NATIONAL CYBER SECURITY STRATEGY GREEN PAPER 4 PROPOSED STRATEGY 3.4 CONDUCT CYBER DEFENCE EXERCISES Cyber defence exercises are to be scheduled and conducted from time to time. Such a measure contributes to the need to review the ability to anticipate, prepare for, identify and attribute, combat hostile cyberspace acts. Apart from technical considerations, cyber defence exercises should also assess non-technical areas both at an operational, tactical as well as at a strategic level such as testing national and international coordination and any relevant Standard Operational Practices. “SUCH MEASURE {CONDUCT CYBER DEFENCE EXERCISES) CONTRIBUTES TO THE NEED TO REVIEW THE ABILITY TO ANTICIPATE, PREPARE FOR, IDENTIFY AND ATTRIBUTE, COMBAT HOSTILE CYBER ACTS.” Although crucial for stakeholders such as the public sector and key market operators13, such exercises should also be conducted by other organisations. 4 GOAL: SECURE CYBERSPACE 4.1 ESTABLISH REGULATION AND VOLUNTARY SELF-COMMITMENT FOR GUARANTEEING CYBER SECURITY The current scenario analysis of cyber security in Malta indicates areas of regulation and policy particularly within the local regulated industry sectors. Focus appears to be mainly on policy frameworks covering the licensing approaches which seek to mitigate risk. Whilst legislation may help, Maltese regulatory authorities may also need to address further emerging technology such as cloud computing applicability, through regulation within their respective sectors. On the other hand, it is understood that legislation and regulation cannot necessarily cover all aspects of cyber security; particularly considering potential financial and human resource constraints for robust cyber security. Voluntary self commitment is, thus, also key to cyber security. The notion of the applicability of a European trust mark, applied also in a number of EU states14 may encourage voluntary self commitment and may therefore be one item to considered locally. Local national strategy may already serve as potential opportunities for further consideration in fostering self commitment, such as: • e-Commerce Malta which highlights three pillars as its basis: i. Engendering trust in ecommerce ii. Transforming micro-enterprises iii. Taking Small to Medium sized Enterprises and industry to the next level; which specifically also refers to an audit-kit – through a Specialist advisory service (Measure 2) and the European trust-mark (Measure 9) 20 MALTA | NATIONAL CYBER SECURITY STRATEGY GREEN PAPER

Select target paragraph3