to large-scale cyber attacks and cyber
incidents on critical information infrastructure, and define the roles and
responsibilities of all actors in cybersecurity and security. critical infrastructure
projects during an emergency situation, key processes and measures to overcome
the emergency situation, criteria for classifying the situation as an emergency
situation, mechanisms for informing citizens, conducting exercises to check the state
of emergency preparedness;
● develop baseline requirements and recommendations for cybersecurity;
● deploy a system for exchanging information on cyber incidents between all
cybersecurity actors;
● introduce a risk-oriented approach in terms of cybersecurity and protection
measures for critical infrastructure and government agencies, in particular to
develop methods for identifying and assessing cyber risks at the national level and
for critical infrastructure sectors of the state, regulate at the legislative level the
obligation to conduct periodic risk assessments. on the basis of the developed
techniques;
● to introduce a system of product certification, which is used for the functioning and
cyber protection of information and communication systems, first of all, objects of
critical information infrastructure;
● to ensure the development of organizational and technical model of cyber defense,
to introduce mechanisms for timely identification of threats, tools for detecting
cyberattacks for rapid response to them and rapid restoration of stable operation
during and after cyberattacks;
● complete the process of identifying critical infrastructure and critical information
infrastructure, create and ensure the functioning of the state register of critical
information infrastructure, constantly review and update the requirements for their
cyber protection, taking into account modern international standards on cyber
security;
● to introduce a national program to identify vulnerabilities of information and
communication systems, to conduct on a regular basis an audit of the security of
communication and technological systems of critical infrastructure for
vulnerabilities;
● to introduce a permanent assessment of the state of protection of critical
information infrastructure and state information resources, to establish incentives,
mandatory and periodicity of such assessment taking into account the criticality