Owing to globalisation and digitalisation, Finland’s security environment has rapidly transformed. Along with the changes in the security and operating environment national threats, such as phenomena and undertakings associated with espionage and terrorism, are increasingly occurring in networks. This change also calls for the authorities to have powers that extend to the cyber domain. As a consequence of the new situation Finland, too, has started preparing intelligence legislation in the administrative branches of the Ministry of the Interior and the Ministry of Defence. The Implementation Programme for 2017–2020 was compiled from recommendations for action gathered during the drafting process. Recommendations were gathered through a targeted request to ministries and government agencies and by arranging interviews and discussions with the scientific and research community, the public administration and the business community. The preparation for the Implementation Programme took into account the strategy documents adopted as Government Resolutions as well as other strategy documents and, when possible, other strategy documents being prepared during the time of the drafting process, such as the updating of the Security Strategy for Society. The selection criteria for the action items were that they promote the achievement of the Vision and comply with the strategic guidelines. The selection emphasised the standpoint of effectiveness, highlighting the individual as a customer of public services, securing the vital functions and cooperation among the public sector, the business community and the scientific and research community. The Implementation Programme gathers together the public sector’s wide-ranging and significant internal projects and actions that aim to improve information and cyber security which are to be implemented together with the business community and NGOs. It also brings them into the public view as coherent and properly delegated processes. When the projects and actions are included in the Implementation Programme it is possible to regularly monitor and measure their progress, which also provides a better overall situation picture of cyber security development. The measurement methods must be continually developed, especially as regards monitoring the quality of actions. In addition to the far-reaching measures selected for the Implementation Programme cyber security is also constantly being improved through other administrative branch-specific actions as well as by the work associated with developing cyber and information security and continuity management. The Implementation Programme is evaluated and measured annually and, in that context, measures can be changed, added or removed. The updating of the Implementation Programme has be prepared in a working group chaired by Pentti Olin, Senior Advisor, Secretariat of the Security Committee and Tuija Kuusisto, Security Manager, Adjunct Professor, Ministry of Finance, Kimmo Rousku, General Secretary of VAHTI, Ministry of Finance, Rauli Paananen, Deputy Director, Finnish Communications Regulatory Authority (FICORA), and Nadja Nevaste, Advisor, Secretariat of the Security Committee as members. 6 The Security Committee

Select target paragraph3