NATIONAL CYBER SECURITY STRATEGY GREEN PAPER 4 PROPOSED STRATEGY • Official EU documentation • Relevant action items within Digital Malta and other local strategy documents such as e-Commerce Malta - the National e-commerce Strategy (2O14-2O2O) - published by the Malta Communications Authority. 1 GOAL: ESTABLISH A GOVERNANCE FRAMEWORK The governance framework covers the necessary key functions and corresponding roles and responsiblities, as well as policies and processes necessary to constitute a robust foundation for an effective National Cyber Security Strategy. “THE GOVERNANCE FRAMEWORK COVERS THE NECESSARY KEY FUNCTIONS AND CORRESPONDING ROLES AND RESPONSIBILITIES, AS WELL AS POLICIES AND PROCESSES NECESSARY TO CONSTITUTE A ROBUST FOUNDATION FOR AN EFFECTIVE NATIONAL CYBER SECURITY STRATEGY.” 1.1 ESTABLISH THE NECESSARY KEY COORDINATION STRUCTURES It is envisaged that the following functions (involving multiple stakeholders) shall be required to ensure sustainability of the Malta Cyber Security Strategy: a. At the strategic level: I. A function for the articulation and periodic review of the National Cyber Security Strategy. The creation of this function is required in the short term. This body would need to work in close cooperation with the strategy implementation function(s) referred to below ii. A strategy implementation function to oversee implementation of the strategy and monitor cyber security operations. Such function needs to have the necessary funding, resources and mandate to: • Take a leading, active role in the implementation of the National Cyber Security Strategy • Ensure security preparedness of the public and private sector of their ICT, in line with established security requirements. The structure4 and responsibilities of these functions are subject to further consultations and may need to be aligned to any relevant European Union requirements. b. At the operational level, function(s) for the national coordination of cyber detection and response. Computer Security Incident Response Teams (CSIRTs) tend to be of such technical and operational nature. This entails ensuring consolidation of a top level coordinating CSIRT5. It also implies close communication and coordination of the CSIRT with the proposed strategy implementation function, given that it would need to be involved on: • Real-time information sharing and response to calls • Longer term planning⁶ Communication and coordination, as the need arises, with other CSIRTs existing in Malta may also be necessary. 15 MALTA | NATIONAL CYBER SECURITY STRATEGY GREEN PAPER

Select target paragraph3