Portuguese Official Journal, Series 1 — No. 108 — 5
June, 2019
the Internal Security System, as well as with authorities and
regulators on relevant sectors such as the electronic
communications sector and the sectors of essential services;
Update the Public Prosecution structures through the
establishment of specialized response structures for emerging
requests arising from crimes in the digital environment to
ensure evidence-based effectiveness and to be able to meet
potential international cooperation requirements in criminal
matters;
Strengthen the capacities of the Criminal Police by
strengthening its structures and human and technical capacities
for investigating and combating cyber-crime by fostering the
human resources allocated to this area and its ability to carry
out evidence-taking measures using technical means, and to
respond to the requirements of the international cooperation of
the police;
Strengthen the Security Intelligence Service, within its
exclusive competence to produce information aimed at
ensuring the internal security and necessary to prevent
sabotage, terrorism, espionage and acts which, by their very
nature, may alter or destroy the constitutionally established
rule of law, as well as the Strategic Defence Intelligence
Service, within its exclusive competence to produce
information that contributes to safeguarding the national
independence, national interests and external security of the
Portuguese State, without prejudice to the intelligence
activities carried out by the Armed Forces necessary to comply
with their specific missions and to ensure military security, so
that their human and technical research and analysis resources
can have a clear picture of the capabilities and intentions of
threat vectors that are being identified at all times, while
strengthening international cooperation and consolidating
proximity with national actors in this field.;
Apply the complementary legislation to the cybersecurity
legal regime ensuring a clear legal framework for all, notably
regarding the security requirements to comply with, the
thresholds for determining the impact of an incident and the
incident reporting requirements;
Enable «CERT.PT» as the national IT security incident
response team to ensure the operational coordination of
incident response, namely in connection with existing IT
security incident response teams and all the other relevant
national structures, considering that incident reporting
improves the situational awareness of cyberspace of national
interest and facilitates the sharing of information for the
benefit of all;
Strengthen the role of the IT security incident response team
communities as a platform of excellence for coordinated
operational response and the sharing of best practices and
incident information;
Increase the interoperability within the structures, in
particular by developing and deepening existing taxonomy and
procedures;
Develop, within the scope of the international action, cyberdiplomacy as the discipline of the State's external action aimed
at promoting, inter alia, the application of the existing
international law to cyberspace in order to ensure its stability,
the transparent and shared governance of its universal use and
the efficient creation of normative capacities, namely within
the Portuguese-Speaking Countries Community.
Axis 2 —
raising:
Prevention,
education
and
awareness
2891
In the context of prevention, the key role of information
sharing in early threat assessment should be safeguarded. The
permanent uncertainty regarding the various diffuse threats, of
undefined, ever-changing contours and developments that
impose on the security of cyberspace of national interest
requires a national capacity to detect and know in a timely
manner indicators that may be associated with potential and
ongoing threats. In this sense, it is crucial to develop the ability
to obtain, in an automated, systematic and coherent way,
knowledge on these indicators. A homogeneous and insightful
knowledge of threat indicators will thus enable the entire
national cyberspace security ecosystem to have an adequate
prior knowledge to produce threat anticipation and security
measures against unwanted impacts.
At the same time, cyberspace security depends on promoting
a culture of security, framed by the principles of ethics, which
provides all with the knowledge, awareness and confidence
needed to use information networks and systems, reducing
exposure to the risks of cyberspace. In this context, it is
essential to inform and raise awareness not only of public
bodies, but also of companies and civil society. On the other
hand, it is crucial for the country to equip itself with qualified
human resources to deal with the complex cyberspace security
challenges.
Ensuring the security of technology infrastructures, network
and information systems depends on the ability of end users to
take measures to prevent the risks to which they are exposed.
Thus, permanent awareness is an essential factor in the
prevention of cyberspace security.
Thus, in the context of prevention, education and awareness,
the following lines of action shall be adopted:
Strengthen the means of information collection and
processing and analysis capabilities;
Know the threat agents, their intentions and capabilities and
assess the potential impacts generated by their activity;
Anticipate the emergence, evolution and mutation of threats,
enabling the timely adoption of actions that add resilience;
Create a more resilient society by stimulating the
development of digital skills in the citizens, without prejudice
to other similar national programs, such as the «National
Digital Skills Initiative e.2030 — INCoDe.2030»;
Create tools and strengthen civil society awareness-raising
measures for the safe and responsible use of digital
technologies, with particular emphasis on capacity building
and knowledge gained by children, adolescents, seniors and
other at-risk groups;
Promote robust and cross-cutting cyber security training
programs for all organizations and the average citizen,
enabling users to understand their responsibilities, using and
adequately protecting the information and resources entrusted
to them;
Strengthen cyberspace security skills and knowledge in
education, including such themes in the syllabus of primary,
secondary and tertiary education and in continuing teacher
training;
Promote digital education and literacy as a prerequisite for
the trust and use of new technology digital resources by new
generations and especially vulnerable groups in a conscious,
informed and responsible manner;
Encourage the identification of young people with high
potential for cybersecurity and promote their timely
integration into a professional context;