2892
Promote the advanced technical training on cyberspace
security in universities and polytechnics to meet the national
needs of professionals in the sector;
Value the inclusion of a conscious and responsible behaviour
regarding the use of technology as an integral and transversal
part of the current academic and professional training;
Promote specialized training and sensitize decision makers,
public managers and operators of critical infrastructures and
entities that provide essential services to society, with a view
to raising awareness and prevention of the need to safeguard
the interests and critical national information;
Value professionals in the field of cyberspace security,
increasing the number of specialists, qualifying professionals
and involving the various actors from all society;
Ensure a high level of quality of cybersecurity training and
requalification courses, obtained through the certification of
this framework;
Create retention mechanisms in national human resources
entities qualified in cyberspace security;
Organize and conduct exercises to assess the preparedness
and maturity of the various entities to deal with incidents with
relevant impact, enhancing synergies. Additionally,
participate in exercises of international scope;
Take advantage of national and international military and
police education and training structures, in particular by taking
advantage of the opportunity in Portugal to build specific
teaching structures of the North Atlantic Treaty Organization
and the European Union and associated initiatives to deepen
the knowledge related to cyberspace and contributing to the
awareness and prevention of its use;
Promote specific awareness programs with public and
private institutions that strengthen the behavioural aspect of
security in the digital environment, based on the sharing of
specialized knowledge about threat agents and their modes of
action;
Sensitize national entities to their specific vulnerabilities that
could be infiltrated, exploited or subverted in the digital field
by various threat agents.
Axis 3 — Cyberspace Protection:
The security of cyberspace is an integral part of national
security and is essential for the regular functioning of the state,
the economic development and innovation, as well as for
citizens' confidence in the digital market and cyberspace.
Thus, for this axis, the following lines of action shall be
adopted:
Identify and reinforce the knowledge on the critical
information infrastructures, following the profound change
and dynamics of the national and international cyberspace
security legal framework;
Promote the continuous development of the capabilities and
maturity of national entities for the prevention, detection,
response and recovery from adverse cyberspace security
scenarios that may impact their network and information
systems and ecosystem that characterize them, building the
mutual trust, the sharing of information and knowledge, and
the quick and effective cooperation;
Promote national and sectoral cyberspace protection
cooperation structures, including from the public sector at
central, regional and local levels, and also from the private
sector, including small and medium-sized enterprises, for
Portuguese Official Journal, Series 1 — No. 108 — 5 June,
2019
information sharing and the promotion of mutual collaboration
in the protection of common interests;
Ensure the application of mechanisms and incentives to
enable the development of national and international
cyberspace security management frameworks and their
adoption by national authorities with responsibilities for
critical infrastructures and essential services;
Maximize the security and defence of the Armed Forces and
National Defence information networks and systems with a
view to maintaining operational capability in cyberspace
through the capability of defensive cyber defence.
Axis 4 —
crime:
Response to threats and combating cyber-
In the area of post-incident response, according to the
characteristics of cyber-attacks, in addition to the criminal
authorities and the entities that make up the Internal Security
System, other entities that, because of their attributions,
detain information, including their own, or resulting from
national and international cooperation relevant to the
attribution of authorship or supporting the criminal
investigation itself, shall intervene.
The national security of cyberspace is also based on its
ability to build deterrent mechanisms. The achievement of
such a goal involves training cyberspace security authorities in
defensive and response mechanisms so that any unlawful
action against cyberspace in the national interest will be the
object of an appropriate action.
Thus, the indispensable existence of mechanisms for the
threat identification, analysis, assessment and disruption make
it imperative to reinforce the means of threat identification and
appropriate response through the strengthening of national
cyberspace security structures.
Also, cyberspace has led to the creation of new patterns of
human behaviour and action for the benefit of society, as well
as new threat typologies and crimes that need a timely,
coherent, participatory and collaborative response, where it is
important to protect legally established property and the rights
of citizens. Furthermore, in addition to opening the way for the
practice of new types of crime, it has also given rise to an
enabling environment for old crimes to develop with new, farreaching offensive methods and actions detrimental to the
national interest.
It is also important to highlight that cyberspace threats are
characterized by their transversality, rapid network
propagation, anonymity and persistence. Considering this
threat typology, only one network response will enhance and
strengthen the effort and capacity of the entire community
involved in risk mitigation, minimizing or preventing the
respective impacts and ensuring a high common level of
security in the cyberspace of national interest.
The challenges posed by the prevention and investigation of
these phenomena imply a careful and permanent observation,
which allows, to prepare for timely legal developments and, to
adapt the capacity of public and private entities to respond to
threats that undermine the operational continuity and the fight
against cyber-crime. Likewise, these challenges require
institutions to make a permanent effort to equip and to enable
them to fully fulfil their missions. It is therefore important that
the threat response systems, such as the police and the
judiciary systems, in coordinated effort, adapt to the ways in
which threats are responded to and investigated through the